Tenant context at the edge
The requested hostname resolves to an active organization before API traffic receives trusted tenant context.
Security and data boundaries
Public discovery never replaces server-side authorization. Every private request remains scoped to the current organization and the user’s role.
Separate global accounts, organization membership and private operational data.
The requested hostname resolves to an active organization before API traffic receives trusted tenant context.
Client separation and navigation improve usability, while the server remains the authority for every mutation.
Payment proof and student records use authenticated access instead of public storage URLs.
Start by creating or claiming the Organization Profile, then choose the operating mode that fits.