Skip to content

Workspaces & data isolation ​

A workspace is one business on NeodyAI: its people, apps, records, processes and settings.

  • Every record belongs to exactly one workspace.
  • Isolation is enforced in the database with row-level security, not only in application code: a query made for one workspace can't return another workspace's rows, even by mistake.
  • A token (session or API key) acts in exactly one workspace. Records from other workspaces answer 404.

People and accounts ​

A person has one login (an account) and can belong to many workspaces — a bookkeeper serving several clients, or a consultant in each client's workspace. In each workspace the person has their own membership with its own roles and app access, so the same person can be an owner in one workspace and a guest in another.

From the API's point of view, a membership is the principal: GET /v1/me returns the membership id as user_id and the workspace as tenant_id.

Apps in a workspace ​

A workspace is entitled to a set of apps (GET /v1/apps lists them for the caller). App endpoints answer only when the app is enabled for the workspace and the token may use it.

Audit ​

Security-relevant actions — sign-ins, role and permission changes, API keys, four-eyes decisions, automation changes, use-case changes — are written to an append-only, hash-chained audit log per workspace. Each entry records who acted (and on whose behalf, for agents), what changed and the outcome. Holders of audit.read can verify the chain and export it.

NeodyAI — run your business from one place.