I like the scope approach for this. Should I namespace the tenant approach as described here? OpenID Connect Scopes