Secrets: Tenant policy
Catalog id: resource.secrets.tenantPolicy
The rulebook every tenant inherits, edited on the platform tenant only. It decides whether tenants may run their own secret backend, whether they may adopt platform offerings, what isolation a backend has to provide, which provider types are permitted at all, and how long a migration may keep the old backend around for rollback.
Policy refuses combinations; it does not create capability. Requiring backend-enforced isolation makes the platform decline offerings that do not implement it, but it cannot add isolation to a backend that has none.
Audience: platform operator.
Guide: Secrets and KMS providers.
What the policy contains
Read the policy in force for a tenant
GET/api/platform/config/v1/tenants/00000000-0000-4000-8000-000000000000/secrets/options200 OK- Admin Console
- Request
- Response
- Try it
Resources > Secrets > Tenant policy on the platform tenant edits the global policy and the overrides.
This capture reads the result from the tenant side, which is the reliable way to see what actually
applies to one tenant: effectivePolicy is the global policy merged with any override attached to
it, so a tenant with an override will not match what the global screen shows.
allowTenantManagedProviders decides whether a tenant may attach its own Vault or cloud secret
manager. Turning it off leaves platform offerings as the only route and gives you one operated
estate. allowPlatformOfferings is the mirror image and is rarely off outside a lockdown or a
break-glass situation.
requireBackendIsolation refuses any offering whose isolation mode does not meet the bar, which is
the control that matters on a shared Vault or a single cloud account. allowedProviderTypes keeps
unexpected backends out of a regulated deployment. retentionDays bounds how long a migration may
keep the source backend available for rollback before it is expected to be purged.
permittedOfferings in the same response is the policy applied: each entry says whether the tenant
is using it, may migrate to it, and if not, why. migrationBlockedReason names the cause rather than
leaving you to infer it.

Full schema: Secret Management API, under the Platform Admin secret-management tenant-policy routes.
Overrides
An override attaches a complete policy to one tenant, for a customer whose contract differs from the default, such as one that must run its own Vault. It replaces the global policy for that tenant rather than merging field by field, so write the whole thing.
Keep the global policy tight and the overrides few. A global policy that permits every provider type and unrestricted tenant-managed backends is the most flexible arrangement and also the one with the largest incident blast radius and the highest support cost. Pick tenants from the directory rather than typing identifiers the product cannot resolve.