A tenant is one customer of Shokoofa. This article explains how a tenant is provisioned, suspended, given apps and deleted.
Provisioning a tenant
Open Platform → Tenants → Provision tenant and fill in:
- Key: the tenant's permanent identifier. It starts with a lowercase English letter and has 2 to 30 lowercase letters or digits. Reserved words such as
platform,admin,apiandconsoleare refused. The key never changes and is never given to another tenant, even after deletion, so choose it carefully. - Display name: the name people see; it can be changed later.
- Owner's email: the owner is invited when provisioning finishes and becomes the tenant's first owner. It can't be the address of Shokoofa platform staff (see The owner).
- Apps and seats: the apps the tenant may use. A seat limit caps how many members can use an app; leave it empty for no limit.
- Plan and deployment mode: the commercial plan's name and how the data is hosted.
Provisioning continues in the background. The tenant's page shows each step as it completes: the tenant record, the groups in the identity service, asking each app to prepare, all apps ready, the owner invited, and the tenant active. The page updates by itself.
When provisioning stalls
If an app does not answer in time, the page shows what went wrong and a Retry provisioning button. Retrying asks the apps to prepare again; apps that are already ready are not affected.
If the suite's message bus is off, the apps cannot be asked to prepare at all. Provisioning then goes on without them: the step reads Apps not notified, each app shows a Not notified badge, and the apps pick the tenant up as soon as the bus is enabled.
If provisioning failed for good (for example the key was mistyped), Abandon provisioning removes the tenant's groups from the identity service and deletes the record at once. Give a reason; it is kept in the audit log. The key can never be used again.
The owner
The tenant's page shows the Owner card: the address the owner invitation went to, when it was sent, and whether it is still waiting, was accepted or expired. The invitation link is valid for 72 hours.
Platform staff can't own a tenant. Anyone with a platform role (owner, operator, support, security or billing) holds no role in customer tenants, so an invitation to them could never be accepted. Console refuses such an address when you provision a tenant, and the card shows a Platform staff warning on any earlier invitation that went to staff. Ask the customer for a different, non-staff person to be the owner.
To invite someone else, or to resend an invitation that expired or could not be sent, choose Change owner invitation and enter the new owner's email (you need the provisioning permission). The pending invitation is revoked and a new one is sent; if the person has no account yet, they receive an email to set one up. While provisioning has not reached the owner step, only the address changes and provisioning invites it. A tenant that is being deleted keeps its owner.
Suspending and reinstating
Suspending a tenant stops its members from using its apps until it is reinstated; nothing is deleted. Give a reason (for example an unpaid invoice or a security incident); it is kept in the audit log.
Apps, seats and settings
On the tenant's page you can turn apps on or off and change seat limits. Turning an app off keeps its data. The Settings section shows every tenant setting from the Shokoofa catalog; the platform changes only the resource limits and the data region, and every change needs a reason. The tenant's own administrators change the rest.
Deleting a tenant
Deletion is protected by the two-person rule:
- A deletion is requested either by the tenant's owner, or by a platform operator with a documented legal or contractual basis (for example a contract clause or a court order).
- Two different platform operators must approve it. The person who requested the deletion cannot approve it, and the first approver cannot also give the second approval. The page shows who approved and hides the approve button from anyone who may not approve.
- The second approval schedules the deletion 30 days later (the grace period) and notifies the tenant's owners. Before approving, you type the tenant key to confirm.
Restoring during the grace period
Until the deletion date, a platform operator (or the tenant's owner) can restore the tenant with everything in it. It returns to the state it had before, active or suspended. After the grace period the data is removed from every app and cannot be recovered.