Multi-tenancy is the architecture pattern where one system serves many customers (tenants) whose data and configuration must remain strictly separated. The engineering question is where isolation is enforced: in application code that remembers to filter by tenant, or in the platform itself, where forgetting is impossible.
Isolation models
- Separate deployments per tenant: strongest isolation, multiplied operating cost.
- Shared app, tenant-filtered queries: cheap, but one missing WHERE clause is a breach.
- Shared database with row-level security (RLS): the database itself refuses cross-tenant reads, regardless of application bugs.
Why RLS changes the risk profile
With RLS, tenant isolation stops being a convention every developer must uphold in every query and becomes a property the data layer enforces. Application bugs still matter — but they fail closed instead of leaking.

