SCOPE.md still said TEN-WP-0008 was "ready, not done" two paragraphs above its own table listing staged promotion as shipped, and its list of finished workplans omitted 0008 and 0011. All twelve workplans are finished; say so once. .claude/rules/architecture.md still described `guardrail/` as a reserved, unimplemented namespace and the production store as TBD. Guardrails shipped in TEN-WP-0006/0007 and PostgreSQL became the production store in TEN-WP-0009. Also corrects the live-lookup caller to `access-engine`, matching SCOPE.md and the boundary contract. No behaviour change; 287 tests pass unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HHwvAEQfmzLHtrFGhXtVjq Assistant: claude-code Assistant-Model: opus Assistant-Process: 823014@bnt-lap001 Assistant-Session: 2a0786b1-efea-4c38-959b-6e86a493f259
1.3 KiB
1.3 KiB
Architecture
Small headless service, modeled on qonto-assistant's layout (same fleet
convention). Layers:
domain/— tenant, grouping, capability-role, and plan-grant models; pure, no framework dependency.store/— persistence for tenant records and the role/plan grant audit trail. In-memory and SQLite back development and tests; PostgreSQL is the production store (TEN-WP-0009).api/— three surfaces per the boundary contract: a cache-read API (key-capecalls at token issuance), a live-lookup API (access-enginecalls synchronously for high-stakes decisions — must fail closed, never open), and a write API (grant/revoke/plan mutations, authorization-gated byflex-auth, not self-authorized).guardrail/— shipped (TEN-WP-0006/0007): spend / entity-count / action-count ceilings resolved as a total function of grouping, plan, override, and lifecycle. Contract:docs/tenant-guardrail-policy.md.
Full ownership boundary and API contract:
net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md.
Claim/carrying mechanism this service implements:
net-kingdom/canon/standards/iam-profile_v0.3.md ("Tenant Roles" section).
Quick Reference
~/state-hub/mcp_server/TOOLS.md — MCP tool reference