Draft-1 proposed one model of multi-tenancy with fixed characteristics.
Rejected: the estate needs a framework that can hold several situations at
once, including repos that do not separate tenants rigorously today and must
be developed toward doing so.
What changed:
- Every plane now carries an ordered ladder (I0-I3, A0-A3, E0-E4, P0-P4),
not just placement. A service is a posture vector, not a verdict.
- D3 reversed. Draft-1 forbade RLS as a control that "looks like a database
guarantee without being one". The observation was right, the conclusion
wrong: RLS is E3, materially stronger than E2, and the actual error was
calling E3 by E4's name. Platform enforcement is now the direction of
travel and an obligation on the platform, not only on consumers.
- New governing rule: conformance is accuracy, not altitude. Declaring E0 is
conformant; concealing it is not. Overclaiming is the only violation.
- Fixed a flaw of draft-1's own making: R0 "shared tables, tenant column" was
an enforcement state mislabelled as placement. Removed; P ladder renumbered.
- Added methodology (analyze/establish/improve/guard) and per-level evidence
artifacts. Guarding checks a service against its own declaration, which is
what makes the verification problem tractable at all.
- D7 softened per operator: tiers carry minimum levels internally, marketing
language stays free, the constraint is on evidence not vocabulary. One hard
line kept: "another tenant cannot reach your data" requires E4.
Ratification now also tests the framework — each reviewing repo publishes its
posture vector, and if a repo cannot express itself in these ladders the
ladders are wrong, not the repo.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The estate has built multi-tenancy across five documents that each cover a
slice and do not compose. This records the whole model and names what is
missing.
Core framing: multi-tenancy here is four orthogonal planes — identity,
authorization, data isolation, placement — not one property. Identity and
authorization are ratified and solid. Data isolation is stated but
unverified. Placement is owned by nobody and is precedent-by-accident.
Three findings that motivated the draft:
- R0 -> R1 -> R2 does not improve tenant isolation at all. Those rungs buy
consumer isolation and capacity. Only R3 makes the tenant boundary
structural. A plan tier selling R2 as isolation would be false.
- No fleet mechanism verifies that any consumer actually enforces the tenant
boundary it is obliged to enforce. A missing WHERE tenant_id would be a
cross-tenant breach that no probe fails and no log shows as an error.
Highest-severity gap; needs an appointed owner.
- platform-pg holds roughly six consumers (100 max_connections, 14 each) and
memory likely binds before connections do. Two are provisioned. The runway
is shorter than the ladder implies.
Also reconciles two already-ratified and contradictory defaults:
instance-per-client for business apps, pooled for platform services, with no
rule for telling a new service which it is.
Proposed, not ratified. Carries a ratification path so it does not join the
shared-platform-relational-storage draft in limbo.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>