# Decide the platform-administrator identity and audit boundary Type: grilling Status: open ## Question Which identity issuer, bootstrap and recovery procedure, invite/allowlist model, session claims, role lifecycle, separation from Organization membership, and append-only audit contract will authenticate Platform Administrators for the initial service? The decision must keep `/admin/platform` private, make every Organization/connection/workload-control mutation attributable, and define a reviewable break-glass path without treating platform staff as customer members.