NoeVault Snip External Requester Identity
Authority: PR-8.7D ExternalRequester Model B (frozen)
Subjects: Stable application subjects such as KP-USER-*
SoR: SupportTicket
External app user
└─ App-authenticated session
└─ Trusted bootstrap maps to ExternalSubject / ExternalRequester
└─ SupportTicket owned without NoeVault UserUID
| Rule | Required behaviour |
|---|---|
| UserUID | Not created for external requesters |
| Seats | Not consumed |
| OLEA | Not created |
| Ticket ownership | ExternalRequester UID + org/solution scope |
| Continuity | Stable subject string (e.g. KitchenPro KP-USER-*) across remounts |
| Staff actors | Real NoeUser UIDs when operators comment from Panel |
| Field | ExternalRequester create | Operator reply |
|---|---|---|
Attachment uploadedBy |
Empty GUID | Operator UserUID (if staff upload) |
Comment authorUserUID (Customer) |
Empty GUID | — |
Comment authorUserUID (Support) |
— | Operator UserUID |
createdByName (projection) |
Trusted ExternalRequester / app label | — |
authorDisplayName (Customer) |
Trusted display precedence (not System) | — |
Presentation-only helper — does not write identity:
AuthorUserUID is non-emptyKitchenPro {role})Empty UserUID on an ExternalRequester-owned customer comment must never render as “(system)”.
Optional claim flows may link support history to a future NoeVault account. Historical tickets remain keyed to their original ExternalRequester UID — claim does not rewrite ownership into a UserUID create-on-submit model.