874 B
874 B
Provisioning Module
The provisioning module orchestrates first-login auto-provisioning. When a user authenticates via OIDC for the first time, AutoProvision creates all governance and resource structures within a single database transaction:
- User — identity record linked to the OIDC subject
- Person — profile record (display name, email)
- Organization — personal org (
org_type = 'personal') - OrgMember — membership with the
ownersystem role - Workspace — default workspace within the org
- Role Assignment — org-scoped role assignment for the owner
- Resource Pool — default pool (
pool_type = 'default',is_auto_managed = true) - Pool Assignment — primary link between workspace and pool (
is_primary = true)
If any step fails, the entire transaction rolls back — no partial structures exist.