A workspace is the tenant boundary
Taskboard is a SaaS application for several organizations. Acme and Orbit use the same running API, but each expects its projects, tasks, members, and billing data to remain separate.
A tenant is the organization whose data and rules the application is handling. In Taskboard, the tenant is a workspace.
Maya's user account is global. Her membership in Acme grants access to Acme. A second membership can grant access to Orbit. Logging in identifies Maya; selecting a workspace identifies the tenant context for an operation.
Shared database, explicit ownership
Taskboard uses shared PostgreSQL tables. Tenant-owned rows carry workspaceId, and queries constrain those rows to an authorized workspace.
This design keeps database operations manageable for one application and makes tenant relationships visible in the course. It also means that a missing workspace condition can become a data leak. Shared storage requires consistent enforcement.
Other tenancy models include a separate schema or a separate database per tenant. Those can provide different operational isolation, but they also add migration, connection, backup, and provisioning costs.
Separate databases do not solve every authorization problem. The application still has to select the correct tenant database and verify the caller's membership.
Tenant context comes from a checked relationship
The frontend can remember a selected workspace in its state. The API cannot trust that selection alone.
For a request to Acme, the server uses Maya's authenticated user identifier to look up her Acme membership. The resulting scope contains the workspace and her role there. Subsequent operations use that scope.
Workspace creation also involves related facts. The server creates the workspace and its owner's membership together. A workspace that commits without an owner has no valid administrative starting point.
Billing belongs to the workspace because the subscription purchases capacity for that organization. A user's access to several workspaces does not mean that one workspace's paid plan upgrades the others.
A common mistake is placing activeWorkspaceId on the user and treating it as shared authority. Maya can have two browser tabs open to different workspaces. The path's explicit tenant context avoids that global switching problem.
Can Maya be an owner in one workspace and a member in another?
Yes. Her memberships hold the workspace-specific roles. The global user record does not assign a universal workspace role.
A tenant is an ownership and access boundary. Keep that boundary explicit in records, requests, and business rules.
Read api/src/tenancy.ts Read api/src/schema.ts