BuildWithHQ
Canonical knowledge unit · data

AppAccount multi-tenancy boundary

Inside a generated SaaS database, AppAccountId is the primary tenant isolation boundary and must be derived/validated server-side for record and AI operations.

ID: BWHQ-DATA-002Status: currentAuthority: hightenancyappaccountisolationsecurity

AppAccount multi-tenancy boundary

Model

A generated SaaS can host multiple internal customer organizations. These organizations are represented as AppAccounts. Their users and application data are scoped by AppAccountId.

Required behavior

Distinction

A BuildWithHQ builder/customer account in the central control plane is not the same thing as an AppAccount inside one of that builder’s SaaS applications.

Machine-readable source: canonical Markdown. This HTML companion exists for human reading, search indexing, and AI retrieval.