Concepts
Multi-tenancy
How one deployment serves many organizations safely.
Every authenticated request carries an organizationId, resolved from the JWT
and stored in per-request context. Data access is implicitly scoped to that
organization — repositories filter by it automatically rather than relying on
each query to remember.
New data models that need scoped access carry organizationId (and usually
createdBy, teamId, regionId, businessUnitId) so the access-control layer
can filter them. Because scoping is centralized, a tenant can never read another
tenant's rows by accident.
Each tenant also has an enabled set of modules and features, so the same deployment can present a different product to each organization.