KontyraKontyra Docs
Organization Hub•console.kontyra.name.ng

Kontyra Console & Organizations

The definitive architectural manual for Kontyra Console: multi-tenant organization workspaces, departmental team separation, role-based access control (RBAC), security policies, and tamper-resistant audit trails.

1. Overview & Multi-Tenancy

Kontyra Console (console.kontyra.name.ng) is the administrative control plane for enterprises, engineering teams, and universities. It establishes clean multi-tenant isolation, separating personal developer sandboxes from shared company deployments, billing contracts, and sensitive credentials.

Multi-Tenant Isolation & Departmental Scoping

How personal credentials bind securely into enterprise departmental resources

Pipeline Flow
Personal Developer IdentityIndividual Tier
alex@kontyra.name.ng

User signs in with personal Passkey; accesses private DevOS sandboxes and VyntaJobs earnings.

Organization Context SwitcherMulti-Tenant RBAC
org_98f12a (Acme Corp)

Switch active session to corporate workspace; evaluates user membership and role (Owner / Admin / Member / Billing).

Departmental Resource MeshDepartment Units
Scoped Permissions

Isolates access across Engineering (DevOS sandboxes), Product (VUX events), and HR (VyntaJobs hiring).

Enterprise Governance & Audit LogCompliance
Immutable Audit Trail

Centralizes corporate Paystack invoicing and appends every administrative mutation to the immutable audit trail.

2. RBAC Roles & Permissions Matrix

Console enforces a strict Role-Based Access Control (RBAC) hierarchy. Permissions are evaluated on every incoming request at the API gateway layer:

Capability / OperationOwnerAdminMemberBilling
Modify Organization Name & Delete OrgYesNoNoNo
Invite & Remove Team MembersYesYesNoNo
Deploy DevOS Edge WorkspacesYesYesYesNo
Manage Payment Methods & InvoicesYesYesNoYes
View Immutable Security Audit LogsYesYesNoNo

3. Departmental Teams & Resource Scopes

Organizations with tens or hundreds of developers can segment members into departmental units:

Engineering & DevOps

Unrestricted access to DevOS sandboxes, deployment diffs, and serverless containers.

Product & Events

Manage VUX event listings, speaker schedules, attendee verification, and door scanner apps.

Talent Acquisition

Post contracts on VyntaJobs, review candidate Kanban pipelines, and release milestones.

Security & Compliance

Inspect real-time audit logs, mandate Passkeys/MFA, and download compliance packages.

4. Member Invitation & Lifecycle

Inviting team members generates a cryptographically signed invitation token sent via email:

Invite Member via cURL
curl -X POST https://api.kontyra.name.ng/v1/orgs/org_98f12a/members \
  -H "Authorization: Bearer test-kontyra-key" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "sarah@acme.corp",
    "role": "admin",
    "department": "Engineering"
  }'

5. Tamper-Resistant Audit Trail

Every administrative, authentication, or billing operation automatically creates an append-only audit event in Cloud Firestore:

Audit Log Schema
{
  "id": "aud_1082a7bc",
  "orgId": "org_98f12a",
  "actorId": "usr_99214b",
  "actorEmail": "admin@acme.corp",
  "action": "member.role_updated",
  "target": "sarah@acme.corp",
  "previousValue": "member",
  "newValue": "admin",
  "ipAddress": "197.210.84.12",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
  "timestamp": "2026-10-03T04:12:00.000Z"
}

6. Security Policies & SSO Enforcement

Organization owners can enforce security guardrails that supersede personal user settings:

  • Mandatory WebAuthn / Passkeys: Disallows password-only logins for all members.
  • Session Inactivity Timeout: Automatically terminates browser sessions after 15, 30, or 60 minutes of inactivity.
  • Domain Restriction: Restricts invitation acceptance exclusively to verified email domains (e.g. @acme.corp).

7. Quota Allocation & Billing Bounds

Prevent unintended cost overruns by setting departmental hard limits on DevOS CPU compute hours, storage bandwidth, and VUX attendee seats.

8. Organization REST API Reference

GET/v1/orgs

Lists organizations the authenticated user belongs to.

GET/v1/orgs/:id/members

Lists members and their active roles (owner, admin, member, billing).

POST/v1/orgs/:id/members

Invites a member to the organization with a designated role.

GET/v1/orgs/:id/audit-logs

Queries the immutable audit log with filters for actor, action, and date range.