docs(adr): accept ADR-0017 with Clients, SSO groups and a default Tenant #225

Merged
ryangr0 merged 5 commits from ryangr0/docs/accept-adr-0017 into development 2026-10-04 16:47:56 +00:00 AGit
Owner

What and why

This accepts system ADR-0017, "A Tenant sits above Teams", with the owner's answers of 2026-10-04. Tenancy and client access move into milestone M1, so that clients can attach context to their own Work Items sooner (ADR-0021, #221).

The owner's decisions:

  • Teams are per Tenant.
  • Every install has a Tenant: a default one when self-hosted, so one code path serves self-hosted and hosted Unfold.
  • A Client owns tracker sources and repositories inside a Tenant. Client users reach only those Work Items.
  • A person may belong to several Tenants and switches between them.
  • Unfold staff never see Tenant content. There is no break-glass role.
  • SSO groups unfold/<tenant>/<role> and unfold/<tenant>/client/<client> carry memberships. ploeg.userTeams goes once the mapping ships.

The domain model's Tenant and Client entries change accordingly and are marked "decided, not implemented yet". The generated glossaries, decision register and landscape are regenerated.

Nothing is implemented here. The follow-ups are in M1 on the board: VIK-1876, 1877, 1878, 1879, 1740, 1742, 1785 and 1786.

Verification

mise run docs-check → ok (ADR registry parity, domain, decisions, landscape, links, mkdocs --strict)
gitleaks 8.30.1 on every changed file → no findings

Board: VIK-1741 (decided by this PR), milestone M1 VIK-1818.

🤖 Generated with Claude Code

## What and why This accepts system ADR-0017, "A Tenant sits above Teams", with the owner's answers of 2026-10-04. Tenancy and client access move into milestone M1, so that clients can attach context to their own Work Items sooner (ADR-0021, #221). The owner's decisions: - Teams are per Tenant. - Every install has a Tenant: a default one when self-hosted, so one code path serves self-hosted and hosted Unfold. - A Client owns tracker sources and repositories inside a Tenant. Client users reach only those Work Items. - A person may belong to several Tenants and switches between them. - Unfold staff never see Tenant content. There is no break-glass role. - SSO groups `unfold/<tenant>/<role>` and `unfold/<tenant>/client/<client>` carry memberships. `ploeg.userTeams` goes once the mapping ships. The domain model's Tenant and Client entries change accordingly and are marked "decided, not implemented yet". The generated glossaries, decision register and landscape are regenerated. Nothing is implemented here. The follow-ups are in M1 on the board: VIK-1876, 1877, 1878, 1879, 1740, 1742, 1785 and 1786. ## Verification ``` mise run docs-check → ok (ADR registry parity, domain, decisions, landscape, links, mkdocs --strict) gitleaks 8.30.1 on every changed file → no findings ``` Board: VIK-1741 (decided by this PR), milestone M1 VIK-1818. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
docs(adr): accept ADR-0017 with Clients, SSO groups and a default Tenant
All checks were successful
[Workflow] On Pull Request / checks (pull_request) Successful in 7m20s
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 42s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 56s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
f6ff286fcd
The owner answered ADR-0017's open questions on 2026-10-04: Teams are per
Tenant; every install has a Tenant, a default one when self-hosted; a
person may belong to several Tenants and switch; Unfold staff never see
Tenant content; SSO groups unfold/<tenant>/<role> and
unfold/<tenant>/client/<client> carry memberships. A Client owns sources
and repositories inside a Tenant and client users reach only those Work
Items. Tenancy and client access move into milestone M1. The domain model's
Tenant and Client entries follow, marked as decided and not implemented.

VIK-1741
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 force-pushed ryangr0/docs/accept-adr-0017 from f6ff286fcd
All checks were successful
[Workflow] On Pull Request / checks (pull_request) Successful in 7m20s
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 42s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 56s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
to f34ebc3b0c
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 32s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 17s
[Workflow] On Pull Request / checks (pull_request) Successful in 8m6s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
2026-10-04 16:10:31 +00:00
Compare
ryangr0 force-pushed ryangr0/docs/accept-adr-0017 from f34ebc3b0c
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 32s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 17s
[Workflow] On Pull Request / checks (pull_request) Successful in 8m6s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
to bfc64190a8
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / ploeg-pin (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
2026-10-04 16:31:32 +00:00
Compare
ryangr0 merged commit 34ad98da77 into development 2026-10-04 16:47:56 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!225
No description provided.