Saltar al contenido principal

Enterprise customer onboarding

Procedure for taking a signed enterprise customer from "contract signed" to "org live with entitlements resolved". Everything runs through the admin UI (audit-first; mutations are step-up-MFA gated).

Feature flag: customer_management_enabled must be ON in the target environment — while OFF the /customers mutations answer 501 and only reads work (shadow-verification mode).

Prerequisites​

  • The customer's Organization exists (/admin/accounts → create, or data.tenancy.create_organization), with the correct tenancy_strategy (database_per_enterprise for BYOC/high-security customers).
  • A BillingAccount exists for the org (plan tier + seat ceiling — the invite/SCIM paths enforce against it).
  • You hold manage:tenants and have step-up MFA available.
  • For SSO customers: their IdP details (Entra tenant id, or Okta/SAML metadata).

Steps​

  1. Create the customer record — /customers → New customer: org_id, display name, account-owner email. Segment defaults to enterprise; lifecycle starts at prospect.
  2. Advance lifecycle to onboarding (detail page → Lifecycle selector).
  3. Create the contract — customer detail → New contract: pick the plan (enterprise for BYOC customers — only that seeded plan carries byoc_deployments: true), set status active, seats per the order form. Activating a contract auto-expires any previously active one. Per-deal deltas go in entitlement_overrides (key-by-key overrides of the plan catalog, e.g. {"max_deployments": 5}).
  4. Verify resolved entitlements — the detail page's Resolved entitlements table must show the plan ∪ overrides you expect (byoc_deployments, kb_federation, live_trading, seats_max, max_deployments). These drive license issuance and self-hosted feature gating.
  5. Wire identity — per the customer's IdP:
    • Entra: /admin/accounts → tenant linking (EntraTenantLink promote).
    • Okta / SAML / generic OIDC: create the IdP connection (POST /tenancy/orgs/{org_id}/idp-connections), map groups → roles.
    • SCIM customers: hand over the SCIM endpoint + token.
  6. Seats — confirm BillingAccount.seat_limit matches the contract seats; invites beyond the ceiling are rejected.
  7. (Licensed self-hosted / BYOC customers) issue the first license lease — follow license-issuance-and-revocation.
  8. Advance lifecycle to active.

Post-action verification​

  • /customers list shows the customer active with the right plan.
  • Audit ledger contains admin.customers.create, admin.customers.contracts.create, and the lifecycle updates, each with your subject + step-up.
  • A user from the customer's IdP can sign in and lands in the right org with the mapped role.

Escalation​

  • Entitlements not resolving → check the contract is active and the plan is is_active in /customers/plans.
  • IdP sign-in failing → identity-service logs; see break-glass only for full lockouts.