Skip to content

Tenant policy

@kindgi/specs/policy.schema.json, schema version 1.0.0.

Kernel-level access control for a tenant. Enforced at every boundary — agent construction, tool invocation, memory read/write, blob access, model routing, event subscription. Applications cannot bypass; they inherit. The decision engine is pluggable (e.g. OpenFGA, Zanzibar-style) — this schema is transport-neutral.

  • id (string, required)
  • tenantId (string, required)
  • version (string, required): Semver — policy edits produce a new version. Decisions are traceable back to the version in force at the time.
  • description (string)
  • rules (array of Rule, required)
  • defaults (object): Fail-closed defaults. If no rule matches a decision request, these apply.
    • onNoMatch ("deny" | "allow")
  • id (string, required)
  • effect ("allow" | "deny", required)
  • principal (PrincipalSelector, required)
  • resource (ResourceSelector, required)
  • action (array of string, required)
  • condition (map of any): Optional structured condition (e.g. time window, IP allowlist, attribute match). Engine-specific evaluation.
  • description (string)

Who this rule applies to. At least one selector field required.

  • userIds (array of string)
  • roles (array of string)
  • groups (array of string)
  • agentIds (array of string)
  • toolIds (array of string)
  • packIds (array of string)
  • any (boolean): If true, applies to any principal (used for public/anonymous rules — rare).

What this rule governs.

  • kind ("memory-fact" | "memory-log" | "blob" | "run" | "flow" | "agent" | "tool" | "model" | "event-subscription" | "provenance" | "approval-queue" | "pack-config" | "tenant-config" | "secret" | "audit-log")
  • ids (array of string): Specific resource ids. If absent, applies to all resources of the kind.
  • scope (map of any): Scope match (project, thread, session, org). Fields interpreted per resource kind.
  • tags (array of string): Match resources bearing all these tags.