Tenant isolation
The authenticated identity establishes the tenant boundary. Application authorization and PostgreSQL row-level security enforce that boundary independently.
Request path
Section titled “Request path”- Identity Access validates credentials and issues a tenant-bound token.
- The API validates token signature, issuer, audience and expiry.
- Effective roles and permissions are resolved for that tenant.
- The database transaction receives the tenant context.
- Row-level security filters reads and rejects cross-tenant writes.
Identifiers are not authorization. Knowing another tenant’s account, request or batch identifier must not make it readable.
Integration rules
Section titled “Integration rules”- Use one tenant-bound credential per institutional context.
- Never cache data without including the effective tenant in the cache key.
- Do not accept a tenant identifier from an untrusted client and forward it as authorization context.
- Treat
404for a known identifier as potentially intentional boundary protection. - Propagate correlation IDs, not credentials, across logs and support workflows.