Control Packs · IDN-003 · v1.0.0
Tenant-Scoped Authority
Keep automated authority inside an explicit tenant, workspace, or organization boundary.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Bind identity, authorization, resource lookup, and audit records to an explicit tenant boundary.
- Automated authority crosses a tenant boundaryA tool or service can access another tenant's resources because tenant scope is inferred, omitted, or checked only after the action.
Versioned applicability rule
{
"all": [
{
"characteristic": "MULTI_TENANT",
"equals": true
},
{
"characteristic": "TOOL_ACCESS",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- How is tenant scope established and enforced for every automated tool call?Tenant isolation cannot rely on an implicit request field or a late display check.IDN-003-Q1 · scope
Requirements for the coding agent
- IDN-003-R1Require an explicit tenant context, enforce it at authorization and data access boundaries, and test cross-tenant denial paths.
Tests and evidence to retain
- TENANT_ISOLATION_TESTVerify same-tenant access, missing context, forged context, cross-tenant read, and cross-tenant write denial.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-3 · Access EnforcementNIST_SP_800_53_5_2_0 · partially addressesExplicit tenant context and cross-tenant denial support access enforcement at the tool boundary; they do not cover every access path.
- AC-4 · Information Flow EnforcementNIST_SP_800_53_5_2_0 · partially addressesTenant-scoped data access constrains selected information flows; it does not establish complete flow enforcement.
- PT-5 · Processing Personally Identifiable InformationNIST_SP_800_53_5_2_0 · partially addressesTenant context reduces inappropriate cross-boundary processing; it does not establish privacy compliance.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_LEAST_AUTHORITY
- National Institute of Standards and Technology — Privacy FrameworkGUIDANCE_DATA_MINIMIZATION
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0