The verdict the console renders, resolved SERVER-side from the deployment type and
the tenant's effective Edition. The console never re-derives it: a surface that
decided its own entitlement would be a second party deciding the same thing, and
the two would eventually disagree.
On a private-cloud or on-premise deployment the answer is always
entitled: true — the operator runs the platform and owns the workloads
that authenticate against it, so there is nothing for an ANKA-issued Edition to
entitle. On an ANKA-operated deployment it is true only for the
Enterprise edition.
resolution is required reading beside the verdict:
LICENSED means the licence answered, FLOORED means it
could not be read and the reply is the fail-closed floor. "Your edition does not
include this" and "we could not confirm your edition" send an operator to two
different people, and a bare entitled: false sends half of them to the
wrong one.
This read is deliberately NOT gated by the entitlement it reports, and it never
fails with a 500: a licence outage is reported as
FLOORED, not raised.
🔴 A tenant WITHOUT the entitlement keeps every workload that already authenticates through a declared issuer. Authentication never consults this verdict, so a licence outage cannot become an authentication outage. What the entitlement buys is the right to declare NEW trust.
Ungated. The verdict has to be readable by the tenant it is about: gating it
would mean a tenant that lost the edition could not find out why its own surface
changed.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||