ADR-005: Organizations are tenants
Status: Accepted Date: 2026-10-10
Context
Coipe is B2B2C. Schools need their own users, branding and subdomain; individuals and families use the product without a school. Retrofitting tenancy later is costly.
Decision
The tenant is the organization. Every account belongs to at least one organization: individuals get a personal or family organization created automatically, so plans, branding and data always hang off an organization and one code path serves B2B and B2C. Organization types are school, family and personal. All tenants share one PostgreSQL database; every tenant-owned table carries org_id, and PostgreSQL row-level security backs up the application's own checks.
Alternatives considered
- Schema or database per tenant: stronger isolation, much harder migrations and operations. Possible later for enterprise customers.
- Separate B2C and B2B products: two code paths for one experience.
Consequences
- Every query is scoped by organization. Cross-organization reads are bugs.
- A school's own domain (e.g.
learn.school.edu) is possible later with Cloudflare for SaaS.