namespace EntitlementBLL.Options; /// /// Config for Thread 1 §2.2 (narrowed) client-identity creation. Bound from /// "Entitlement:ClientProvisioning". /// public class ClientProvisioningOptions { public const string SectionName = "Entitlement:ClientProvisioning"; /// MROLE.ROLECODE (in Entitlement's own shared platform database — NOT a /// per-tenant business-DB role) granted to the first admin user created for a brand-new /// client. Resolved 2026-08-05 (tracker §31.12) to "CLADMIN" — a new, dedicated MROLE /// row seeded via the additive migration /// 20260805_Entitlement_ClientAdminRole_Seed_{SqlServer,Postgres}.sql, deliberately NOT /// GBSUPERUSER/SystemAdmin (those are internal GB5-staff roles used by the menu-seed /// migrations, §24.2/§24.4 — a different concept from a customer's own admin role). /// Resolved by RoleCode lookup at runtime (ClientProvisioningDAL.GetRoleIdByCodeAsync) /// rather than a hardcoded numeric RoleId, so this stays correct across environments — /// any install just needs the same ROLECODE seeded, no per-install ID to re-resolve. /// Empty/whitespace = not configured; CreateClientAsync throws rather than silently /// inserting an invalid FK value. public string DefaultAdminRoleCode { get; set; } = "CLADMIN"; }