Aglet

Prioritize cross-tenant webhook routing risks

Tenant routing should queue by boundary risk before event volume. A missing label that safely quarantines is different from a valid event written under another tenant. Weigh identity evidence, shared handler reach, resource reuse, and recovery authority. Keep resource ownership evidence attached during review.

Decide where the work belongs

  1. Map boundary consequence

    For each event, record tenant evidence, resource key, operation, route, record state, and side effect. Separate unknown route from confirmed cross-tenant write. Attach event and subscription identities separately, and identify the mapping revision that selected the destination tenant for that delivery.

  2. Compare containment

    Assess quarantining, explicit subscription mapping, tenant-scoped lookup, current-state review, or correcting a cache. Record owners and replay rules. Do not fall back to global or current-user context to keep processing moving.

  3. Set routing order

    Queue confirmed wrong-tenant effects and shared ambiguous handlers first, then missing labels and isolated lookup gaps. Set owner, fixture, review time, and evidence threshold. Keep resource-key normalization behind tenant identity proof.

What to carry forward

Return a routing queue with tenant evidence, effect exposure, endpoint reach, containment, owner, and reconciliation proof. Escalate cross-tenant writes. Keep rank provisional when subscription or resource ownership is incomplete. Keep cross-tenant effects ahead of event volume before replay.

Technical background: GitHub documentation.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow