Tenant policy
@kindgi/specs/policy.schema.json, schema version 1.0.0.
Kernel-level access control for a tenant. Enforced at every boundary — agent construction, tool invocation, memory read/write, blob access, model routing, event subscription. Applications cannot bypass; they inherit. The decision engine is pluggable (e.g. OpenFGA, Zanzibar-style) — this schema is transport-neutral.
id(string, required)tenantId(string, required)version(string, required): Semver — policy edits produce a new version. Decisions are traceable back to the version in force at the time.description(string)rules(array of Rule, required)defaults(object): Fail-closed defaults. If no rule matches a decision request, these apply.onNoMatch("deny"|"allow")
Definitions
Section titled “Definitions”id(string, required)effect("allow"|"deny", required)principal(PrincipalSelector, required)resource(ResourceSelector, required)action(array of string, required)condition(map of any): Optional structured condition (e.g. time window, IP allowlist, attribute match). Engine-specific evaluation.description(string)
PrincipalSelector
Section titled “PrincipalSelector”Who this rule applies to. At least one selector field required.
userIds(array of string)roles(array of string)groups(array of string)agentIds(array of string)toolIds(array of string)packIds(array of string)any(boolean): If true, applies to any principal (used for public/anonymous rules — rare).
ResourceSelector
Section titled “ResourceSelector”What this rule governs.
kind("memory-fact"|"memory-log"|"blob"|"run"|"flow"|"agent"|"tool"|"model"|"event-subscription"|"provenance"|"approval-queue"|"pack-config"|"tenant-config"|"secret"|"audit-log")ids(array of string): Specific resource ids. If absent, applies to all resources of the kind.scope(map of any): Scope match (project, thread, session, org). Fields interpreted per resource kind.tags(array of string): Match resources bearing all these tags.