Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
103 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 5 / 9

Multi-tenancy and isolation

For isolation by construction:

  • Scope storage keys by owner so the layout itself reflects ownership and cross-tenant access requires an explicit, checkable decision.
  • Never let the client address raw internal identifiers in a way that bypasses checks. If a request can name a resource by id, the access check must run on that id.
  • Default to private. New resources are visible only to their owner until explicitly shared.
  • Make sharing data-driven and checked (Chapter 9): a shared_with list or a shares table that the access helpers consult.
← → arrow keys work too