TEN · Tenancy
An organization is the tenant. It has legal entities (TOP, MOP), which sign contracts and receive money, and pools (Pamulang…), where cars and drivers belong. Code TEN.
Answered questions
Section titled “Answered questions”- DOC-Q2 (which time zones): a new rule, R-TEN-16: a pool's time zone is one of Indonesia's four.
- DOC-Q6 (global tables): R-TEN-01 now names its exceptions as [Ref] Data model V13 lists them. profiles and permissions are global, with no organization. This makes the wording exact; the rule's meaning is unchanged.
- DOC-Q11 (who reads an organization's row): its members. A new rule, R-TEN-17.
R-TEN-01 · Every row belongs to one organization, except in the tables the data model names
Section titled “R-TEN-01 · Every row belongs to one organization, except in the tables the data model names”- Status: planned
- Example: given a new vehicles row, when it is saved without organization_id, then it is refused. Given a new permissions row, it has no organization_id column at all.
- Refusal: none: not_null_violation (23502).
- Who: every writer.
- Source: [Ref] Data model V13, the columns left out of every table. The exceptions:
- Global, no organization: organizations, profiles (a person may work for several organizations) and permissions (one catalogue for every tenant).
- Belong through their parent: pool_settings, role_permissions and member_rental_companies.
- Organization may be empty for system rows shared by every tenant: roles, charge_types, lead_sources, inspection_item_types and body_panels.
R-TEN-02 · A user sees no row of an organization they aren't a member of
Section titled “R-TEN-02 · A user sees no row of an organization they aren't a member of”- Status: planned
- Example: given Deka, an admin of organization A only, when Deka reads vehicles, then no car of organization B comes back.
- Refusal: none: hidden.
- Who: every signed-in user, whatever their roles.
- Source: [Ref] Roles, permissions and row-level security; the M0 acceptance checks.
R-TEN-03 · System rows of shared lookups (no organization) are visible to every organization
Section titled “R-TEN-03 · System rows of shared lookups (no organization) are visible to every organization”- Status: planned
- Example: given the system charge type rent, which has no organization, when a member of any organization reads charge_types, then rent is among the rows.
- Refusal: none.
- Who: every member of any organization.
- Source: [Ref] Roles, policy matrix (master data); the M0 acceptance checks.
R-TEN-04 · A unique value is unique within its organization, so two organizations may hold the same plate, NIK, code or document number
Section titled “R-TEN-04 · A unique value is unique within its organization, so two organizations may hold the same plate, NIK, code or document number”- Status: planned
- Example: given organization A has plate B1234XYZ, when organization B saves a car with plate B1234XYZ, then it is accepted; a second B1234XYZ inside organization A is refused.
- Refusal: none: unique_violation (23505), within one organization.
- Who: every writer.
- Source: D9 (P3).
R-TEN-05 · A row can't reference a parent row of another organization
Section titled “R-TEN-05 · A row can't reference a parent row of another organization”- Status: planned
- Example: given a driver of organization A and a car of organization B, when a rental of organization A links them, then it is refused.
- Refusal: none: foreign_key_violation (23503), from composite foreign keys (organization_id, id).
- Who: every writer, jobs included: foreign keys ignore row-level security.
- Source: D9 (P2). Due before the second tenant, on drivers, vehicles, rentals and charges.
R-TEN-06 · An organization's slug is unique across all organizations
Section titled “R-TEN-06 · An organization's slug is unique across all organizations”- Status: planned
- Example: given an organization with slug optima, when another organization is saved with slug optima, then it is refused.
- Refusal: none: unique_violation (23505).
- Who: every writer.
- Source: [Ref] Data model V13: organizations.
R-TEN-07 · A legal entity's code is unique within its organization
Section titled “R-TEN-07 · A legal entity's code is unique within its organization”- Status: planned
- Example: given legal entity TOP, when a second TOP is saved in the same organization, then it is refused.
- Refusal: none: unique_violation (23505).
- Who: every writer.
- Source: [Ref] Data model V13: legal_entities.
R-TEN-08 · A pool's code is unique within its organization
Section titled “R-TEN-08 · A pool's code is unique within its organization”- Status: planned
- Example: given pool PML, when a second PML is saved in the same organization, then it is refused.
- Refusal: none: unique_violation (23505).
- Who: every writer.
- Source: [Ref] Data model V13: pools.
R-TEN-09 · A pool's time zone defaults to Asia/Jakarta
Section titled “R-TEN-09 · A pool's time zone defaults to Asia/Jakarta”- Status: planned
- Example: given a new pool saved without a time zone, when it is read back, then timezone is Asia/Jakarta.
- Refusal: none.
- Who: every writer.
- Source: D9 (P11); [Ref] Data model V13: pools.
R-TEN-10 · An organization has at most one subscription
Section titled “R-TEN-10 · An organization has at most one subscription”- Status: planned
- Example: given an organization with a subscription, when a second subscription is saved for it, then it is refused.
- Refusal: none: unique_violation (23505).
- Who: every writer.
- Source: [Ref] Data model V13: subscriptions.
R-TEN-11 · Legal entities and pools are readable by every member of the organization
Section titled “R-TEN-11 · Legal entities and pools are readable by every member of the organization”- Status: planned
- Example: given a satpam at pool PML, when he reads pools, then every pool of his organization comes back, PML and the others.
- Refusal: none.
- Who: every member, whatever their roles.
- Source: [Ref] Roles, policy matrix.
R-TEN-12 · Adding or changing a legal entity or a pool needs master_data:write
Section titled “R-TEN-12 · Adding or changing a legal entity or a pool needs master_data:write”- Status: planned
- Example: given a finance user, when she renames a pool, then nothing changes; an admin's rename goes through.
- Refusal: none: insufficient_privilege (42501) on insert; no effect on update.
- Who: super_admin, admin, maintenance and asuransi hold master_data:write.
- Source: [Ref] Roles, policy matrix.
R-TEN-13 · App users can't delete a legal entity or a pool
Section titled “R-TEN-13 · App users can't delete a legal entity or a pool”- Status: planned
- Example: given a super_admin, when she deletes a pool, then nothing is deleted; a pool that closes is set inactive.
- Refusal: none: no effect, as there is no delete policy.
- Who: every app user, super_admin included.
- Source: [Ref] Roles, policy matrix; D9 (P13).
R-TEN-14 · Reading the organization's subscription needs user:write
Section titled “R-TEN-14 · Reading the organization's subscription needs user:write”- Status: planned
- Example: given an admin, when he reads subscriptions, then no row comes back; a super_admin sees the organization's plan.
- Refusal: none: hidden.
- Who: super_admin holds user:write.
- Source: [Ref] Roles, policy matrix (subscriptions: owner only).
R-TEN-15 · App users can't change the organization's subscription
Section titled “R-TEN-15 · App users can't change the organization's subscription”- Status: planned
- Example: given a super_admin, when she changes the plan to enterprise, then nothing changes.
- Refusal: none: no effect, as there is no insert, update or delete policy.
- Who: every app user. Billing changes come from a job or the migration.
- Source: [Ref] Roles, policy matrix.
R-TEN-16 · A pool's time zone is one of Indonesia's: Asia/Jakarta, Asia/Pontianak, Asia/Makassar or Asia/Jayapura
Section titled “R-TEN-16 · A pool's time zone is one of Indonesia's: Asia/Jakarta, Asia/Pontianak, Asia/Makassar or Asia/Jayapura”- Status: planned
- Example: given a new pool in Balikpapan, when it is saved with Asia/Makassar (WITA), then it is accepted; Asia/Singapore or a misspelt Asia/Jakart is refused.
- Refusal: none: check_violation (23514).
- Who: every writer.
- Source: D9 (P11), which adds the time zone for pools in WITA and WIT cities. Asia/Jakarta and Asia/Pontianak are WIB, Asia/Makassar is WITA, Asia/Jayapura is WIT. Added for DOC-Q2. A pool outside Indonesia would need a change request.
R-TEN-17 · An organization's own row is readable by its members
Section titled “R-TEN-17 · An organization's own row is readable by its members”- Status: planned
- Example: given Deka is a member of organization A only, when he reads organizations, then A's row comes back, so the app can show its name, and no other organization's.
- Refusal: none: hidden.
- Who: every member, whatever their roles.
- Source: [Ref] Roles, The RLS pattern (organization-level tables use app.my_org_ids(): any member reads). Added for DOC-Q11.