In practice
The models run from a shared database with a tenant column, through a schema per tenant, to a database per tenant. Shared is cheapest to operate and demands the most discipline, because one missing filter in one query exposes data belonging to another customer. Isolated is easier to defend to a regulator and considerably more work to maintain at scale.
Where it fits in a build
Choose by the obligations you are taking on, not by elegance. Regulated sectors, public-sector buyers and enterprise security reviews frequently decide this question for you, so ask before you design.
Common mistakes
- Enforcing separation in application code alone, with nothing at the database layer as a backstop.
- Shared caches keyed without the tenant, which leaks across customers invisibly.
- Background jobs that run without a tenant context and touch everything.
Related terms
Working on something that involves this?
ASTACKRA designs and builds AI systems, automation and custom software for businesses that need technology shaped around their own workflow. If this term turned up in a proposal and you want a straight answer about whether it applies to your situation, ask us — no obligation, and we will tell you if the answer is no.
Related