Development guides

Beyond login: keep each company’s data separate

Permissions must cover the data itself, including search results, files, exports and administrative actions.

ProApp editorialPublished and checked
A login security token and physical key
AI-generated illustration of the article’s setting.

The workflow illustrates a possible design and is not a client case study.

Illustrative workflow
  1. Identify user and company
  2. Authorize action
  3. Audit and revoke

Hiding a menu does not protect the data

Hiding a menu does not stop someone opening a direct link or calling an API. A person may belong to several companies, and a session may remain active after their role changes. Define which company they are acting for, what they may do and where those checks are enforced.

Review identity and data-access rules

Supabase provides row-level security, but its rules must match your data and company relationships. Review the identity and access design as a whole, including file storage and privileged server operations. A different login screen alone will not separate customer data.

Check permissions through one complete workflow

Map each role to its allowed actions. Follow one complete process through the server, database and attachments. Define invitations, company switching and removal of access. Limit privileged actions and record who approved changes to roles.

Test changed URLs and company identifiers

Use two companies and several roles to test direct requests, search, downloads and exports. Remove a member, expire an invitation and change the company ID in a request. Confirm that access is refused and the response contains no unauthorised data.

Bring roles and company relationships

Bring the roles, company relationships, types of data and actions requiring approval. Include people who work across more than one company.

Working through a similar problem?

Tell us how you work today, which tools you use and what you want to improve. We can discuss changes to your current system, connecting tools or developing something new.