Skip to content
Stackship documentation Svenska

Access controlUsers

Tenants and guests

Which principals a boundary can see and grant roles to, and what happens when a platform administrator reaches outside the tenant.

Every boundary belongs to a tenant: the group of people, and the sign-in settings, it shares with the other boundaries of the same customer. A new boundary starts as a tenant of its own. A Platform Owner can move a boundary into another tenant; the people who had access to it then become members of that tenant too.

The tenant decides two things in access control: whom you find when you search for a principal, and to whom you may assign a role, a deny assignment or — as the requester — a just-in-time request.

Who belongs to a tenant

Principal Belongs to the tenant when
User They are a member: invited to one of its boundaries, signed in through the tenant's single sign-on, added as a guest, or carried over when a boundary moved in
Group It was created for one of the tenant's boundaries
Service account, managed identity It was created for one of the tenant's boundaries

When the platform keeps tenants as organizations in its identity provider — the default — tenant membership is kept in step with the organization, so a person added there is a member here. Inviting people is described in Users and invitations, sign-in through a company identity provider in Single sign-on.

A service account or managed identity created for one boundary can be given roles in the other boundaries of the same tenant, but not in another tenant's unless a boundary trust allows it.

Guests

A Platform Owner assigning a role sees an extra switch, Include other tenants, under the member search. With it on, the search covers everyone on the platform. Assigning a role to a user found that way makes them a guest member of the boundary's tenant — recorded as such, with an entry in the boundary's activity log — so the tenant can see who from outside has access. Only users become guests: a group or service principal from another tenant that a Platform Owner assigns is not recorded as a member.

Without the switch the search stays within the tenant. For anyone who is not a Platform Owner, a principal from another tenant is refused with "Principal not a member of this tenant."

Workloads from another tenant

Anyone but a Platform Owner can give a managed identity or service account from another tenant's boundary a role here only when a platform administrator has recorded a boundary trust from its boundary into this one. Operators can read how in Boundary trusts.