One system, many customers: proving their data stays apart
A product that holds several companies’ sales calls must never let one see another’s. Saying so is easy. Here is how we checked it on the live system, and what we built so the answer stays true after every change.
A software product with many customers usually keeps all of them in one system. For an AI sales-coaching product, that means several companies’ recorded sales calls side by side. One company must never see another’s. Every product says that. We wanted to be able to show it.
Rules where the data lives
Separation was enforced in the database itself, not only in the application code above it. We reviewed and tightened all 70 of 70 data access rules, and checked the live system before and after the change.
Test it like an outsider
Then we tried every way in without signing in: 69 entry points, 101 attempts on the live system. Every one was refused.
We also proved separation with two test companies on the live product: signed in as one, we saw its 37 scored calls; signed in as the other, we saw nothing of them. Inside a company, the same idea applies to teams: with seeded test teams, an admin saw all 5 salespeople and a team manager saw exactly their 3.
Keep it true after the next change
A check run once proves the past. Two habits protect the future:
- A security review on every change, as the last step before release.
- Every change to data leaves a record. We found 13 actions that were not being recorded and fixed them, and the build now fails if a new one forgets.
How we ship
We do not ask customers to trust a promise. We test the promise, on the live system, and make the test part of every release.
The examples in this article come from real engagements. Client details withheld; every figure comes from the client’s own data.
Read the case study →