Tenant-Isolated Data Layer

Enforce company scoping in services, SQL predicates, composite relationships, and PostgreSQL row-level security.

Overview

Description

The Tenant-Isolated Data Layer makes company identity explicit in service inputs and SQL while PostgreSQL row-level policies provide a second enforcement boundary.

Tenant-Isolated Data Layer is delivered through typed package contracts rather than a surface-specific shortcut. Its primary modules separate the public input or configuration shape from validation, durable state, and the operation that produces the result. That separation lets product surfaces and integrations invoke one implementation while tenant scope and existing domain rules remain in force. Errors stay bounded to the request instead of weakening the underlying data contract.

Selling Points

  • Prevents accidental cross-company reads and writes.
  • Covers ordinary tenant rows and shared built-in rows.
  • Keeps raw property-key interpolation behind sink guards.
  • Applies one typed package contract across every supported caller and surface.
  • Keeps invalid inputs and unavailable dependencies from silently widening durable state.

User Story

As a customer, I trust that another tenant cannot access my Dotabases even if an application query omits a boundary. In practice, I configure or invoke the capability through a supported surface, supply only the inputs its contract accepts, and receive a result governed by the same rules as every other caller. I can inspect the resulting row, setting, event, or query state and correct my input when validation fails. I walk away with a repeatable workflow rather than a one-off client implementation.

Extension Surface

Fixed core: tenant predicates and RLS policy factories are security invariants, not user customization.

The fixed_core rating is evidenced by packages/dotabases/src/contracts/drizzle-client.ts, which defines the supported seam used by trusted callers or configuration. The capability can be composed wherever that contract is available, but its invariants are not replaced by tenant-authored executable code. This keeps extension honest: callers control documented inputs and policy choices while the package owns validation and safety.

Capabilities & Limits

  • Capability: Executes the scoped workflow described above through the cited live implementation paths.
  • Capability: Preserves typed validation and applicable tenant, schema, lifecycle, or service boundaries.
  • Limit: RLS is a backstop, not a replacement for scoped services. Correct request-scoped identity must still reach the database connection. Tenant-Isolated Data Layer supports the concrete operations described here and composes them with tenant, schema, or lifecycle checks already owned by the package. It does not grant raw database access, make unsupported inputs valid, or assume that optional providers and downstream consumers exist. Callers remain responsible for permissions and meaningful configuration, and product rendering or external delivery stays outside the package unless explicitly stated.

Implementation Map

  • packages/dotabases/src/contracts/drizzle-client.ts
  • DrizzleClientLike
  • packages/db/src/rls/company-scoped-policies.ts
  • companyScopedPolicies
  • packages/db/src/rls/system-row-scoped-policies.ts
  • systemRowScopedPolicies

Properties

Property
Value
product
dots-platform
extensibility
fixed-core
module
Dotabases
packages
dotabases, db
status
shipped
surface
cross-cutting
summary
Enforce company scoping in services, SQL predicates, composite relationships, and PostgreSQL row-level security.

Connections

Tenant-Isolated Data Layer · Explore connections

  • documented bytoAccess And Tenancy
  • implemented bytopackages/dotabases/src/internal/contracts/drizzle-client.ts
  • implemented bytopackages/db/src/rls/system-row-scoped-policies.ts
  • implemented bytopackages/db/src/rls/company-scoped-policies.ts
  • complementstoSelf-Hosted Schema and Migrations
  • implemented bytoDrizzleClientLike
  • implemented bytocompanyScopedPolicies
  • implemented bytosystemRowScopedPolicies
  • implementstoDS_Dotabases — Comprehensive Module Spec
  • referencesfromfix(docs): Seed document endpoint titles into the export artifact
  • referencesfromfix(docs): Seed document endpoint titles into the export artifact

Connected Records11

Complements
Documented by
Implemented by
companyScopedPolicies
DrizzleClientLike
packages/db/src/rls/company-scoped-policies.ts
packages/db/src/rls/system-row-scoped-policies.ts
packages/dotabases/src/internal/contracts/drizzle-client.ts
systemRowScopedPolicies
Implements
DS_Dotabases — Comprehensive Module Spec
References
fix(docs): Seed document endpoint titles into the export artifact
fix(docs): Seed document endpoint titles into the export artifact
11 connections.

Documents

Title
Type