Independent realm
Platform tokens use a Platform-only issuer, audience, client, and host-only session cookie.
Enforced boundaries
Platform tokens use a Platform-only issuer, audience, client, and host-only session cookie.
No Platform token is accepted by Tenant APIs. Support access uses an audited, one-time handoff.
Updates require a Tenant-approved, current grant. Signing, approvals, Regulatory Controls, and immutable records remain prohibited.
Every support session retains the actual KAATS Administrator identity.