Spatial7 EAM AdministratorLesson 2 of 4 · 0% complete
Users, roles and access

Tenant isolation and data access

How one organisation's records stay separate from another's.

45 min

Records are scoped, not just hidden

Client-scoped records carry the organisation they belong to. Access is enforced on the data itself — a user of one organisation cannot read, update or delete another organisation's records, whether they come through a page, a report or a direct API call.

What this means for you

  • Adding a record to the wrong organisation scope is an access decision, not a filing mistake
  • Sharing must be explicit: a record is visible to the people the record says it is visible to
  • Reporting inherits the same restriction, so a dashboard can never show another organisation's figures

Administrator discipline

Before granting elevated access, ask what the person needs to do. Most tasks need user; only platform management needs admin. The smaller the elevated group, the easier it is to defend the data.

Create an Academy account to track your progress and resume where you stop.

Skip to Datasets and reference data