Platform Endpoint Tenant Classification

Scope

Classification Ledger

Endpoint fileCategoryTenant sourceAuth baselineNotes
AdministrationTrustSigningMutationEndpoints.cstenant-required businessPlatformRequestContextResolverplatform policy groupsTenant-scoped key/issuer/certificate operations.
AnalyticsEndpoints.cstenant-required businessPlatformRequestContextResolverPlatformPolicies.AnalyticsReadAggregation paths require tenant context for cache keys and result shaping.
ContextEndpoints.cstenant-required businessPlatformRequestContextResolverPlatformPolicies.ContextRead/WriteContext preferences keyed by (tenant, actor).
EnvironmentSettingsEndpoints.csglobal/systemnoneAllowAnonymousSetup/bootstrap configuration payload for frontend shell.
EnvironmentSettingsAdminEndpoints.csglobal/systemnonePlatformPolicies.SetupRead/SetupAdminDB setting overrides are setup-admin operations, not tenant business data.
EvidenceThreadEndpoints.cstenant-required businessPlatformRequestContextResolverevidence policy groupsEvidence queries are tenant-scoped.
FederationTelemetryEndpoints.cslayered: tenant participation + installation operationsPlatformRequestContextResolver for /participation/*; none for /installation/*telemetry participation/facts policies; Platform federation policiesCurrent-tenant consent and fact ingress are isolated under /participation/*. Site status, privacy budget, bundles, intelligence, and trigger are installation-wide Platform state under separately authorized /installation/* routes.
FederationPeerEndpoints.csinstallation-to-installation internal transportnone; source site derives from the presented client certificate bindingconnection client certificate plus exact certificate-thumbprint-to-site binding and explicit trusted DSSE signer-key-to-site bindingInternal peer bundle receipt is excluded from public OpenAPI. Tenant headers do not authenticate the caller; sealed or disabled federation rejects delivery.
FunctionMapEndpoints.cstenant-required businessPlatformRequestContextResolverfunction-map policy groupsTenant-scoped function map catalog and operations.
IntegrationReadModelEndpoints.cstenant-required businessPlatformRequestContextResolverPlatformPolicies.IntegrationsReadFeed/vex source projections require tenant context.
LegacyAliasEndpoints.cstenant-required businessPlatformRequestContextResolversame as canonical mapped policiesCompatibility aliases enforce same tenant requirements as canonical endpoints.
MigrationAdminEndpoints.csglobal/systemnonePlatformPolicies.SetupAdminMigration operations are control-plane/system admin functions.
PackAdapterEndpoints.cstenant-required businessPlatformRequestContextResolverpack adapter policiesRelease-pack adaptation paths are tenant-scoped.
PlatformEndpoints.cstenant-required business (plus guarded tenant-param admin reads)PlatformRequestContextResolver + route tenant parity checkhealth/quota/onboarding/preferences/search/metadata policy groupsRoute tenant IDs are now validated against resolved tenant (tenant_forbidden on mismatch).
ReleaseControlEndpoints.cstenant-required businessPlatformRequestContextResolverrelease-control policy groupsBundle/version/materialization operations use tenant-bound store calls.
ReleaseReadModelEndpoints.cstenant-required businessPlatformRequestContextResolverrelease-read policiesRun/activity/release projections are tenant scoped.
SeedEndpoints.csglobal/systemnonePlatformPolicies.SetupAdmin + STELLAOPS_ENABLE_DEMO_SEED gateExplicitly system/admin for controlled demo seeding.
SetupEndpoints.cstenant-aware adminresolver when available; controlled bootstrap setup context when platform not initializedsetup policy groupsIntentional bootstrap bypass is bounded to setup lifecycle checks.
TopologyReadModelEndpoints.cstenant-required businessPlatformRequestContextResolverPlatformPolicies.TopologyReadTopology data assembled from tenant-keyed release control stores.