The verdict the platform console renders next to that tenant's trust configuration,
resolved SERVER-side from the deployment type and the tenant's effective Edition. It
is the SAME projection the tenant's own plane returns for the same tenant, from the
same resolution — the operator and the customer must not read two verdicts that can
disagree.
🔴 It gates nothing here. A tenant reading entitled: false is
still provisioned by a ROOT operator through this plane, and the write succeeds. The
verdict predicts what the TENANT self-service plane would do, and it tells the
operator whether the customer could also manage this themselves — which changes who
they tell, not what they may do.
resolution is required reading beside the verdict:
LICENSED means the licence answered, FLOORED means it
could not be read and the reply is the fail-closed floor. "Their edition does not
include this" and "we could not confirm their edition" send an operator to two
different people, and a bare entitled: false sends half of them to the
wrong one.
On a private-cloud or on-premise deployment the answer is always
entitled: true — the operator runs the platform and owns the workloads
that authenticate against it, so there is nothing for an ANKA-issued Edition to
entitle. On an ANKA-operated deployment it is true only for the
Enterprise edition.
It never fails with a 500: a licence outage is reported as
FLOORED, not raised. And it never becomes an authentication outage —
verification never consults this verdict, so a tenant WITHOUT the entitlement keeps
every workload that already authenticates through a declared issuer.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||