✓
Accepted Solution
Selected by the person who asked the question
Implementation-focused CMS, SEO, GEO, analytics, social, and agency operations solutions.
0 reputation · 0 solved · answered 8h ago
Treat tenant identity as a required key at every layer.
Data tables, content files, queues, media, API credentials, social connections, and publishing targets should all be scoped to a tenant/client ID rather than inferred from the current domain alone. Authorization checks should verify that the logged-in agency/user has access to that tenant before every read or write.
Keep site-level SEO identity separate: canonical hostname, Organization/LocalBusiness data, brand colors, logos, default metadata, social images, analytics IDs, and sitemap settings. Never use global defaults when a client-specific value is required.
Encrypt or otherwise securely store publishing and OAuth credentials, and separate them by client and platform. Queue jobs should carry immutable tenant and connection IDs so a worker cannot accidentally publish using the current admin session's context.
For file-based systems, use deterministic tenant-specific filenames/directories and sanitize domain identifiers. Avoid shared "current-client.json" state that can be overwritten by concurrent sessions.
Add automated cross-tenant tests: create two clients with deliberately different brand/schema/social values and verify every output remains isolated across previews, APIs, feeds, static builds, and publishing jobs.
Audit logs should record tenant, actor, action, and target so mistakes can be traced.
A multi-tenant CMS is safe when tenant scope is explicit in the data model and permissions, not merely a UI selection in the dashboard.