If two customers share a platform and isolation is “UI only,” you have a liability.
Problem
Every request must answer: whose data is this? If the client supplies orgId and you politely believe it, you already lost.
Solution concept
- Authenticate the caller
- Load memberships
- Bind tenant context for this request
- Scope DB reads/writes to that tenant
- Keep files/workspaces under the same identity
The org dropdown is a reminder, not the control plane.
Residual risk
Rare bypass paths need review. App filters without DB enforcement are thinner. Isolation shrinks blast radius, it is not absolute safety.
Try a real console - leave feedback
Review / discuss: GitHub Discussions #11


Top comments (0)