Workspace isolation
- Every table that holds your data carries a workspace ID and is protected by PostgreSQL row-level security, forced on for every table.
- The application sets the workspace for each query inside a database transaction. A query with no workspace in scope is refused before it reaches the database.
- Automated tests create two workspaces and prove neither can read or write the other's rows, tokens or webhook deliveries.