Tenants and guests
Which principals a boundary can see and grant roles to, and what happens when a platform administrator reaches outside the tenant.
Every boundary belongs to a tenant: the group of people, and the sign-in settings, it shares with the other boundaries of the same customer. A new boundary starts as a tenant of its own. A Platform Owner can move a boundary into another tenant; the people who had access to it then become members of that tenant too.
The tenant decides two things in access control: whom you find when you search for a principal, and to whom you may assign a role, a deny assignment or — as the requester — a just-in-time request.
Who belongs to a tenant
| Principal | Belongs to the tenant when |
|---|---|
| User | They are a member: invited to one of its boundaries, signed in through the tenant's single sign-on, added as a guest, or carried over when a boundary moved in |
| Group | It was created for one of the tenant's boundaries |
| Service account, managed identity | It was created for one of the tenant's boundaries |
When the platform keeps tenants as organizations in its identity provider — the default — tenant membership is kept in step with the organization, so a person added there is a member here. Inviting people is described in Users and invitations, sign-in through a company identity provider in Single sign-on.
A service account or managed identity created for one boundary can be given roles in the other boundaries of the same tenant, but not in another tenant's unless a boundary trust allows it.
Guests
A Platform Owner assigning a role sees an extra switch, Include other tenants, under the member search. With it on, the search covers everyone on the platform. Assigning a role to a user found that way makes them a guest member of the boundary's tenant — recorded as such, with an entry in the boundary's activity log — so the tenant can see who from outside has access. Only users become guests: a group or service principal from another tenant that a Platform Owner assigns is not recorded as a member.
Without the switch the search stays within the tenant. For anyone who is not a Platform Owner, a principal from another tenant is refused with "Principal not a member of this tenant."
Workloads from another tenant
Anyone but a Platform Owner can give a managed identity or service account from another tenant's boundary a role here only when a platform administrator has recorded a boundary trust from its boundary into this one. Operators can read how in Boundary trusts.