Architecture concept

Verification Required

Tenancy and security concepts.

Use this page to read tenant, dataset, stream visibility, auth mode, bearer token, trusted-header, and current-gap language without turning local or controlled-beta evidence into a broader identity, privacy, support, or compliance claim.

Concept Snapshot

Core terms
7
Product surfaces
4
Default posture
Review
Review state
Pending

Term Map

Tenant

Verification Required

A product-scoped identity or partition boundary used by docs examples, route checks, limits, records, or access policy.

Use now: Use when a product reference names the tenant field, header, route permission, quota, or local policy that applies to a request.

Boundary: Does not imply product-wide isolation, customer identity integration, privacy posture, regulatory posture, or shared tenancy semantics across products.

Dataset

Verification Required

A named grouping or filter boundary whose exact behavior is owned by the product page that defines the field.

Use now: Use for LogDB query authorization and filters, Concordia local TSDB or placement examples, and cautious ObjectDB native-model discussion.

Boundary: Does not imply a global Stornamics namespace, cross-product policy boundary, or customer data governance claim.

Stream Visibility

Controlled Beta

The Message Broker route behavior that returns only tenant-visible stream descriptions or not-found errors for streams outside the caller's route context.

Use now: Use with broker stream list, stream describe, storage catalog, stream inspect, and permission language from the HTTP reference.

Boundary: Does not imply cross-tenant discovery, external identity-provider validation, or every stream-sharing pattern a deployment might need.

Auth Mode

Verification Required

A configured product posture for checking credentials or admitting local requests, such as insecure-local, api-key, mTLS, external, or local bearer-token modes.

Use now: Use only with the exact product mode, route family, credential source, transport, and local or controlled-beta status named by the reference.

Boundary: Does not imply direct identity-provider validation, customer credential parity, hosted control-plane integration, or a uniform auth model across products.

Bearer Token

Verification Required

A credential value passed in an Authorization header or metadata field where a product reference names that behavior.

Use now: Use for Message Broker API-key examples, LogDB local tenant admission, and Concordia local Cache, TSDB, or Gateway admission checks.

Boundary: Local tokens are example or development admission boundaries unless a product page names stronger credential validation and reviewer acceptance.

Trusted Header

Verification Required

An external Message Broker identity mode where a configured upstream component supplies identity through headers the broker trusts.

Use now: Use when documenting broker external auth mode and route checks that depend on configured upstream identity headers.

Boundary: Does not imply direct identity-provider validation, header trust outside the configured boundary, or automatic support in ObjectDB, Concordia, or LogDB.

Current Gap

Verification Required

A named area where the docs intentionally hold stronger identity, security, privacy, support, or policy wording for later evidence and review.

Use now: Use near auth, tenant, dataset, encryption, trusted-header, local-token, support, or customer-commitment language that is not yet accepted.

Boundary: A current gap is not a defect claim or roadmap promise; it is a review boundary for the exact wording in front of the reader.

Product Surface Map

Tenancy and security surfaces by product
ProductCurrent surfaceEvidenceBoundary
ObjectDBS3 Core gateway examples use local development principals and ObjectDB-specific permission headers; bucket policy, SSE header mapping, and customer credential composition stay review-bound.DOCS-029, DOCS-038, ODB-EVID-009Do not claim IAM parity, customer credential parity, encryption-at-rest backend composition, tenant isolation, or policy outcomes beyond the named local gateway behavior.
Message BrokerThe controlled-beta HTTP surface supports insecure-local, api-key, mTLS, and external auth modes, with tenant and stream permissions for protected route families.DOCS-031, DOCS-032, DOCS-040, SMB-EVID-010, SMB-EVID-011Do not claim direct identity-provider validation, unrestricted remote CLI credentials, Kafka listener identity semantics, or production support coverage.
ConcordiaCache, TSDB, and Gateway local routes use documented bearer-token admission checks; TSDB and placement examples carry tenant and dataset identifiers.DOCS-035, DOCS-041, DOCS-042, CONC-EVID-012, CONC-EVID-013Do not claim JWT signature validation, key-source loading, identity-provider integration, shared storage policy, or cross-node authorization behavior.
LogDBOTLP and query routes use x-logdb-tenant plus Authorization bearer credentials in local development; query requires a dataset and checks dataset read authorization.DOCS-033, DOCS-034, DOCS-039, LDB-EVID-003, LDB-EVID-010Do not treat custom endpoint JSON helper routes as tenant-admitted OTLP behavior or claim broader identity, privacy, retention, or BYOC readiness.

Review Flow

  1. Name The Product SurfaceIdentify whether the claim is about ObjectDB S3 Core, Message Broker HTTP routes, Concordia local surfaces, or LogDB OTLP/query routes.
  2. Name The BoundaryState tenant, dataset, stream, auth mode, token, header, route, transport, and local or controlled-beta posture.
  3. Attach EvidenceLink source, compatibility row, known limit, evidence index, and reviewer owner for the exact behavior.
  4. Hold Stronger ClaimsKeep product-wide isolation, hosted identity, customer credential, privacy, support, compliance, and commitment wording in review.

Do Not Infer

No Shared Identity Plane

Product-specific tenant, dataset, stream, and token behavior does not create one cross-product identity model.

No Hosted IdP Claim

API keys, local bearer tokens, mTLS trust files, and trusted headers only mean what the owning reference says they mean.

No Compliance Shortcut

Access checks, tenant headers, and local admission examples do not establish certification, regulatory, privacy, support, or legal commitments.

Evidence

DOCS-047 evidence map
Concept areaEvidenceStatus
Cross-product tenancy and security vocabularyDOCS-007, DOCS-019, DOCS-044, DOCS-045, DOCS-046pending
ObjectDB local principal, policy, SSE, and credential boundariesDOCS-029, DOCS-038, ODB-EVID-007, ODB-EVID-009pending
Message Broker auth modes, tenant permissions, and stream visibilityDOCS-031, DOCS-032, DOCS-040, SMB-EVID-010, SMB-EVID-011pending
Concordia local bearer-token and production identity boundariesDOCS-035, DOCS-041, DOCS-042, CONC-EVID-012, CONC-EVID-013pending
LogDB tenant admission, dataset authorization, and helper-route boundariesDOCS-033, DOCS-034, DOCS-039, LDB-EVID-003, LDB-EVID-010pending

Internal review records track this concept page and its claim boundaries.

Safe Next Steps

  • Available: DOCS-007

    Use the claim-review checklist

    Route security, privacy, support, credential, identity, tenant, and customer-commitment wording through the required reviewers.

  • Available: DOCS-045

    Read product mental models

    Use product nouns correctly before writing tenant, dataset, stream, auth, or trusted-header copy.

  • Available: DOCS-042

    Review known limits

    Check unsupported auth, identity, token, trusted-header, and customer credential behavior before publishing guidance.

  • Available: E06

    Compare compatibility rows

    Use compatibility status and evidence before strengthening identity or access-control wording.