Tenants

Customer organisations, their users, security policy and subscriptions.

A tenant is a customer organisation. Users can belong to several tenants and switch between them.

Tenant settings

Each tenant sets its own security policy: whether MFA is required, password complexity and expiry, account lockout, access-token and refresh-token lifetimes, session timeout and whether email confirmation is required.

Registration

Tenants can register themselves (POST /api/v1/auth/register-tenant). Registration creates the tenant, its first administrator and a default subscription.

Isolation

Records carry their tenant in the record-information row, and the data engine scopes every query to the current tenant, app and environment. Files are stored under app and tenant folders, and logs and audit history use indices per tenant.