# Enterprises, tenancy and organization workspaces

One product serves many organizations; a single sign-in never means holding all of any organization's data. Organization, permission and data boundaries come first; deeper enterprise collaboration follows step by step.

> Document ID: MYRILUM-DOC-ARCH-013
> Document type: concept
> Product: NOT_APPLICABLE
> Version: 0.1.0
> Region: GLOBAL
> Visibility: PUBLIC
> Publication: PUBLISHED_GLOBAL
> Content maturity: DRAFTED
> Governance: APPROVED
> Capability state: IN_DEVELOPMENT
> Availability: NOT_AVAILABLE
> Authorization: PUBLIC_INFORMATION
> Freshness: CURRENT
> Safety class: INFORMATIONAL
> Owner: Web3Capital Documentation Steward
> Approvers (assignment only; not approval evidence): Stephen
> Canonical authority: SRC-ARCHITECTURE-ATLAS-V2-2
> Source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a
> Content digest: 3ca63810e65600ebcb0547ddbe996db57ccabb7f1c265c6ff3091d7c1add90ce
> Effective: NOT_SET
> Expires: NOT_SET
> Last verified: 2026-09-23
> Review due: 2026-10-23
> Command authority: NONE
> Canonical URL: /en/architecture/enterprise-and-tenancy

<a id="overview"></a>

## What this map shows

![Enterprises, tenancy and organization workspaces diagram (A13)](/figures/atlas-v2-2/A13.png)

*MYRILUM architecture map v2.2 · A13 (public edition). Labels are in Chinese; every element is listed in English below. Select the diagram to open it at full size.*

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

One product can serve many organizations; a single sign-in never means owning all of any organization's data.

First get organization, permission and data boundaries right, then deepen enterprise collaboration step by step.

<a id="part-1"></a>

## Organizations and identity

| Field | Value |
|---|---|
| Organization | Legal and business details are kept apart from platform identifiers |
| Tenant boundary | Owns data, access, keys and run policies |
| Workspace | Scope of projects, materials, members and organization knowledge |
| Members and roles | Invitation, joining, permissions, revocation and leaving |

> **A user is not a company** — One person can belong to several organizations; every action states the current principal, space and resource.

<a id="part-2"></a>

## Enterprise work and resources

| Field | Value |
|---|---|
| Projects and delivery | Tasks, approvals, artifacts, evidence, acceptance and archiving |
| Budgets and procurement | Department and project credits; procurement kept apart from authorization |
| Organization knowledge | Authorized import, permissions, indexing, updates and deletion |
| Enterprise system connections | CRM, ERP and other systems connect as needed through connectors |

> **Isolation along the whole chain** — Databases, files, caches, search, queues, logs, temporary directories and admin surfaces all must be tested.

<a id="part-3"></a>

## Cross-organization collaboration by explicit sharing

| Field | Value |
|---|---|
| Sharing request | Resource, purpose, receiving organization, actions and time limit |
| Approval and grant | The data side and the executing side each confirm their responsibilities |
| Checked again at run time | Member, resource, purpose, permission and validity |
| Revocation and completion | Stops new access; handles copies, caches and handoffs |

> **The enterprise edition does not rebuild all software** — Existing enterprise systems are connected first; whether to build a business module ourselves depends on real needs and contracts.

<a id="part-4"></a>

## The enterprise lifecycle

| Field | Value |
|---|---|
| Onboarding | Contract, region, identity and data policy are checked |
| Ongoing management | Seats, cost, support, audit and risk |
| People and structure changes | Leavers, mergers and inherited permissions are handled explicitly |
| Export and closure | Data export, ending tasks, and revoking keys and permissions |

> **Membership is not administration** — A paid seat only provides product entitlements; system administrators, approvers and data owners hold separate permissions.

<a id="source"></a>

## Source

This page follows A13 of the MYRILUM architecture map v2.2 (public edition: restricted products and internal open items are left out). Related: “Identity, authorization and access decisions”; “Data and memory lifecycle”; “Regions, disaster recovery and exit”.

---

This document is read-only, grants no command authority, and does not authorize deployment, payment, provider modification, or any other real-world action.
