Concepts
Auth & JWT
Identity, tokens, and system-user simulation.
Authentication uses JWT. A token encodes the user and their organization, and per-request context is populated from it.
There are two user shapes:
- Organization users — belong to a single tenant.
- System users — cross-tenant, with no fixed organization.
A system user can enter simulation for a specific organization and then act as if inside that tenant. Simulation is explicit, reversible, and audited (enter/exit events are recorded), so cross-tenant access always leaves a trail.