Core
Tenant-local App directory reads
Read basic identities without repeated Core callbacks.
Basic User, Party, legal entity, operating unit and site lookups use tenant-local read-only views in isolated App runtimes. Existing SDK contracts stay unchanged. Background jobs can resolve basic organization identities without a human actor. Private contact searches, membership selection and business authorization remain governed by Core.
Upgrade Core first: tenant migrations synchronize existing allocation grants automatically. Use nexia-apps:sync-database-references from the database operator process for targeted recovery. New allocations and credential renewal also prepare grants automatically. Then upgrade the App runtime. No App source or SDK package change is required.
Shared runtime code can be patched without republishing Apps. Reviewed App source remains unchanged, and replacement is allowed only when PHP, extensions, SDK and locked dependencies have identical build metadata. Dependency changes require rebuilding and reviewing the Apps.