docs(adr): propose ADR-0017 a Tenant above Teams as the access boundary #168
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/adr-tenant-boundary"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Ploeg and Vloer scope access by Team, but a Team is a capability pool:
created work moves between Teams, the root budget pool is locked per
source Team, the deploy token is deployment-wide, scope pins collide,
operator admission trusts request repository ids, and Vloer shows every
source and repository to every signed-in user.
ADR-0017 proposes a Tenant (ADR-0009's agency tenant) above Teams that
owns users via SSO groups, tracker sources, repositories, Teams, root
budgets, deploy identities and Work Items, with enforcement points in
both services, 404 for forbidden objects, the follow-up enforcement
tickets and isolation tests as Confirmation. Open owner questions are
listed in the ADR. Registered in the system index, the decision register
and as an ambiguity in the product domain model.
Proposed, not accepted: five owner questions are listed in the ADR. The domain model gets an ambiguity entry only; the Tenant definition changes when the ADR is accepted.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1741
🤖 Generated with Claude Code