Files
govoplan-tenancy/README.md
T

2.0 KiB

GovOPlaN Tenancy

Repository type: module (platform).

govoplan-tenancy owns tenant lifecycle, tenant administration API route contributions, the tenancy.tenantResolver capability, and the tenant registry and tenant settings WebUI panels during the GovOPlaN module split.

govoplan-access no longer hard-depends on this module. Access can run in the single-scope compatibility mode used by the core/access baseline; installing tenancy adds explicit tenant management and resolver behavior. The shared scope storage table is core-owned as core_scopes; tenancy provides lifecycle and administration behavior over those rows rather than owning the table.

The @govoplan/tenancy-webui package contributes system-tenants and tenant-settings through the shared admin.sections capability. The Access module owns the /admin shell but does not import these panels. Historical access.admin.* surface identifiers remain stable so existing saved Views keep working after the ownership move.

The tenant registry and active-tenant settings follow the shared interface pattern contract documented in docs/INTERFACE_PATTERN_MIGRATION.md. Manifest-provided documentation topics back contextual help for tenant fields, governance limits, permission blockers, and lifecycle consequences.

Destructive tenant erasure is an explicit, durable workflow rather than a single delete request. Provider previews, policy-defined multi-party approval, recent authentication, typed confirmation, suspension, idempotent checkpoints, and reconciliation must all succeed before the Core scope is removed. See docs/TENANCY_MODULE_BOUNDARY.md for the API and recovery contract.

Core's module_entitlements tenant-setting key is reserved. Generic tenant updates preserve it even when replacing the remaining settings document; system and tenant module administrators change it through the Admin module's dedicated, revision-checked module policy APIs.