| Situation | What you do | What you maintain |
|---|---|---|
| Warehouse supports per-member auth | Route identity through (Module 1) | Nothing new — your existing policies |
| Shared service account, policies exist in the warehouse | Mirror them into guards + drift watch (Module 4) | The mirror, reviewed like a firewall |
| Embedded / external users | Fail-closed guards keyed to trusted scope (Module 3) + TQL-only | The guards + the test suite |
The capstone
Prompt
Where to go from here
- Admin & Governance — the console-side dials, SSO/SCIM, and audit drills.
- Ontology Operations — running governed surfaces in production, review routing, golden datasets.
- The Context Stack — the behavioral layer: personas whose allowed surfaces match your enforced ones.
- Embed TextQL in Your Product — where the tenant-scoped guard pattern earns its keep.