MSP / Owner Model
Owner portal provides tenant management, usage visibility, audit-backed actions, and read-only impersonation.
Safety rules
- • Owner-only server validation on `/owner` routes and APIs.
- • Read-only impersonation blocks write APIs with `READ_ONLY_IMPERSONATION`.
- • Every owner action writes an audit event.
- • Export surfaces return non-sensitive tenant summaries only.