FEATURES
Secure Workspace Discovery and Entry
Route people through a platform-owned public surface before tenant authentication starts, so workspace entry stays clear and auditable.
Public entry should not guess at tenant identity after sign-in has already started. GlossaryQ separates the public routing surface from the tenant authentication boundary so users begin on the base domain, resolve the correct workspace, and then continue into the right tenant host.
That separation makes the platform easier to review. Security teams can inspect the public trust pages, legal coverage, status channel, and onboarding steps without touching tenant content. Returning users can still move quickly because the platform can surface a validated workspace shortcut when the browser already has a trusted tenant context.
The result is a cleaner identity story: discovery, recovery routing, demo evaluation, and registration all start on a platform-owned surface, while actual tenant sign-in remains tenant-scoped.