tenant-engine/docs
tegwick d132db064f Name what CheckRequest.tenant denotes; record the access-engine rename intake
TEN-DEC-2026-002 answers flex-auth's FLEX-WP-0022-T01, open since
2026-09-15: `tenant` denotes the target tenant record, equals
`resource.id` by intent, and the write API is cross-tenant by design —
no action is refused on the subject/tenant relationship, and
tenant.guardrail.read must not differ because flex-auth itself calls it
across tenants. docs/flex-auth-integration.md states the relation in
this repo's voice.

TEN-IN-0004 is the live record flex-auth asked for on FLEX-WP-0020.
Runtime names stay flex-auth (FLEX-DEC-2026-013) and all deploy, cluster
and settings coordinates verify as retained; only five documentation
repository paths change when the rename lands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:09:55 +02:00
..
evidence Onboard tenant-engine to the staged-promotion contract 2026-08-29 14:51:27 +02:00
intakes Implement TEN-WP-0011 security layer conformance 2026-08-29 13:02:51 +02:00
data-retention-policy.md Implement PostgreSQL production store path 2026-08-19 14:43:08 +02:00
evidence-emission.md Correct the audit-core envelope to the published wire contract 2026-09-10 18:46:16 +02:00
flex-auth-integration.md Name what CheckRequest.tenant denotes; record the access-engine rename intake 2026-09-21 02:09:55 +02:00
tenant-guardrail-policy.md Finish TEN-WP-0010: mutable grouping, contract corrected, handoffs sent 2026-08-17 22:53:10 +02:00
tenant-lifecycle-api.md Implement PostgreSQL production store path 2026-08-19 14:43:08 +02:00