Security and data boundaries

Access follows the organization boundary

Public discovery never replaces server-side authorization. Every private request remains scoped to the current organization and the user’s role.

Clear workflow, clear boundaries

Separate global accounts, organization membership and private operational data.

Security and data boundaries

Tenant context at the edge

The requested hostname resolves to an active organization before API traffic receives trusted tenant context.

Security and data boundaries

Roles checked by the API

Client separation and navigation improve usability, while the server remains the authority for every mutation.

Security and data boundaries

Private assets stay private

Payment proof and student records use authenticated access instead of public storage URLs.

Ready to bring the workflow together?

Start by creating or claiming the Organization Profile, then choose the operating mode that fits.

Apply for classly