## Architecture Small headless service, modeled on `qonto-assistant`'s layout (same fleet convention). Layers: - `domain/` — tenant, grouping, capability-role, and plan-grant models; pure, no framework dependency. - `store/` — persistence for tenant records and the role/plan grant audit trail. In-memory and SQLite back development and tests; PostgreSQL is the production store (`TEN-WP-0009`). - `api/` — three surfaces per the boundary contract: a cache-read API (`key-cape` calls at token issuance), a live-lookup API (`access-engine` calls synchronously for high-stakes decisions — must fail closed, never open), and a write API (grant/revoke/plan mutations, authorization-gated by `flex-auth`, not self-authorized). - `guardrail/` — shipped (`TEN-WP-0006`/`0007`): spend / entity-count / action-count ceilings resolved as a total function of grouping, plan, override, and lifecycle. Contract: `docs/tenant-guardrail-policy.md`. Full ownership boundary and API contract: `net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`. Claim/carrying mechanism this service implements: `net-kingdom/canon/standards/iam-profile_v0.3.md` ("Tenant Roles" section). ## Quick Reference `~/state-hub/mcp_server/TOOLS.md` — MCP tool reference