# Constal Resource Names

Every policy and binding target has one canonical address.

```text
crn:constal:<environment>:<tenant>:<namespace>:<kind>/<path>
```

Construct general names with `resourceName` and parse them with `parseResourceName`. Narrow validators include `authProviderName`, `credentialProviderName`, `credentialName`, `policyName`, `customerTenantName`, and `bindingName`. Use these helpers rather than string concatenation.

| Part | Example |
| --- | --- |
| environment | production |
| tenant | acme |
| namespace | support |
| kind | agent |
| path | triage |

Patterns are separate validated values for Policy matching. Exact resource operations authorize the exact CRN, not a display name or mutable deployment service.
