Skip to content

[R1-15a backend] List platform tenant metadata for operators #238

Description

@smiggleworth

Backend child of #237 under R1 — Readiness program scoped. Deliver an operator-only, paginated tenant metadata inventory through GET /api/v1/platform/tenants and a read-only list_platform_tenants MCP tool. Define snake_case route, query, JSON, result, error, and OpenAPI contracts first. Reuse IPlatformOperatorRequest and the explicitly configured PlatformOperatorAuthority; add a Portia query handler over the existing global Fitz TenantDirectory projection and event history. Return only tenant identity, names, slug, provisioning/lifecycle status, first-administrator invitation indicator, and operator attribution. Do not expose client business records or give the operator implicit tenant membership, role grants, or engagement assignment.

Prove operator allow and nonoperator deny without disclosing tenant identities or counts, stable pagination, status changes and replay, projection lag and recoverable failure, and standalone/split API-worker parity. Close only after backend acceptance evidence and exact-head CI are linked. Keep #237 and product parent #127 open for later UI/integration.

Applicable backend dependencies: #152 (R1-15 backend foundation), #157 (EN-01 backend), #123 (M0-D25 tenant/operator policy), #126 (M0-A07 tenant context), and #139 (M0-D28 canonical model). M0-D24 #136 is UI-only. Platform operator status grant/revoke and cross-tenant client business-data authority remain unresolved in #123 and are outside this child.

Later M0-D25 decision

This closed issue records the operator-directory capability as delivered with the then configured operator authority; it does not claim to deliver later operator grants. M0-D25, accepted 2026-09-22, now requires in-product operator grants and revocations, initial configuration bootstrap only, and metadata-only operator access. R1-15 backend #152 owns that remaining change. The historical delivery evidence above remains unchanged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:tenancyClient organizations, tenant isolation, firm staff, engagements, and independencearea:workspacePlatform membership, roles, collaboration, and accountable workpriority:P0Required for the first usable audit workflowtype:featureUser-facing product capability

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions