Tenancy and access model
Every record is scoped to a tenancy and enforced at the database layer through row-level policies, not only in application code. Access inside a tenancy is role-based: viewer, custodian, operator and administrator. Enterprise tenancies can enforce SSO with SCIM deprovisioning and custom role definitions.