Database-enforced tenant boundary
Tenant-scoped financial tables use Postgres row-level security with FORCE, so the database applies workspace isolation to the application role.
Data isolation
Tenant isolation is enforced in Postgres with FORCE row-level security.
Tenant-scoped financial tables use Postgres row-level security with FORCE, so the database applies workspace isolation to the application role.
Financial mutations write audit events, and database triggers reject updates or deletes to those audit records.
This page documents the database controls that protect workspace records and the append-only history of financial mutations.