Isolated teams, one platform
Run multiple organizations safely on one platform with workspace isolation backed by row-level security. Invite members, manage join-code access requests, and scale team operations without creating separate infrastructure per tenant.
1
Workspace truth
Shared objects, members, permissions
24h
Invite to first record
Typical new member onboarding
RLS
Row isolation
Tenant boundaries at the database
Tenant isolation, team growth
Invites, join codes, and approvals on one workspace model.
Workspaces provide the tenancy boundary for OSTRATA. Each organization works in an isolated environment with its own members, schema, permissions, and operational context, while the platform handles shared infrastructure behind the scenes.
This structure supports both security and simplicity. Teams gain strong data isolation through row-level security, then onboard users through invites or join codes with admin approval, making growth manageable without multiplying technical overhead.
Tenant isolation with RLS
Each workspace is data-isolated at database level, supporting secure multi-tenant operation on one platform.
Flexible member onboarding
Admins invite by email or approve join-code requests, matching different rollout styles across teams.
Scale without per-tenant infrastructure
Add members and profiles as teams grow, avoiding isolated environment sprawl for each organization.
Members
Workspace boundary as core platform unit
Use workspace as primary boundary for data, members, and configuration.
- Keep schema and permissions isolated per organization
- Scope operations to one tenant context
- Support custom workflows without cross-org coupling
Join codes
Isolation enforced with row-level security
Row-level security enforces tenant isolation at the database policy layer.
- Prevent cross-workspace record visibility by default
- Reduce reliance on ad hoc app-side filtering
- Maintain separation on shared infrastructure footprint
Isolation
Onboarding flow for real team growth
Invite by email or approve join-code requests as team access grows.
- Support controlled rollouts with direct invites
- Enable self-service requests through approval queue
- Track who joined and who approved access
Continuity
Role and profile assignment at scale
Assign existing profiles to new roles for predictable access at scale.
- Onboard members without rebuilding per-user policy
- Keep Operations and Views behavior consistent
- Handle growth with repeatable role administration
Scale
One platform footprint, many teams
Run many isolated teams on one platform without per-tenant infrastructure sprawl.
- Scale membership and config inside each workspace
- Avoid separate stacks for every organization
- Reduce maintenance while keeping tenant separation
Questions
Short answers before you request access.
- How does OSTRATA isolate data between workspaces?
- Isolation is enforced with workspace-scoped policies using row-level security at the database layer. Each workspace has separate operational context and data boundaries, so organizations can share platform infrastructure without exposing records across tenants during normal product usage.
- How can admins add new members to a workspace?
- Admins can invite members by email from Setup or share a join code for self-service access requests. Join-code requests enter an approval workflow, giving administrators control while supporting faster onboarding when many teammates need access.
- Does each workspace need separate infrastructure provisioning?
- No. OSTRATA is designed for shared platform operation with tenant isolation handled by workspace boundaries and row-level security. Teams can scale membership and configuration without creating dedicated infrastructure stacks for each organization.
- How do permissions fit into workspace growth?
- Permission profiles are assigned within each workspace, so access management scales with team changes. Admins can onboard new roles by applying profile rules instead of rebuilding policy per user, keeping governance consistent as organizations expand.