KAATS PlatformControl plane

Enforced boundaries

Security controls

Independent realm

Platform tokens use a Platform-only issuer, audience, client, and host-only session cookie.

Brokered Tenant access

No Platform token is accepted by Tenant APIs. Support access uses an audited, one-time handoff.

Default read-only

Updates require a Tenant-approved, current grant. Signing, approvals, Regulatory Controls, and immutable records remain prohibited.

No impersonation

Every support session retains the actual KAATS Administrator identity.