Explicit authority across authentication and tenant boundaries
implementation-proofA platform operator may enter a non-personal organisation only through one active, matching, audited assumption. Superadmin status exposes the option; it never grants tenant permission by itself.
Source: docs/products/story-specs/platform-admin-organisation-access/story-spec.md
A valid session must resolve to the existing identity. Failed recovery creates no duplicate identity and reveals no account existence.
Memberships and authorised non-personal organisations appear. Personal workspaces never appear.
The operator must choose the exact target. Superadmin eligibility alone cannot cross the tenant boundary.
The active assumption and allow audit are durable before the signed cookie can carry authority.
The URL tenant, stored target, cookie, actor, and active state must agree. Any mismatch denies before data access.
A matching active assumption may form the principal without a target-organisation profile. Ambient superadmin authority remains forbidden.
Dashboard authority and one representative operation must succeed in the selected tenant; URL or banner arrival is insufficient.
Changing context revokes the prior assumption before selecting the next member or assumed workspace.
Exit, logout, expiry, revocation, malformed cookie, or operator removal must deny the next request.