Beyond login: keep each company’s data separate
Permissions must cover the data itself, including search results, files, exports and administrative actions.

The workflow illustrates a possible design and is not a client case study.
- Identify user and company
- Authorize action
- Audit and revoke
Hiding a menu does not protect the data
Hiding a menu does not stop someone opening a direct link or calling an API. A person may belong to several companies, and a session may remain active after their role changes. Define which company they are acting for, what they may do and where those checks are enforced.
Review identity and data-access rules
Supabase provides row-level security, but its rules must match your data and company relationships. Review the identity and access design as a whole, including file storage and privileged server operations. A different login screen alone will not separate customer data.
Check permissions through one complete workflow
Map each role to its allowed actions. Follow one complete process through the server, database and attachments. Define invitations, company switching and removal of access. Limit privileged actions and record who approved changes to roles.
Test changed URLs and company identifiers
Use two companies and several roles to test direct requests, search, downloads and exports. Remove a member, expire an invitation and change the company ID in a request. Confirm that access is refused and the response contains no unauthorised data.
Bring roles and company relationships
Bring the roles, company relationships, types of data and actions requiring approval. Include people who work across more than one company.