Glossary
Precise definitions for every term used across this site. If a page uses a capitalized term (Entitlement, AppRole) without defining it inline, it means exactly what’s written here.
Access path
One way a User reaches an Application: their own personal Entitlement, or an org-wide grant from an Organization that includes them. Resolved access is the union of every active path. See Access Control.
API Key
A long-lived service credential (satk_live_…/satk_test_…), scoped to the platform or to one Application. An app-scoped key can only ever touch its own Application’s rows. See API Keys.
App token
The short-lived (5-minute) JWT an Application verifies locally, with aud set to that Application. Carries entitlement_status and effective_permissions. See Auth → The app token.
Application
(also “App”) One developer’s separately-hosted app (web, iOS, macOS, Windows, Linux, …) that uses Substratal Apps for its users, settings, organizations, tenancy, and storage. This is its catalog entry. See Domain Model → Applications.
AppProfile
Per-app identity data for one user — e.g. a display handle meaningful only inside that one app. Distinct from the global Profile.
AppRole
A Role scoped to one Application, defined by that app’s own catalog entry rather than by the platform. See Domain Model → Roles & Permissions.
AppSettings
Per-app configuration for one user, layered over that user’s global Settings and the Application’s declared defaults. See Workflows → Settings resolution.
Audit Event
An immutable record of who changed what access, when. See Domain Model → Orders & Audit.
Effective permissions
The resolved set of Permissions a user holds for a given Application — the union of the permissions on their app-scoped Roles for that app (explicit assignments plus the app’s default_app_role), and empty unless the User and their Entitlement are both active. Only that app’s own app.<slug>.* keys ever appear; platform Roles govern the hub, not apps. See Access Control.
Entitlement
The join record between a User (or Organization) and an Application: do they own it, and is it currently switched on. The record behind “turn an app on/off for a user.” See Domain Model → Entitlements.
Hub
Shorthand used throughout this site for Substratal Apps itself — the platform this API belongs to.
MCP
Model Context Protocol — the standard this site’s AI-agent-facing tool-call interface implements. See MCP Server. Introduces no new authorization model of its own; see Authentication — no new model.
Order
Not an entity of this API. It’s the developer’s own commerce record, in their own billing system. An Entitlement carries only an opaque order_id reference to it. See Domain Model → Orders & Audit.
Organization
A domain/grouping object for Users — a company, or a group within a company — used to organize shared admin standing and group-wide Application access. Decoupled from infrastructure placement; see Tenant and Tenant vs. Organization. Pulled into Phase 2; see Organizations.
OrganizationMembership
The join record between a User and an Organization, carrying that User’s standing within that one Organization (org_admin or member) and whether it’s pending (invited, not yet accepted) or active — a User can hold this for any number of Organizations at once. See Domain Model → Users & Organizations.
Permission
An atomic, checkable capability, written as a dotted key (billing.manage, app.timetrack.export). Never assigned directly to a user — always granted through a Role.
Plan
The commercial subscription on a Tenant: starter, team, or enterprise. Independent of Tier. See Pricing.
PlatformRole
A Role that applies across the whole hub rather than one Application — superadmin, support, billing_admin, member.
Profile
Global, cross-app identity and contact data for a User — name, avatar, email, locale. Distinct from AppProfile.
Restricted
The state of a Tenant whose subscription lapsed while its usage exceeded what it could drop to. Existing access keeps working; new usage returns 402. See Pricing → Subscription lapse.
Role
A named bundle of Permissions. Either a PlatformRole or an AppRole.
Seat
A distinct User with active resolved access to at least one Application a Tenant owns. The unit Team and Enterprise are billed on. See Pricing.
Session
One successful login (ses_…). Every refresh token and app token minted from it carries its id as sid, and revoking it ends them all. See Auth → Sessions.
Settings
Global, cross-app configuration for a User — locale, timezone, notification preferences. Distinct from AppSettings.
Tenant
The infrastructure-placement and data-isolation boundary for one of Substratal’s own paying customers — the owner of an Application’s catalog entry. shared (default), isolated, or dedicated_region. Not the same thing as Organization — see Tenant vs. Organization. See Domain Model → Tenancy.
Tier
Where a Tenant’s data physically lives: shared, isolated, or dedicated_region. Independent of Plan, except that the non-shared tiers require Enterprise.
User
A person with an account on Substratal. One identity, used everywhere in the hub and, via the Trust Model, in every app they launch from it.
Webhook
A signed HTTPS POST the hub sends an Application when something changes. access.revoked and role.removed are required subscriptions. See Webhooks.