One shared platform across every brand
Per-brand data isolation is what keeps every brand and location's data separate underneath one shared platform. That separation travels with every read and write. Isolation is compliance-grade by default — not a configuration afterthought.
Note
This page is the short orientation. The canonical, in-depth treatment — enforcement mechanics, the deny-by-default grant model, and how to structure a new brand — lives at how per-brand data isolation works. The database machinery underneath is documented at database isolation mechanics.
Principles
- Which brand's data you're working with is always explicit — never assumed for convenience
- Individual brands run on the shared platform; they do not stand up a second, separate business database
- Brands can be sold or spun off cleanly, without forking the underlying platform
Operator implication
Console work always happens in the context of one brand. Your overall account and your role on a specific brand stay distinct — Triangle: secure sign-on establishes who you are, and the platform resolves what you may do per brand. For where the brand boundary sits inside the wider org tree, see multi-tenant architecture.
