namespace EntitlementBLL.Options;
///
/// Config for Thread 1 §2.2 (narrowed) client-identity creation. Bound from
/// "Entitlement:ClientProvisioning".
///
public class ClientProvisioningOptions
{
public const string SectionName = "Entitlement:ClientProvisioning";
/// MROLE.ROLECODE (in Entitlement's own shared platform database — NOT a
/// per-tenant business-DB role) granted to the first admin user created for a brand-new
/// client. Resolved 2026-08-05 (tracker §31.12) to "CLADMIN" — a new, dedicated MROLE
/// row seeded via the additive migration
/// 20260805_Entitlement_ClientAdminRole_Seed_{SqlServer,Postgres}.sql, deliberately NOT
/// GBSUPERUSER/SystemAdmin (those are internal GB5-staff roles used by the menu-seed
/// migrations, §24.2/§24.4 — a different concept from a customer's own admin role).
/// Resolved by RoleCode lookup at runtime (ClientProvisioningDAL.GetRoleIdByCodeAsync)
/// rather than a hardcoded numeric RoleId, so this stays correct across environments —
/// any install just needs the same ROLECODE seeded, no per-install ID to re-resolve.
/// Empty/whitespace = not configured; CreateClientAsync throws rather than silently
/// inserting an invalid FK value.
public string DefaultAdminRoleCode { get; set; } = "CLADMIN";
}