You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Aug 11, 2026. It is now read-only.
Plan definitions do not protect anything until effective entitlements are resolved and enforced consistently. Existing module management supports tenant module lifecycle, but SaaS entitlements must remain a separate commercial/access layer and must not silently disable or delete tenant data.
Objective
Implement a tenant-entitlement capability that derives effective feature/module/quota access from a published offer version plus controlled overrides and exposes one default-deny enforcement contract to modules and derived applications.
Scope
Add admitted module/extension descriptor, permissions, capability port, events, and navigation.
Parent epic: #868
Depends on: #869, #870
Context
Plan definitions do not protect anything until effective entitlements are resolved and enforced consistently. Existing module management supports tenant module lifecycle, but SaaS entitlements must remain a separate commercial/access layer and must not silently disable or delete tenant data.
Objective
Implement a tenant-entitlement capability that derives effective feature/module/quota access from a published offer version plus controlled overrides and exposes one default-deny enforcement contract to modules and derived applications.
Scope
Out of scope
Security and integrity requirements
Acceptance criteria
Testing
Documentation
Dependencies
Consumed by #872 provisioning, #873 lifecycle, #875 usage metering, and #876 subscription billing.