GHOSTSOFTWARE by Logic Foundry
Architecture proposal

Device identity & ownership

Bind a physical device to the right customer before its first reading.

A proposed registry model

Device
  internal_id / tenant_id / site_id
  provider / integration_id / application_id / dev_eui
  model / firmware / decoder_version
  lifecycle_state / commissioned_at / last_seen_at

Use an internal immutable identifier for your own records. Enforce the chosen ownership invariant in the database, not only in a form. The integration binding must not be supplied by the device payload.

Lifecycle

Suggested states are inventory, commissioned, assigned, active, suspended and retired. Moving a device between customers requires an audited transfer process: stop routing, settle outstanding commands, change ownership and resume only after verification.

Commissioning codes

A client-facing activation code should be random, single-use, expiring and stored as a hash. It resolves to a precommissioned internal record; it must never expose radio keys. Apply attempt limits and transactional redemption. A printed code is not a substitute for authorization to the destination site.

Historical data

Retain the original tenant and site association on each accepted event. Moving a device must not silently move a previous customer’s history. Document retention and deletion rules for retired devices.