Platform overview
The cross-tenant surfaces this build serves, and the rule that shapes all of them.
Tenants
Every team on the platform, their lifecycle state, and the provisioning entry point.
Search
Cross-tenant lookup by order reference, ticket reference or support reference, over platform_search_index.
Work queue
Exceptions surfaced by tenants into platform_work_items — support escalations, reconciliation, DLQ follow-ups.
There is no live cross-tenant query on this portal
Every tenant-owned table has row-level security forced on it, and the one function that opens a platform-scope transaction takes no tenant and sets exactly one setting. That is not a limitation to work around — it is the reason a bug in this portal cannot read another team’s ticket buyers.
Cross-tenant numbers come from three denormalized tables, each written inside the owning tenant’s own transaction and checked by a trigger that refuses a row whose tenant does not match the transaction’s: platform_search_index, platform_work_items and tenant_usage_rollups. Anything that fits none of the three is an operator-triggered pass over the tenant list, one tenant at a time.
Revenue and usage tiles are absent here because the rollup writer has not shipped. An aggregate with no writer behind it is a zero that reads as a number.