Organization isolation
Every signed-in request belongs to an organization context. Tindre uses that context together with the person’s access to limit what the request can read or change.
Identity
Who is making the request
Organization
Which tenant the request belongs to
Authorization
What that identity may do there
A boundary on every request
Organization-scoped data is read and changed inside the active organization. A person who belongs to more than one organization still works in one organization context at a time.
Access inside the boundary
Isolation does not replace authorization. Access roles control administrative capabilities, while object-level rules such as Standard visibility and Agent configuration narrow what a person or experience can use.
Answering the public
A visitor on a website has no employee identity. The answer uses the published widget and the Agent behind it, with a deliberately narrower content boundary.
Operational access
Platform operations are separate from ordinary organization access and are auditable. Cross-organization access is not part of the normal employee or administrator experience.