Architecture Decisions
ArchitectureLicense PlatformAccepted
Tenant isolation through explicit scoped access
Use a shared schema with tenant_id on business data and enforce tenant scope through the data-access boundary; PostgreSQL RLS remains a documented future defense-in-depth option.
Multi-tenancyPostgreSQLIsolation
Decision
Business tables carry tenant identity and repository operations require tenant scope explicitly. IDs are resolved inside the caller's tenant boundary rather than trusted as globally meaningful input.
Trade-off
RLS would add defense in depth, but the accepted phase decision judged its connection/session policy overhead disproportionate while access remained centralized in the repository layer.