Multi-tenancy is the architecture pattern where one system serves many customers (tenants) whose data and configuration must remain strictly separated. The engineering question is where isolation is enforced: in application code that remembers to filter by tenant, or in the platform itself, where forgetting is impossible.

Isolation models

  • Separate deployments per tenant: strongest isolation, multiplied operating cost.
  • Shared app, tenant-filtered queries: cheap, but one missing WHERE clause is a breach.
  • Shared database with row-level security (RLS): the database itself refuses cross-tenant reads, regardless of application bugs.

Why RLS changes the risk profile

With RLS, tenant isolation stops being a convention every developer must uphold in every query and becomes a property the data layer enforces. Application bugs still matter — but they fail closed instead of leaking.

RELATED CONCEPTS