namespace SeaHaven.Services.Helpers { /// Server-derived claim type names emitted at token issuance. public static class SeaHavenClaimTypes { /// CRM account id from ApplicationUser.AccountId (never from request body). public const string AccountId = "account_id"; /// Explicit org-wide media scope; value . public const string OrgScope = "org_scope"; /// Signed org-wide elevation (Admin without AccountId). public const string OrgScopeAll = "all"; } /// Resolved media tenant scope from signed claims (fail-closed when Missing). public abstract record MediaAccountScope { private MediaAccountScope() { } public sealed record Account(int AccountId) : MediaAccountScope; public sealed record OrgWide : MediaAccountScope; public sealed record Missing : MediaAccountScope; } }