Skip to content
All stories
RetailMulti-tenant

Thornbury Retail untangled one shared user table

A single users table with a tenant column had become the source of every incident.

Illustrative example

Thornbury Retail is a composite example, not a named customer. The situation and the way it was solved are drawn from what teams actually bring to us; the company itself is invented. Real customer stories are published only with the customer’s permission and their own name on them.

1
tenant boundary
0
cross-tenant incidents since
memberships
not a column

The situation

Cross-tenant bugs were rare and catastrophic. Every query needed a tenant filter, and one missing WHERE clause was a data leak.

What they did

Organizations became the tenant boundary, with memberships instead of a column, and every API call scoped by construction.

What changed

The class of bug is gone rather than reduced. New endpoints cannot forget the filter because there is no filter to forget.

Evaluate the intended workflow

This composite story explores a roadmap outcome. Compare it with the implemented product boundary and current release evidence before planning an integration.

What’s your enterprise story?

Tell us what the checklist is costing your team and we will give you a straight answer on fit.