Tenancy Overview

Stella Ops is designed for strict multi-tenancy. Tenancy is an explicit input to requests, storage, and exported evidence so decisions remain auditable and replayable (including in air-gapped deployments). This overview is the entry point for engineers and operators who need to understand how the tenant boundary is identified, isolated, and enforced across the platform.

Tenant Identity

Optional sub-scoping within a tenant is supported but does not replace the tenant boundary:

Note: there is no workspace tenant sub-scope claim today; “Policy Studio workspaces” are an authoring concept gated by the policy:author scope, not a tenancy boundary.

Isolation Guarantees

StellaOps aims for defense-in-depth isolation:

Enforcement Stack

Offline / Air-Gap Considerations

References