What this guide covers: what Tenant Enforcement actually controls, and why both enabling and disabling it go through a deliberate, reason-required flow.
Two independent switches
Found at Authority Administration → Tenant Enforcement. Two toggles, each with its own three-row status table:
- Direct-Jurisdiction Enforcement — strict per-officer jurisdiction checking.
- Role-Scope Enforcement — strict per-role scope checking.
Each shows three layers: Environment capability (whether it's even permitted in this deployment), Tenant configuration (whether this tenant has opted in), and Effective (whether it's actually active right now — which can read false even if you've opted in, if the environment capability itself isn't permitted).
EnablingEnabling enforcement
Enabling either one requires running its migration readiness report first. Direct-Jurisdiction Enforcement's report buckets every officer into: already direct, copy from institution, needs review (ambiguous operational), needs review (conflicting), or would lose all access — and activation is blocked until conflicts are resolved. The server re-verifies this regardless of what the client-side report says, so there's no way to force it through a stale preview.
DisablingDisabling enforcement
Disable on either switch requires a reason and a confirmation dialog — it's framed deliberately as a security-sensitive rollback, not a harmless reset, because disabling either one widens what officers across the tenant can see.