Repository navigation
Plan a tenant hierarchy: parent tenants that create and enter their own child tenants - #767
Draft
MikeAlhayek wants to merge 2 commits into
Draft
MikeAlhayek wants to merge 2 commits into
MikeAlhayek wants to merge 2 commits into
Conversation
Design plan for a module that lets a parent tenant create and manage its own child tenants, and lets parent users enter those children through delegated access with strict isolation and attribution. Covers the Orchard Core findings it relies on, the threat model, the architecture, policies, alternatives, a phased plan and the recorded decisions. Nothing is built.
Adds goal G8 and a scope containment section: requests carry registry ids instead of tenant names, only the broker reaches other tenants, a host-level IShellHost guard refuses and filters anything outside the hierarchy, and a feature audit covers the features that open other tenants by design. Adds the matching phase 0 spike, phase 1 deliverables and tests, and explains the two ways a firm works with a business.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a design plan,
docs/engineering/tenant-hierarchy/tenant-hierarchy-plan.md. It covers a module that lets a non-Default "parent" tenant create and manage its own "child" tenants, and lets parent users move between those children without signing in again. The motivating case is a bookkeeping firm that runs one tenant per client business. Nothing is built yet; this PR is the plan only.What the plan concludes
IShellHostrefuses any scope a parent or child opens outside its hierarchy, and hides other tenants' settings from it. A feature audit covers what opens other tenants by design, including this repo's AI Agent tenant tools.__Host-cookie names;The plan also covers the threat model, the Orchard Core code it relies on (with file and line references at
988c29a406), alternatives, deployment needs, a phased plan starting with ten phase 0 spikes, the recorded decisions and the risks.Naming
The plan was first drafted as "Umbrella Tenants". It was renamed to Tenant Hierarchy because "umbrella" isn't a standard software term, already means a specific kind of employer in UK payroll and tax, and is the name of a well-known security product. The new terms are:
The labels people see on screen can be set per parent, so a firm can show "Clients" instead of "Child tenants".
🤖 Generated with Claude Code