Governance UX per EXP-002 / PROP-005 / ADR-037. Federation summaries are read-only; Keycloak remains operator-controlled (ADR-028). Commercial posture is versioned and agreement-linked when policy rows exist (SPEC-019).

Session actor (development)

Set headers sent to the admin API. In production, replace with authenticated identity and OIDC claims (finance: finance_operator per SPEC-027).

tenant_admin, partner, and partner_operator require tenant scope.

  • Federation runbooks live under specifications/QueryTek Tapestry/08_Docs_Playbooks.
  • Segregation of duties for commercial mutations: ADR-037.
  • Revshare exports — settlement and engagement CSVs (SPEC-027 / EXP-006).