Reference
Tenant separation
Understand how the current build keeps tenant requests and records in the selected tenant scope.
Tenant separation is enforced by the service
Tenant records carry a tenant identity. Product requests and database queries use the selected tenant identity with the named resource.
A missing, old, or different tenant resource identity fails closed during access checks.
Tenants are not separate physical databases
Pūnaha has separate Control, Workflow, and AI databases by service purpose. Each of those databases can hold records for more than one tenant.
Tenant separation therefore depends on server checks and tenant scoped data access. Do not claim that every tenant has a separate database.

Access remains tenant scoped
A normal tenant member receives access inside the selected tenant. A resource grant refers to an item in that tenant.
Platform administration has wider authority by design. Limit it to approved people and review its audit records.
Child information is limited
Access to a child item can expose the minimum parent name needed to find it. It does not give access to sibling items or the parent management page.
Check separation safely
- Use approved test tenants and test accounts.
- Confirm an allowed item appears in its tenant.
- Confirm a different tenant item does not appear.
- Try the direct address and confirm the service still blocks it.
- Keep the request and audit IDs as evidence.
Never use real customer data in a separation test unless the approved test plan requires it.
Related tasks
Read Manage tenants, Tenants, people, and access, and Understand administration responsibilities.
Was this page helpful?
Your answer helps us improve the documentation.
Do not include personal information, customer information, passwords, or keys.