feat: orchestrate governed tenant erasure

This commit is contained in:
2026-08-24 15:57:21 +02:00
parent 9ed32618ea
commit e412c7d1bd
15 changed files with 1791 additions and 72 deletions
+6
View File
@@ -26,6 +26,12 @@ pattern contract documented in
Manifest-provided documentation topics back contextual help for tenant fields,
governance limits, permission blockers, and lifecycle consequences.
Destructive tenant erasure is an explicit, durable workflow rather than a
single delete request. Provider previews, policy-defined multi-party approval,
recent authentication, typed confirmation, suspension, idempotent checkpoints,
and reconciliation must all succeed before the Core scope is removed. See
`docs/TENANCY_MODULE_BOUNDARY.md` for the API and recovery contract.
Core's `module_entitlements` tenant-setting key is reserved. Generic tenant
updates preserve it even when replacing the remaining settings document;
system and tenant module administrators change it through the Admin module's