Core tenant and module access
Operate the foundation without bypassing it
One foundation.
Clear operating surfaces.
Tenant self-service, platform diagnostics, and a repeatable developer workflow now sit on the same authorization, isolation, provider, module, event, and billing contracts.
Tenant portal, audited admin diagnostics, and local module tooling ready
Tenant portalPermission-aware · Self-service
AdminDiagnosable · Fully audited
Developer pathScaffold · Validate · Test
Operating surfaces
Purpose-built views. Shared contracts.
Expanded capabilities and metering
Phase 10 principles
Easy to operate.
Hard to misuse.
Navigation follows permission
The portal presents only server-authorized tenant and manifest surfaces. Every direct API call repeats the same centralized permission and tenant checks.
Operations without database access
Platform administrators can inspect tenant, provider, job, dead-letter, billing, and audit health through secret-free, audited read models.
A repeatable module path
One local CLI creates modules, checks manifests and migrations, verifies SDK compatibility, and runs the generated test surface before integration.