Overview
Multi-tenancy allows multiple organizations to use the platform while keeping their data completely isolated. Each tenant operates independently with their own products, categories, orders, and team members.How It Works
Tenant Resolution
The system identifies the current tenant from theX-Tenant-ID header:
Automatic Scoping
Models using theHasTenant trait are automatically filtered:
Tenant-Scoped Models
These models belong to a single tenant:Catalog
- Products
- Categories
- Product Images
Operations
- Orders
- Order Items
- Ratings
Integrations
- Webhooks
- Integration Outbox
Configuration
- System Config
- Settings
Cross-Tenant Models
These models exist across tenants:- User - Can belong to multiple tenants
- Tenant - The organization itself
- TenantUser - Pivot table linking users to tenants
User Roles
Each user has a role per tenant:- ADMIN
- MEMBER
Full Control
- Add/remove team members
- Update member roles
- Manage products and categories
- Configure webhooks
- Update tenant settings
Best Practices
1. Always Include X-Tenant-ID
2. Verify Tenant Membership
Before accessing tenant resources:3. Check Role for Sensitive Operations
4. Don’t Manually Set tenant_id
TheHasTenant trait handles this automatically:
Security Considerations
Tenant Isolation
- Data is automatically scoped by tenant
- Cross-tenant queries are prevented
- Users can only access their tenants’ data
Role Verification
- ADMIN role required for team management
- Role checks happen at the controller level
- Middleware validates tenant access