2.0 KiB
GovOPlaN Tenancy
Repository type: module (platform).
govoplan-tenancy owns tenant lifecycle, tenant administration API route
contributions, the tenancy.tenantResolver capability, and the tenant registry
and tenant settings WebUI panels during the GovOPlaN module split.
govoplan-access no longer hard-depends on this module. Access can run in the
single-scope compatibility mode used by the core/access baseline; installing
tenancy adds explicit tenant management and resolver behavior. The shared scope
storage table is core-owned as core_scopes; tenancy provides lifecycle and
administration behavior over those rows rather than owning the table.
The @govoplan/tenancy-webui package contributes system-tenants and
tenant-settings through the shared admin.sections capability. The Access
module owns the /admin shell but does not import these panels. Historical
access.admin.* surface identifiers remain stable so existing saved Views keep
working after the ownership move.
The tenant registry and active-tenant settings follow the shared interface
pattern contract documented in
docs/INTERFACE_PATTERN_MIGRATION.md.
Manifest-provided documentation topics back contextual help for tenant fields,
governance limits, permission blockers, and lifecycle consequences.
Destructive tenant erasure is an explicit, durable workflow rather than a
single delete request. Provider previews, policy-defined multi-party approval,
recent authentication, typed confirmation, suspension, idempotent checkpoints,
and reconciliation must all succeed before the Core scope is removed. See
docs/TENANCY_MODULE_BOUNDARY.md for the API and recovery contract.
Core's module_entitlements tenant-setting key is reserved. Generic tenant
updates preserve it even when replacing the remaining settings document;
system and tenant module administrators change it through the Admin module's
dedicated, revision-checked module policy APIs.