feat: orchestrate governed tenant erasure
This commit is contained in:
@@ -26,6 +26,12 @@ pattern contract documented in
|
||||
Manifest-provided documentation topics back contextual help for tenant fields,
|
||||
governance limits, permission blockers, and lifecycle consequences.
|
||||
|
||||
Destructive tenant erasure is an explicit, durable workflow rather than a
|
||||
single delete request. Provider previews, policy-defined multi-party approval,
|
||||
recent authentication, typed confirmation, suspension, idempotent checkpoints,
|
||||
and reconciliation must all succeed before the Core scope is removed. See
|
||||
`docs/TENANCY_MODULE_BOUNDARY.md` for the API and recovery contract.
|
||||
|
||||
Core's `module_entitlements` tenant-setting key is reserved. Generic tenant
|
||||
updates preserve it even when replacing the remaining settings document;
|
||||
system and tenant module administrators change it through the Admin module's
|
||||
|
||||
Reference in New Issue
Block a user