Multi-tenant SaaS architecture
Separate workspaces, branded portals, isolated data by RLS, custom users, and secure API routes.
Workspace isolation
Every row carries workspace_id and is protected by membership policies.
Role-based access
Owner, admin, sales, production, accountant, freelancer, and client scopes.
PWA mobile feel
Manifest, responsive layout, touch-friendly controls, and offline cache shell.
Security posture
RLS, validation, rate limits, webhook signatures, and server-only secrets.
Security checklist
Supabase service role only on server
Input validation with Zod
Webhook signature checks
Storage path policies by workspace
Authenticated Data API grants with RLS