Architecture Decisions
ArchitectureLicense PlatformAccepted

Tenant isolation through explicit scoped access

Use a shared schema with tenant_id on business data and enforce tenant scope through the data-access boundary; PostgreSQL RLS remains a documented future defense-in-depth option.

Multi-tenancyPostgreSQLIsolation
01

Decision

Business tables carry tenant identity and repository operations require tenant scope explicitly. IDs are resolved inside the caller's tenant boundary rather than trusted as globally meaningful input.

02

Trade-off

RLS would add defense in depth, but the accepted phase decision judged its connection/session policy overhead disproportionate while access remained centralized in the repository layer.