How to Evaluate This Multi-Tenant SaaS Prototype
A production-ready reference architecture delivering complete data, user, and operational isolation across independent enterprise companies, powered by PostgreSQL 16 Row-Level Security, granular RBAC, deterministic financial workflows, and Securiti-governed AI.
PostgreSQL Isolation Engine
Interactive simulation proving zero cross-tenant data leakage via PostgreSQL Row-Level Security and transaction session context.
Operations & Take-Rate Hub
Deterministic math engine (Platform Fee = Gross × 2.4% + $0.30). Zero LLM calculation hallucination. Live transaction mutation.
Granular RBAC Matrix
5 distinct roles across 10 fine-grained capabilities. Live policy evaluator testing 200 OK vs 403 Forbidden access decisions.
Tenant AI Copilot & Audit
Dual-provider AI intelligence bounded strictly within company context. Securiti-certified inline LLM firewall and SHA-256 audit trail.
Zero-Leakage Multi-Tenancy Architecture: 1. PostgreSQL 16 RLS session policies (SET LOCAL app.current_tenant_id) ➔ 2. Deterministic ledger isolation ➔ 3. Pre-commit SHA-256 cryptographic audit trail.
SET LOCAL app.current_tenant_id = 'ten_acme_892';
Audit logs cannot be updated or rolled back without hash invalidation
Queries without session context drop to 0 rows automatically
Last audit health check: 2 mins ago
PostgreSQL Multi-Tenant Isolation Engine
RLS ActiveShared DB + RLSSession-driven Row-Level Security (RLS) guaranteeing complete data containment at the database kernel.
Shared DB + Row-Level Security
Single database, shared tables. PostgreSQL evaluates session context via current_setting('app.current_tenant_id').
Schema-Per-Tenant
Isolated PostgreSQL schemas (tenant_hrzn_410). Connection pools switch dynamic search_path per request.
Isolated Table Partition / VIP DB
Declarative table partitioning by LIST (tenant_id) or dedicated Amazon Aurora instance for high-compliance VIPs.
| ID | REFERENCE | AMOUNT | TENANT_ID | STATUS |
|---|---|---|---|---|
| tx_9841 | INV-2026-901 | $14,250.00 | ten_acme_892 | SETTLED |
| tx_9842 | INV-2026-902 | $8,640.50 | ten_acme_892 | SETTLED |
| tx_9843 | INV-2026-903 | $32,400.00 | ten_acme_892 | PROCESSING |
| tx_9844 | INV-2026-904 | $19,800.00 | ten_acme_892 | ESCROW_HOLD |
Tenant Financial Ledger & Operations Hub
Acme Logistics CorpDeterministic calculation engine (Fee = Gross × 2.4% + $0.30). Zero LLM math hallucination.
| Reference | Customer | Gross Amount | Fee (2.4%+$0.30) | Net Settled | Status | Risk Score |
|---|---|---|---|---|---|---|
| INV-2026-901 | Global Freightway Ltd billing@globalfreight.com | $14,250.00 | -$342.30 | $13,907.70 | SETTLED | 4/100 |
| INV-2026-902 | TransPacific Cargo Co ops@transpacific.io | $8,640.50 | -$207.67 | $8,432.83 | SETTLED | 2/100 |
| INV-2026-903 | Atlantic Intermodal Corp finance@atlanticintermodal.com | $32,400.00 | -$777.90 | $31,622.10 | PROCESSING | 12/100 |
| INV-2026-904 | Nordic Rail & Port SL accounts@nordicrailport.eu | $19,800.00 | -$475.50 | $19,324.50 | ESCROW_HOLD | 48/100 |
Granular Role-Based Access Control (RBAC) Matrix
5 Roles • 10 CapabilitiesStrict separation of duties. Cryptographically signed JWT claims mapped to PostgreSQL transaction roles.
Live Policy Evaluator Simulator
| Granular Capability | SuperAdmin | OrgAdmin | FinanceMgr | OpsLead | Auditor |
|---|---|---|---|---|---|
Cross-Tenant Context Switch tenant:switch | - | - | - | - | |
Update Tenant Webhooks & Settings tenant:update_settings | - | - | - | ||
Invite & Manage Team Members users:invite_manage | - | - | - | ||
Read Transactions & Invoices transactions:read | - | ||||
Initiate New Ledger Transactions transactions:create | - | - | |||
Disburse Payouts & Settlement Batches transactions:refund_settle | - | - | - | ||
Rotate Production API Keys & Secrets api_keys:rotate | - | - | - | ||
Inspect Immutable SHA-256 Audit Trail audit_log:view_raw | - | - | |||
Export Signed Compliance Bundles (SOC2) audit_log:export_signed | - | - | - | ||
Run Autonomous AI Copilot & Anomaly Scans ai_copilot:execute |
Cryptographic Immutable Audit Log
SHA-256 Pre-Commit VerifiedEvery mutation triggers a PostgreSQL PL/pgSQL digest calculation. Zero retrospective tampering permitted.
| Timestamp (UTC) | Action | Actor | Target Resource | Status | SHA-256 Digest | Details |
|---|---|---|---|---|---|---|
| 11:45:12 AM | TENANT_SETTINGS_UPDATE | e.rostova@acmelogistics.com OrgAdmin • 198.51.100.42 (US-East) | tenants/ten_acme_892/webhooks | SUCCESS | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | |
| 11:30:00 AM | PAYMENT_SETTLEMENT_BATCH | m.vance@acmelogistics.com FinanceManager • 198.51.100.89 (US-East) | ledger/batches/batch_8841 | MUTATION_LOGGED | 7a9f81d8c6b2450efb78a9c334b2f15e8c1e8b23f87c9012d98a6b5c3e2f14aa | |
| 11:15:22 AM | CROSS_TENANT_READ_ATTEMPT | ATTACKER_SESSION_SIMULATOR Unauthenticated/Guest • 203.0.113.19 (Adversarial IP) | transactions (WHERE tenant_id = ten_hrzn_410) | BLOCKED_RLS | 3c8e7f12a9d604b3e811c790b246a8d7e93012fcba587421de091427bc591c8a | |
| 10:02:18 AM | CRYPTOGRAPHIC_VERIFICATION | d.kellinger@acmelogistics.com ComplianceAuditor • 198.51.100.12 (US-East) | audit_log/chain/sha256_verify | SUCCESS | 9f83c21a4e5d6c7b8a90123456789abcdef0123456789abcdef0123456789abc |
Tenant Autonomous AI Copilot & Governance Engine
Dual-Provider (OpenAI + Gemini)Securiti NIST AI RMFStrict tenant-bounded intelligence. Zero cross-tenant data leakage. Inline LLM firewall sanitizing all inputs.
Cloud Infrastructure Cost & Take-Rate Margin Engine
Compare infrastructure burn across Shared DB + RLS vs Schema-per-Tenant vs DB-per-Tenant at enterprise scale.
SaaS Scale Parameters
Itemized Infrastructure Cost Comparison
💡 Architectural Recommendation: Deploy Strategy A (Shared DB + RLS) for 95% of standard and enterprise customers to minimize database migration friction and idle connection pool costs, while offering Strategy C as a premium VIP add-on for regulated enterprise tiers requiring dedicated physical storage.
One-Click Architecture Blueprints (SQL DDL & Docker Stack)
Export ready-to-run PostgreSQL DDL schemas with RLS policies, connection pool configurations, and containerized Docker Compose services.
-- ============================================================================
-- IsoCore Production PostgreSQL Multi-Tenant Architecture Blueprint
-- Strategy A: Shared DB + Row-Level Security (RLS) via Session Context
-- ============================================================================
-- 1. Tenants Directory
CREATE TABLE tenants (
id VARCHAR(64) PRIMARY KEY,
slug VARCHAR(64) UNIQUE NOT NULL,
name VARCHAR(255) NOT NULL,
tier VARCHAR(32) NOT NULL DEFAULT 'Enterprise',
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
);
-- 2. Isolated Ledger Transactions Table
CREATE TABLE transactions (
id VARCHAR(64) PRIMARY KEY DEFAULT 'tx_' || replace(gen_random_uuid()::text, '-', ''),
tenant_id VARCHAR(64) NOT NULL REFERENCES tenants(id) ON DELETE RESTRICT,
reference_id VARCHAR(128) NOT NULL,
customer_name VARCHAR(255) NOT NULL,
amount NUMERIC(14, 2) NOT NULL CHECK (amount >= 0),
platform_fee NUMERIC(14, 2) NOT NULL,
net_settled NUMERIC(14, 2) NOT NULL,
status VARCHAR(32) NOT NULL DEFAULT 'PROCESSING',
risk_score INTEGER NOT NULL DEFAULT 0,
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
);
-- 3. Composite Tenant B-Tree Indexes
CREATE INDEX idx_transactions_tenant_date ON transactions (tenant_id, created_at DESC);
-- 4. Enable & Force Row-Level Security
ALTER TABLE transactions ENABLE ROW LEVEL SECURITY;
ALTER TABLE transactions FORCE ROW LEVEL SECURITY;
-- 5. Zero-Leakage Restrictive Security Policy
CREATE POLICY tenant_isolation_policy ON transactions
AS RESTRICTIVE
FOR ALL
USING (tenant_id = current_setting('app.current_tenant_id', true))
WITH CHECK (tenant_id = current_setting('app.current_tenant_id', true));
-- 6. Connection Pool Hook (Run before any tenant query):
-- SET LOCAL app.current_tenant_id = 'ten_acme_892';Run the SQL blueprint on your AWS Aurora, Supabase, or RDS instance to establish tables, indexes, and FORCE RLS policies.
Set pool mode to transaction and ensure DISCARD ALL clears session parameters on checkout.
Connect your application container. Session middleware injects SET LOCAL app.current_tenant_id per incoming HTTP request.