A tenant is one customer of Shokoofa. This article explains how a tenant is provisioned, suspended, given apps and deleted.
Provisioning a tenant
Open Platform → Tenants → Provision tenant and fill in:
- Key: the tenant's permanent identifier. It starts with a lowercase English letter and has 2 to 30 lowercase letters or digits. Reserved words such as
platform,admin,apiandconsoleare refused. The key never changes and is never given to another tenant, even after deletion, so choose it carefully. - Display name: the name people see; it can be changed later.
- Owner's email: the owner is invited when provisioning finishes and becomes the tenant's first owner. It can't be the address of Shokoofa platform staff (see The owner).
- Apps and seats: the apps the tenant may use. A new tenant has none until you enable them: a tenant gets an app only when the platform enables it. Console, Peyk and Avand are not tenant apps; every person has them on their own account. A seat limit caps how many members can use an app; leave it empty for no limit.
- Plan and deployment mode: the commercial plan's name and how the data is hosted.
Provisioning continues in the background. The tenant's page shows each step as it completes: the tenant record, the groups in the identity service, asking each app to prepare, all apps ready, the owner invited, and the tenant active. The page updates by itself.
When provisioning stalls
If an app does not answer in time, the page shows what went wrong and a Retry provisioning button. Retrying asks the apps to prepare again; apps that are already ready are not affected.
If the suite's message bus is off, the apps cannot be asked to prepare at all. Provisioning then goes on without them: the step reads Apps not notified, each app shows a Not notified badge, and the apps pick the tenant up as soon as the bus is enabled.
If provisioning failed for good (for example the key was mistyped), Abandon provisioning removes the tenant's groups from the identity service and deletes the record at once. Give a reason; it is kept in the audit log. The key can never be used again.
The owner
The tenant's page shows the Owner card: the address the owner invitation went to, when it was sent, and whether it is still waiting, was accepted or expired. The invitation link is valid for 72 hours.
Platform staff can't own a tenant. Anyone with a platform role (owner, operator, support, security or billing) holds no role in customer tenants, so an invitation to them could never be accepted. Console refuses such an address when you provision a tenant, and the card shows a Platform staff warning on any earlier invitation that went to staff. Ask the customer for a different, non-staff person to be the owner.
To invite someone else, or to resend an invitation that expired or could not be sent, choose Change owner invitation and enter the new owner's email (you need the provisioning permission). The pending invitation is revoked and a new one is sent; if the person has no account yet, they receive an email to set one up. While provisioning has not reached the owner step, only the address changes and provisioning invites it. A tenant that is being deleted keeps its owner.
Suspending and reinstating
Suspending a tenant stops its members from using its apps until it is reinstated; nothing is deleted. Give a reason (for example an unpaid invoice or a security incident); it is kept in the audit log.
Apps, seats and settings
On the tenant's page you can turn apps on or off and change seat limits. Turning an app off keeps its data. When an app is enabled, the tenant's owners and administrators get it at once (their roles include each app's administrator role); members get it when a tenant administrator gives them the app's role, and new invitations follow the tenant's default roles. Each enabled app shows Ready once it has prepared the tenant.
Announce to apps sends an active or suspended tenant's current details (apps, seats and settings) to every app again. Use it when an app doesn't know the tenant, for example because it was connected to the suite's message bus after the tenant was created. Apps that already know the tenant only update it, and nothing is deleted. Each app shows Waiting for the app until it answers, then Ready. The Settings section shows every tenant setting from the Shokoofa catalog; the platform changes only the resource limits and the data region, and every change needs a reason. The tenant's own administrators change the rest.
Deleting a tenant
Deletion is protected by the two-person rule:
- A deletion is requested either by the tenant's owner, or by a platform operator with a documented legal or contractual basis (for example a contract clause or a court order).
- Two different platform operators must approve it. The person who requested the deletion cannot approve it, and the first approver cannot also give the second approval. The page shows who approved and hides the approve button from anyone who may not approve.
- The second approval schedules the deletion 30 days later (the grace period) and notifies the tenant's owners. Before approving, you type the tenant key to confirm.
Restoring during the grace period
Until the deletion date, a platform operator (or the tenant's owner) can restore the tenant with everything in it. It returns to the state it had before, active or suspended. After the grace period the data is removed from every app and cannot be recovered.