the-custodian/canon/architecture/adr-008-multi-tenancy-model.md
codex 1674ea550d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ADR-008: relocate the multi-tenancy framework to NetKingdom canon
Multi-tenancy is part of the IT-security framework NetKingdom provides, so it
belongs beside the IAM Profile and the tenant-engine boundary contract rather
than in the work-factory canon. Operator decision.

Relocation surfaced two things a review would have caught embarrassingly late.

NetKingdom's accepted platform-identity-security-architecture has used the word
plane since July for a trust and deployment layer - bootstrap, platform
control, tenant. This framework was using the same word for an independent
dimension of concern. Two senses of one word in one canon is precisely the
concept-ownership collision the estate is careful about, and the newcomer
yields: they are now axes. The rename is also just better, since a posture
vector is a point in five-dimensional space.

That same document also disproves the framework's opening line. It has
described the trust model, the tenant model and a capability progression since
2026-07-23, so the claim that the estate had never written down what it was
building was wrong. The accurate and narrower claim is that nothing said how
far a given service had got, or could hold several answers at once.

Stub left behind so the ADR-008 identifier resolves. The renderer moved to
policy-nexus, which owns publication.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:40:59 +02:00

1.4 KiB
Raw Blame History

id type title status decided_by date
ADR-008 architecture-decision-record Multi-Tenancy Framework — relocated to NetKingdom superseded Bernd Worsch 2026-08-17

ADR-008 — relocated

Drafts 14 of the multi-tenancy framework were written here. On 2026-08-17 the operator determined that multi-tenancy is part of the IT-security framework NetKingdom provides, so the framework belongs in NetKingdom canon beside the IAM Profile and the tenant-engine boundary contract.

It now lives at net-kingdom/canon/standards/tenancy-posture_v0.1.md.

Two things changed on relocation:

  1. The five dimensions were renamed from planes to axes. NetKingdom's accepted platform-identity-security-architecture already uses plane for a trust and deployment layer (bootstrap / platform control / tenant), and two senses of one word in one canon is a concept-ownership collision.
  2. The opening claim that the estate "has never written down what it is building" was corrected. That architecture document has described the trust and tenant model since 2026-07-23. What was actually missing is a way to say how far a given service has got.

This stub remains so that the ADR-008 identifier resolves rather than dangling. It is not a second copy and must not be edited as one.

The publication renderer that lived in tools/ moved to policy-nexus, which owns publication.