Kaizen
Browse modulesTenancyTypes

Type Alias: TenantBinding

type TenantBinding = 
  | {
  actorId: string | null;
  mode: "tenant";
  tenantId: string;
}
  | {
  mode: "public-read";
};

Defined in: server/tenancy/context.ts:23

Request-scoped tenant context — the source of truth both tenancy layers read (see the module README): the app-layer read-scope interceptor (withTenantScope) and the Postgres RLS backstop (withTenantTransaction, which pins the app.current_org GUC per request).

The value is SERVER-DERIVED (an auth session, or a trusted header) — never client input. A consumer binds it for the lifetime of a request with runWithTenant; everything reached inside (services → repositories → Prisma) inherits it through AsyncLocalStorage without threading it through signatures.

Three modes:

  • tenant — a normal tenant-scoped request. Reads are tenant-filtered; the GUC is the tenant id, so RLS admits only that tenant's rows.
  • public-read — the deliberate cross-tenant public exception (e.g. an unauthenticated status lookup returning a PII-free subset). Reads are NOT tenant-filtered and the GUC sets a SELECT-only bypass.
  • unbound — no binding (seed / system / an authed request with no active tenant). No filter; no GUC ⇒ RLS FAILS CLOSED (zero rows).