Skip to main content

Multi-tenancy and isolation

Agentstration is not yet a production multi-tenant platform, but its current authorization boundary is shared across resource, Flow, Runtime, Work, Workplace, MCP, and realtime surfaces. The Control Plane has a canonical Tenant and Workspace model plus provider-neutral Principals, local and external identity mappings, Workspace memberships, role assignments, Platform administrators, and enforced ASP.NET Core authorization policies. Local credentials are isolated in the ASP.NET Core Identity store; external authentication uses OIDC/OAuth 2.0. Agentstration does not issue OAuth tokens.

Every owned path carries a canonical instance, Tenant, or Workspace scope through routes, services, repository queries, background processing, and artifacts. Exact-scope operations are distinct from descendant-visible enumeration: instance resources may be visible to Tenant and Workspace descendants, and Tenant resources only to that Tenant's Workspaces. Homonymous resources are not merged or shadowed. Secrets, Vaults, and Parameters additionally require an explicit descendant-use grant; visibility or a reference alone does not authorize use. Unauthorized cross-scope reads and mutations do not disclose resource existence.

A global fallback policy requires authentication except for explicitly anonymous health, bootstrap, authentication, and static-asset paths. HTTP APIs declare contextual resource or Run permissions; MCP tool calls require runs/execute; Workplace and Flow Run SignalR hubs require runs/read. Platform administration remains global and does not imply a Tenant or Workspace membership. See ADR-0042, ADR-0079, ADR-0119 — descendant-use grants, Tenant, and Workspace.