> ## Documentation Index
> Fetch the complete documentation index at: https://docs.amdital.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-tenant Architecture

> Build multi-tenant applications on AmDital's platform.

## Tenant Model

Every resource in AmDital belongs to a workspace. The workspace is resolved from your authenticated session or API key — never from a URL parameter or request body — so a request can only ever act on the workspace its credential actually belongs to.

```bash theme={null}
# workspace is resolved from your Bearer token, not passed explicitly
GET https://api.amdital.com/api/v1/tasks \
  -H "Authorization: Bearer YOUR_API_KEY"
```

## Data Isolation

AmDital enforces tenant isolation at three layers:

* Postgres Row-Level Security per `workspace_id`
* Every query carries a `workspace_id` predicate at the application data-access layer, even for trusted-origin reads
* Application-layer workspace membership verification

## Membership & Roles

Workspace members have roles (owner, admin, manager, employee, client, consultant) stored in `workspace_members`. The JWT carries the workspace role claim for server-side enforcement.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.