Provision tenants, promote a tenant to its own database (a silo), and approve a tenant to mint live merchant keys. Every action here is authenticated with a staff session (alyte.control audience) and written to the durable audit log.
One form. Merchant tenant creates the merchant's WorkOS org (= their tenant) and invites the owner (dev mode: provisions the tenant only, no org). Bare tenant just provisions the tenant — no org, no owner.
Send a WorkOS email invitation. Staff joins the Alyte team (admin/operator → /admin, /dashboard); Merchant owner joins a specific merchant org (→ /merchant).
The registry — every tenant, its isolation, silo status, and go-live flag. Promote a pooled tenant to its own DB and toggle its live gate right here.