CANONICAL PRODUCT LANGUAGE

One shared dictionary for clients, partners, developers and support.

Use these meanings consistently in the website, portal, API, documentation, onboarding, quotations, UAT and incident reports.

A–C

Access request

A time-bound integrator request for a client permission not currently granted. It records permission, reason, decision and expiry.

Alert

A time-stamped condition requiring awareness or action, such as high capacity, offline connector, backup failure or credential expiry.

Alembic

The database migration framework used by the production FastAPI service.

Analyse

The first Smart Space Manager stage. It evaluates capacity, policy and metadata without deleting files.

API credential

A tenant-bound machine credential for connectors or integrations. It is never a human portal password.

API health

A lightweight process response. It does not prove that all production dependencies are ready.

API readiness

A dependency check covering PostgreSQL, Valkey and the command-signing key.

Archive

A controlled copy or move of approved files to a retention and recovery destination.

Archive verification

Validation of expected files, bytes, checksums and restore access before reclaim.

Audit event

A record of actor, tenant, object, action, result and time. Important audit records should be tamper-evident.

Axon Platform Admin

An internal Axon role responsible for the whole platform, tenants, integrators, releases and security operations.

Backup evidence

The backup file, checksum, archive-readability result, off-server status and restore-test record.

Billing owner

The party responsible for the client subscription. In the integrator model, this is always the client.

Blind deletion

Removing files without verified archive, policy, approval and recovery evidence. 1ProNAS must not do this.

Burn-in

A timed non-destructive stability test checking health, restarts, database readiness and resources.

Capacity forecast

An estimate of when a volume will reach warning or critical usage based on observed growth.

Client

The organisation owning a tenant, subscription, data, settings and connector identities.

Client Free Forever

Exactly one NAS and one client user at USD 0/month.

Client context

The server-authorised tenant currently selected in an integrator session.

Client tenant

A logically isolated environment containing client users, NAS devices, settings, credentials, jobs and audit.

Connector

A customer-side outbound agent that reports state and performs approved local operations.

Connector pairing

The short-lived single-use process binding one connector to one client tenant.

Control plane

The SaaS service coordinating policies, recommendations, approvals, jobs and audit without directly mounting customer files.

Cross-tenant isolation

The guarantee that one tenant or partner assignment cannot access another tenant without authorisation.

D–I

Delegated permission

A client-approved permission granted to an integrator relationship or assigned technician.

Deny by default

Access is unavailable until explicitly granted and validated.

Disaster recovery

The procedures and independent copies needed to restore service after major failure or data loss.

Dry run

A non-destructive simulation showing planned actions, files, totals and exceptions.

Email OTP

A short-lived, hashed, single-use code delivered to a verified email address for human login.

Entitlement

The server-enforced NAS, user and feature allowance derived from the client subscription.

File reclamation

Removal of a source copy only after archive, verification, policy, grace period and approval pass.

Free integrator account

The Integrator / MSP Partner workspace at USD 0. It does not transfer client billing to the partner.

Grace period

The time after successful verification during which the source remains available before reclaim.

Human account

A portal identity using OTP, secure browser session and optional passkey, not an API key.

Idempotency

Processing duplicate copies of the same external event without applying the business change twice.

Integrator

An approved external IT organisation authorised by clients to support assigned NAS environments.

Integrator client link

The database relationship connecting one integrator to one client tenant.

Integrator Free Forever

The partner workspace at USD 0, separate from client subscriptions.

Integrator Technician

A partner user restricted to explicitly assigned clients and delegated permissions.

Invitation

A short-lived, single-use request to join a company, tenant or client-integrator relationship.

J–P

Legal hold

A rule blocking archive or reclaim for files subject to legal, regulatory or investigation requirements.

Link status

The state of an integrator-client relationship, such as pending, active, revoked or suspended.

Localhost binding

A port available only on the server itself, such as 127.0.0.1:3010, 3020 or 3030.

Machine credential

An API or connector identity used by software, not a human login.

Metadata

Information about files, devices or operations. Metadata is still client data and must remain tenant-scoped.

MSP

Managed Service Provider, covered by the Integrator / MSP Partner model.

Multi-client dashboard

An integrator view of assigned clients that never merges underlying tenant credentials or ownership.

NAS count

The NAS devices entitled inside one client tenant. Portfolio totals are not billed to the integrator.

Nonce

A unique command value persisted by the connector to prevent replay.

Off-server backup

An encrypted backup stored outside the production VPS or failure domain.

Outbound-only connector

A connector initiating secure communication without exposing SMB, NFS or NAS administration publicly.

Partner commission

An optional Axon-funded payment or credit, disabled by default and not guaranteed.

Passkey

A phishing-resistant human authentication credential offered after verified activation.

Permission

A server-enforced authorisation for a specific action.

Pilot API

The SQLite fallback service on localhost port 3020.

Platform fee

A client paid-pricing component. It does not apply to the free integrator account.

Preflight

The automated release gate for Git, containers, routes, migration, database, cache, TLS, resources and restore evidence.

Primary integrator

The one active permanent integrator linked to a client in the first release.

Production API

The PostgreSQL and Valkey service on localhost 3030 and the public API hostname.

Protected path

A folder excluded from archive or reclaim by policy.

Q–Z

Quiet hours

A local-time interval suppressing normal alerts while preserving configured critical escalation.

Rate limit

A server-side request limit by user, integrator, tenant, credential or IP.

Reclaim

The final Smart Space stage allowing source removal only after every safeguard passes.

Recommendation

A reviewable proposal from analysis, not an automatic command.

Replay attack

Reusing a valid signed command or token. Expiry and nonce tracking prevent replay.

Restore test

Restoring the latest PostgreSQL backup to a temporary database and verifying schema and readability.

Revocation

Immediate disabling of a credential, session, connector, assignment or relationship.

Role

A named permission group. Role does not bypass tenant, relationship or assignment checks.

Secret reference

The environment or secret-store name saved instead of the raw provider secret.

Secure browser session

A server-managed human session using Secure, HttpOnly, SameSite cookies, rotation and revocation.

Sensitive action

An action requiring stronger permission or approval, such as billing, archive approval or reclaim.

Signing key

The private Ed25519 key used to sign connector commands. It must never be exposed.

Smart Space Manager

The 1ProNAS capacity and file-lifecycle control plane.

Staff assignment

The link granting one integrator user access to one integrator-client relationship.

Step-up verification

Recent authentication or an extra check required before a sensitive action.

Subscription status

The state controlling client entitlements, such as free, active, past due, suspended or cancelled.

Support window

The period during which temporary integrator permissions remain valid.

Tenant filter

A mandatory database query condition limiting results to the authorised client.

Tenant API key

A machine credential limited to one tenant and scopes, never a portal password.

UAT

User Acceptance Testing. The checklist separates testable functions, required evidence and unfinished features.

User count

Client human users counted for client pricing. Integrator and Axon users are excluded.

Valkey

The authenticated production cache and rate-limit service with append-only persistence.

Verification

The stage proving expected files, bytes, checksums and restore access before reclaim.

Written launch approval

A recorded decision by Amit authorising the next launch stage after evidence review.

Zero-trust relationship check

Validating identity, link, assignment, permission and tenant on every request.

Canonical statements

Integrator account: Free Forever at USD 0.
Client subscription: owned and paid by the client.
Client data ownership: always the client.
Integrator service fees: separate from 1ProNAS billing.
Tenant API keys: machine credentials, never human passwords.
Smart Space workflow: Analyse -> Recommend -> Approve -> Archive -> Verify -> Reclaim.
No blind automatic deletion.
One primary integrator per client in the first release.
Every client and every NAS keeps a separate tenant-bound identity.