docs(adr): propose ADR-0017 a Tenant above Teams as the access boundary #168

Merged
ryangr0 merged 1 commit from ryangr0/adr-tenant-boundary into development 2026-10-03 11:49:34 +00:00 AGit
Owner

Ploeg and Vloer scope access by Team, but a Team is a capability pool:
created work moves between Teams, the root budget pool is locked per
source Team, the deploy token is deployment-wide, scope pins collide,
operator admission trusts request repository ids, and Vloer shows every
source and repository to every signed-in user.

ADR-0017 proposes a Tenant (ADR-0009's agency tenant) above Teams that
owns users via SSO groups, tracker sources, repositories, Teams, root
budgets, deploy identities and Work Items, with enforcement points in
both services, 404 for forbidden objects, the follow-up enforcement
tickets and isolation tests as Confirmation. Open owner questions are
listed in the ADR. Registered in the system index, the decision register
and as an ambiguity in the product domain model.

Proposed, not accepted: five owner questions are listed in the ADR. The domain model gets an ambiguity entry only; the Tenant definition changes when the ADR is accepted.

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1741

🤖 Generated with Claude Code

Ploeg and Vloer scope access by Team, but a Team is a capability pool: created work moves between Teams, the root budget pool is locked per source Team, the deploy token is deployment-wide, scope pins collide, operator admission trusts request repository ids, and Vloer shows every source and repository to every signed-in user. ADR-0017 proposes a Tenant (ADR-0009's agency tenant) above Teams that owns users via SSO groups, tracker sources, repositories, Teams, root budgets, deploy identities and Work Items, with enforcement points in both services, 404 for forbidden objects, the follow-up enforcement tickets and isolation tests as Confirmation. Open owner questions are listed in the ADR. Registered in the system index, the decision register and as an ambiguity in the product domain model. Proposed, not accepted: five owner questions are listed in the ADR. The domain model gets an ambiguity entry only; the Tenant definition changes when the ADR is accepted. Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1741 🤖 Generated with [Claude Code](https://claude.com/claude-code)
docs(adr): propose ADR-0017 a Tenant above Teams as the access boundary
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
0315881d42
Ploeg and Vloer scope access by Team, but a Team is a capability pool:
created work moves between Teams, the root budget pool is locked per
source Team, the deploy token is deployment-wide, scope pins collide,
operator admission trusts request repository ids, and Vloer shows every
source and repository to every signed-in user.

ADR-0017 proposes a Tenant (ADR-0009's agency tenant) above Teams that
owns users via SSO groups, tracker sources, repositories, Teams, root
budgets, deploy identities and Work Items, with enforcement points in
both services, 404 for forbidden objects, the follow-up enforcement
tickets and isolation tests as Confirmation. Open owner questions are
listed in the ADR. Registered in the system index, the decision register
and as an ambiguity in the product domain model.

VIK-1741

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit 875fbdefe5 into development 2026-10-03 11:49:34 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!168
No description provided.