MSP / Owner Model

Owner portal provides tenant management, usage visibility, audit-backed actions, and read-only impersonation.

Safety rules

  • • Owner-only server validation on `/owner` routes and APIs.
  • • Read-only impersonation blocks write APIs with `READ_ONLY_IMPERSONATION`.
  • • Every owner action writes an audit event.
  • • Export surfaces return non-sensitive tenant summaries only.