Kontyra Console & Organizations
The definitive architectural manual for Kontyra Console: multi-tenant organization workspaces, departmental team separation, role-based access control (RBAC), security policies, and tamper-resistant audit trails.
1. Overview & Multi-Tenancy
Kontyra Console (console.kontyra.name.ng) is the administrative control plane for enterprises, engineering teams, and universities. It establishes clean multi-tenant isolation, separating personal developer sandboxes from shared company deployments, billing contracts, and sensitive credentials.
How personal credentials bind securely into enterprise departmental resources
User signs in with personal Passkey; accesses private DevOS sandboxes and VyntaJobs earnings.
Switch active session to corporate workspace; evaluates user membership and role (Owner / Admin / Member / Billing).
Isolates access across Engineering (DevOS sandboxes), Product (VUX events), and HR (VyntaJobs hiring).
Centralizes corporate Paystack invoicing and appends every administrative mutation to the immutable audit trail.
2. RBAC Roles & Permissions Matrix
Console enforces a strict Role-Based Access Control (RBAC) hierarchy. Permissions are evaluated on every incoming request at the API gateway layer:
| Capability / Operation | Owner | Admin | Member | Billing |
|---|---|---|---|---|
| Modify Organization Name & Delete Org | Yes | No | No | No |
| Invite & Remove Team Members | Yes | Yes | No | No |
| Deploy DevOS Edge Workspaces | Yes | Yes | Yes | No |
| Manage Payment Methods & Invoices | Yes | Yes | No | Yes |
| View Immutable Security Audit Logs | Yes | Yes | No | No |
3. Departmental Teams & Resource Scopes
Organizations with tens or hundreds of developers can segment members into departmental units:
Unrestricted access to DevOS sandboxes, deployment diffs, and serverless containers.
Manage VUX event listings, speaker schedules, attendee verification, and door scanner apps.
Post contracts on VyntaJobs, review candidate Kanban pipelines, and release milestones.
Inspect real-time audit logs, mandate Passkeys/MFA, and download compliance packages.
4. Member Invitation & Lifecycle
Inviting team members generates a cryptographically signed invitation token sent via email:
curl -X POST https://api.kontyra.name.ng/v1/orgs/org_98f12a/members \
-H "Authorization: Bearer test-kontyra-key" \
-H "Content-Type: application/json" \
-d '{
"email": "sarah@acme.corp",
"role": "admin",
"department": "Engineering"
}'5. Tamper-Resistant Audit Trail
Every administrative, authentication, or billing operation automatically creates an append-only audit event in Cloud Firestore:
{
"id": "aud_1082a7bc",
"orgId": "org_98f12a",
"actorId": "usr_99214b",
"actorEmail": "admin@acme.corp",
"action": "member.role_updated",
"target": "sarah@acme.corp",
"previousValue": "member",
"newValue": "admin",
"ipAddress": "197.210.84.12",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)",
"timestamp": "2026-10-03T04:12:00.000Z"
}6. Security Policies & SSO Enforcement
Organization owners can enforce security guardrails that supersede personal user settings:
- Mandatory WebAuthn / Passkeys: Disallows password-only logins for all members.
- Session Inactivity Timeout: Automatically terminates browser sessions after 15, 30, or 60 minutes of inactivity.
- Domain Restriction: Restricts invitation acceptance exclusively to verified email domains (e.g.
@acme.corp).
7. Quota Allocation & Billing Bounds
Prevent unintended cost overruns by setting departmental hard limits on DevOS CPU compute hours, storage bandwidth, and VUX attendee seats.
8. Organization REST API Reference
Lists organizations the authenticated user belongs to.
Lists members and their active roles (owner, admin, member, billing).
Invites a member to the organization with a designated role.
Queries the immutable audit log with filters for actor, action, and date range.