Device identity & ownership
Bind a physical device to the right customer before its first reading.
A proposed registry model
Device internal_id / tenant_id / site_id provider / integration_id / application_id / dev_eui model / firmware / decoder_version lifecycle_state / commissioned_at / last_seen_at
Use an internal immutable identifier for your own records. Enforce the chosen ownership invariant in the database, not only in a form. The integration binding must not be supplied by the device payload.
Lifecycle
Suggested states are inventory, commissioned, assigned, active, suspended and retired. Moving a device between customers requires an audited transfer process: stop routing, settle outstanding commands, change ownership and resume only after verification.
Commissioning codes
A client-facing activation code should be random, single-use, expiring and stored as a hash. It resolves to a precommissioned internal record; it must never expose radio keys. Apply attempt limits and transactional redemption. A printed code is not a substitute for authorization to the destination site.
Historical data
Retain the original tenant and site association on each accepted event. Moving a device must not silently move a previous customer’s history. Document retention and deletion rules for retired devices.