Phase 1. Implement the Workspace tenancy anchor and signed-token authn — authorization derives from signed token claims only, never request headers.
Tasks
Acceptance
- A header-injected role has no effect; identity/tenant come only from the signed token.
Refs: ADR-0003, THREAT-MODEL §7.
Phase 1. Implement the
Workspacetenancy anchor and signed-token authn — authorization derives from signed token claims only, never request headers.Tasks
Workspace+Membership(roles: reader/operator/approver/admin) data modelmemberships[workspace]claimx-*-role/x-*-tenantheadersAcceptance
Refs: ADR-0003, THREAT-MODEL §7.