The Customer Authority Portal is a scoped handoff, not a permanent customer workspace. Its opaque URL is bound to one vendor/customer/environment relationship, expires, and is stored only as a hash.
The customer authenticates before accepting the relationship. Acceptance records the customer subject and moves the connection into INSTALLING; it does not grant the vendor mutation authority.
The customer installs the signed Gateway, owns secret references, and controls activation, rotation, revocation, and removal. The vendor receives relationship health and safe completion state only.