Enterprise customer onboarding
Procedure for taking a signed enterprise customer from "contract signed" to "org live with entitlements resolved". Everything runs through the admin UI (audit-first; mutations are step-up-MFA gated).
Feature flag: customer_management_enabled must be ON in the target
environment — while OFF the /customers mutations answer 501 and
only reads work (shadow-verification mode).
Prerequisites
- The customer's Organization exists (
/admin/accounts→ create, ordata.tenancy.create_organization), with the correcttenancy_strategy(database_per_enterprisefor BYOC/high-security customers). - A BillingAccount exists for the org (plan tier + seat ceiling — the invite/SCIM paths enforce against it).
- You hold
manage:tenantsand have step-up MFA available. - For SSO customers: their IdP details (Entra tenant id, or Okta/SAML metadata).
Steps
- Create the customer record —
/customers→ New customer:org_id, display name, account-owner email. Segment defaults toenterprise; lifecycle starts atprospect. - Advance lifecycle to
onboarding(detail page → Lifecycle selector). - Create the contract — customer detail → New contract: pick the
plan (
enterprisefor BYOC customers — only that seeded plan carriesbyoc_deployments: true), set statusactive, seats per the order form. Activating a contract auto-expires any previously active one. Per-deal deltas go inentitlement_overrides(key-by-key overrides of the plan catalog, e.g.{"max_deployments": 5}). - Verify resolved entitlements — the detail page's Resolved
entitlements table must show the plan ∪ overrides you expect
(
byoc_deployments,kb_federation,live_trading,seats_max,max_deployments). These drive license issuance and self-hosted feature gating. - Wire identity — per the customer's IdP:
- Entra:
/admin/accounts→ tenant linking (EntraTenantLink promote). - Okta / SAML / generic OIDC: create the IdP connection
(
POST /tenancy/orgs/{org_id}/idp-connections), map groups → roles. - SCIM customers: hand over the SCIM endpoint + token.
- Entra:
- Seats — confirm
BillingAccount.seat_limitmatches the contract seats; invites beyond the ceiling are rejected. - (Licensed self-hosted / BYOC customers) issue the first license lease — follow license-issuance-and-revocation.
- Advance lifecycle to
active.
Post-action verification
/customerslist shows the customeractivewith the right plan.- Audit ledger contains
admin.customers.create,admin.customers.contracts.create, and the lifecycle updates, each with your subject + step-up. - A user from the customer's IdP can sign in and lands in the right org with the mapped role.
Escalation
- Entitlements not resolving → check the contract is
activeand the plan isis_activein/customers/plans. - IdP sign-in failing → identity-service logs; see break-glass only for full lockouts.