docs: resolve tenant security audit

This commit is contained in:
2026-07-10 03:05:58 +08:00
parent 5e412761d2
commit 682bc70563
11 changed files with 368 additions and 2 deletions
@@ -0,0 +1,11 @@
# Enforce Organization status at the shared authorization seam
Type: task
Status: open
## Question
Make non-ACTIVE Organizations fail closed for project authorization,
onboarding, queued execution, and Feishu triggers through one shared seam, with
negative tests proving a SUSPENDED or ARCHIVED tenant cannot create, bind,
trigger, resume, or mutate work while operator recovery remains explicit.