Skip to content

feat(organisations): organisation reach, picker and admin screen (PPT-2702) - #319

Draft
camreeves wants to merge 1 commit into
developfrom
PPT-526-tenancy
Draft

camreeves wants to merge 1 commit into
developfrom
PPT-526-tenancy

Conversation

@camreeves

Copy link
Copy Markdown
Contributor

Backoffice half of multi-tenancy (PPT-2702, under PPT-526). Pairs with PlaceOS/rest-api#451, PlaceOS/ts-client#31 and PlaceOS/models#332. Draft until the set has been through a clean install on the test cluster.

What this does

  • Reach bootstrap. After the support groups load, Backoffice reads GET /organisations/current once. An API without that route behaves exactly as today (cluster reach, nothing hidden).
  • Organisation picker in the sidebar, next to the support-group picker and built the same way: cluster staff choose any organisation or all, partner staff choose among their partner's organisations, organisation admins see no picker. The choice persists per user and narrows every list through organisation_id.
  • Scoped lists. The system, zone and module query wrappers and the domain, user, trigger, zone and system actions pass the selected organisation. The API scopes to reach regardless; the picker only narrows further.
  • Admin > Organisations. Partners and organisations tables with add, edit and remove for cluster staff, read-only for partner staff. "Claim unowned zones" adopts root zones no organisation owns, with their systems and modules. The page states the caller's reach and whether the API is enforcing or logging.
  • Cluster-only screens (Repositories; Admin tabs Database, Clusters, Interfaces, Brokers, Extensions, Schemas, Build jobs) are hidden from partner and organisation admins. Drivers stay visible because organisation admins create modules from them.
  • Domain form gains an owner select for cluster staff; the About tab names the owning organisation.
  • Vocabulary. The two strings that said "Authority" now say "Domain".

ts-client dependency

bun installs git dependencies without their dev tooling, so it cannot build ts-client from its source branch. package.json therefore pins @placeos/ts-client to a commit on PPT-526-tenancy-dist, a disposable branch holding the built output of PPT-526-tenancy. Once ts-client#31 merges and publishes, this goes back to a version range and the dist branch is deleted.

Verification

  • Unit tests: 87 files, 1016 tests pass, including a new spec for the reach state (cluster, partner and single-organisation shapes, persistence, cluster-only screens).
  • nx build clean.
  • Not yet driven in a browser against the enforcing API: that is the test-cluster pass in the plan's section 4b.

Plan: https://gist.github.com/camreeves/3fabfff92bcdef77a1dcb4b8d8ebfe7b

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
backoffice Ready Ready Preview Oct 7, 2026 4:27am UTC

…-2702)

Reads the caller's reach after login, adds an organisation picker that
narrows every list, an Admin > Organisations page for partners,
organisations and claiming unowned zones, hides cluster-only screens from
partner and organisation admins, and lets cluster staff set a domain's
owner. ts-client comes from the built PPT-526-tenancy-dist branch until
ts-client#31 publishes.

This branch was successfully deployed

1 active deployment
Preview — 6c851365 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant