Prompt file imported from Zynapses/Radiant (
.windsurf/workflows/licensing-enforcement.md). Copyright stays with the author.
Licensing Enforcement Policy (Bidirectional)
CRITICAL: This policy enforces licensing in BOTH directions:
- Direction A: New app → MUST implement licensing, roles, admin UI, sidebar entry
- Direction B: New license type → MUST propagate to all existing apps, APIs, and admin UIs
When This Applies
This policy applies when:
- Adding new API endpoints to ANY app
- Adding new features to any user-facing app
- Adding new regulatory/compliance features
- Adding new apps to the platform (Direction A)
- Adding new license types to
license_catalog(Direction B) - Modifying user invitation or provisioning flows
- Any change that could be gated by a license
- Any change to roles or permissions
Rules
1. Every API Endpoint Must Check Licensing
All API endpoints in user-facing apps MUST use the license middleware:
const license = await checkLicense(user.tenantId, user.userId, {
app_id: 'think_tank', // Which app
check_seat: true, // Verify user has a seat
check_feature: true, // If feature-gated
feature_code: 'hipaa', // Which feature license
});
if (!license.allowed) return forbidden(license);
2. Regulatory Features Are Licensed
ALL regulatory standards (HIPAA, GDPR, SOC2, CCPA, ISO 27001, etc.) are licensable features:
- If tenant has no license → feature DISABLED
- UI shows: "Contact Think Tank support at support@thinktank.app"
- API returns 403 with
LICENSE_REQUIREDerror - NEVER enable compliance features without checking the license
3. Seat Licensing Per App
- Each app has its own seat count per tenant
- Active users consume seats; deactivated users FREE seats
- Invitation checks seat availability BEFORE creating user
- Think Tank seat granted by default; other apps require explicit activation
4. Unlicensed Feature UI Pattern
When a feature requires a license the tenant doesn't have:
⚠ [Feature Name]
This feature requires a [LICENSE_NAME] license.
To add this license, contact Think Tank support at support@thinktank.app
[Contact Support]
5. Direction A: Adding New Apps (COMPREHENSIVE)
When adding a new app to the RADIANT platform, ALL of the following MUST be completed:
Database & Backend (Required)
- Add
seat:<app_id>row tolicense_catalogtable (migration) - Add
has_access_<app_id>boolean touserstable (migration) - All API endpoints use license middleware with new
app_id - Add Lambda handler in
lambda/admin/<app>.tswith standard admin API pattern - Add CDK stack or Lambda function config in
packages/infrastructure/
Admin Dashboard (Required)
- Add admin page in
apps/admin-dashboard/app/(dashboard)/<app>/page.tsx - Add sidebar entry in
components/layout/sidebar.tsxwith appropriate icon and section - Ensure page has full detail view (NOT just a widget/summary)
User Management (Required)
- Add to invitation UI in Think Tank Tenant Admin (app selection checkboxes)
- Add to user profile / app access toggles
- Add role definitions for the new app (at minimum: viewer, user, admin)
Swift Deployer (Required)
- Add
RadiantApplication.<appId>to Swift deployer app model - Add URL configuration (subdomain, path, icon, tier)
Settings & Configuration (Required)
- Add URL field in Admin Dashboard Settings → URLs page
- Add Quick Link in settings page
Documentation (Required)
- Update
docs/THINKTANK-LICENSING-MODEL.md(license catalog, tier defaults) - Update
docs/THINKTANK-TENANT-ADMIN-GUIDE.md(invitation flow, app access) - Update
CHANGELOG.md - Update
docs/RADIANT-ADMIN-GUIDE.md(new admin section) - Update
docs/RADIANT-PLATFORM-ARCHITECTURE.md(new pages, APIs, routes)
6. Direction B: Adding New License Types (COMPREHENSIVE)
When adding a new license type (feature, compliance, add-on), ALL of the following MUST be completed:
Database (Required)
- Add row to
license_catalogtable with:license_type,display_name,description,category,tier_defaults - If regulatory: set
is_regulatory = trueandregulatory_standardcode
API Enforcement (Required)
- Add license check to ALL API endpoints that should be gated by this license
- If the license gates existing endpoints, add middleware checks to those existing handlers
- Verify 403
LICENSE_REQUIREDresponse format is correct
UI Gating — ALL Apps (Required)
- Add UI gating in Think Tank (if user-facing feature)
- Add UI gating in Admin Dashboard (if admin-facing feature)
- Add UI gating in any other affected apps (Curator, Dojo, Cato Trainer, Genesis)
- Show unlicensed feature pattern (Section 4 above) in ALL affected UIs
- Add license to Tenant Admin → License Management page
Admin Dashboard (Required)
- If this license enables a new admin feature, create a detail page (NOT just a widget)
- Add sidebar entry for the new detail page
- Add license status indicator in Compliance → Regulatory Standards page (if regulatory)
Documentation (Required)
- Update
docs/THINKTANK-LICENSING-MODEL.md - Update
docs/THINKTANK-TENANT-ADMIN-GUIDE.md - Update tier defaults documentation
- Update
CHANGELOG.md
7. Admin Page Requirement
EVERY admin-configurable feature MUST have:
- A dedicated detail page (not just a widget on another page)
- A sidebar entry in
components/layout/sidebar.tsx- Widget summaries are fine, but MUST link to the detail page
See also: /.windsurf/workflows/admin-page-required.md
8. Role Propagation
When adding new apps or features:
- New apps MUST define roles:
viewer,standard_user,adminat minimum - Roles must be added to the
userssoft permissions JSONB structure - Role checks must be in API middleware
- Admin Dashboard must show role management for the new app
- Think Tank Tenant Admin must show role assignment in user management
Verification Checklist
Before marking any licensing-related task complete:
Direction A (New App):
□ license_catalog entry with seat:<app_id>
□ users table has_access_<app_id> column
□ All API endpoints check licensing
□ Admin dashboard page exists (detail, not widget)
□ Sidebar entry exists
□ Invitation UI updated
□ Swift Deployer model updated
□ Settings URLs page updated
□ All documentation updated
Direction B (New License):
□ license_catalog entry added
□ API endpoints gated
□ UI gating in ALL affected apps
□ Unlicensed pattern shown correctly
□ Tenant Admin license management updated
□ Admin dashboard detail page (if admin feature)
□ Sidebar entry (if new page)
□ All documentation updated
Key Documents
- Licensing Model:
docs/THINKTANK-LICENSING-MODEL.md - ADR:
docs/architecture/ADR-USER-PROVISIONING-SEAT-LICENSING-AUTH.md - Tenant Admin Guide:
docs/THINKTANK-TENANT-ADMIN-GUIDE.md - Admin Page Policy:
/.windsurf/workflows/admin-page-required.md - New App Onboarding:
/.windsurf/workflows/new-app-onboarding.md
Support Contact
All "contact support" messages MUST use: support@thinktank.app
