Admits the issuer into the effective trust set of every tenant on the
deployment, effective on the very next request.
This is the verb that actually widens what the deployment will accept a token from, which is why declaring and enabling are separate acts. Nothing here is written per tenant: a tenant's trust set is composed at read time as the deployment-scoped issuers union its own, so one row becoming enabled is the whole change.
Enable it after the bindings that make it useful exist. A binding may name a disabled issuer deliberately, so the natural order is declare, bind the workloads, then enable.
Never entitlement-gated. No Edition widens or narrows this plane. These are
the deployment operator's own declarations rather than a tenant's, so there is no
Edition to consult (FR-181.16).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||