The planned scenario

SaaS Company represents a service used by multiple tenants. A tenant dashboard, administration surface, public API, and artifact browser form the public catalog. Private records cover workers and queues, internal metrics, and tenant object storage.

Review how tenant ownership should remain consistent across different kinds of information. A dashboard record, export artifact, and worker job may refer to a tenant while passing through different operational contexts. An exercise can make those relationships explicit before attempting to validate an access assumption.

Public surfaces

These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.

Public routes declared in the SaaS Company catalog
RouteSurfaceContext
/tenant-dashboardTenant user dashboard and account workflow.
/adminadmin-consoleSaaS admin and support operations surface.
/apipublic-apiPublic API facade for tenant resources.
/artifactsartifact-browserCI/CD artifact and release metadata facade.

Private systems

These service names and segments describe the internal context of SaaS Company. They help define exercise boundaries and interpret the generated records.

worker-queue

Private worker and queue simulation. Catalog segment: private application.

metrics-admin

Internal metrics and admin API. Catalog segment: private application.

object-storage

Tenant object storage and export data. Catalog segment: private application.

Configure your exercise

Choose a question for the assignment and define the evidence participants should collect.

  • How is tenant ownership represented across users, exports, audit events, and worker jobs?
  • What should distinguish a tenant view from administration and internal metrics context?
  • Which release artifacts are appropriate for a public browser, and which reveal internal development or customer context?

What to hand in

Create a tenant and surface inventory, then report observed exposure against a stated ownership rule. Separate a recommended authorization design from behavior demonstrated by an actual endpoint.

Records and evidence

Tenants, users, audit events, object exports, CI artifacts, worker jobs, and metrics provide several places to investigate tenant context. Compare the ownership represented in each category and document which records support a particular tenant or administrative view.

  • tenants
  • users
  • audit-events
  • object-exports
  • ci-artifacts
  • worker-jobs
  • metrics

Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.

Public self-service at launch

Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.

Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.