Skip to content

TEN · Tenancy

An organization is the tenant. It has legal entities (TOP, MOP), which sign contracts and receive money, and pools (Pamulang…), where cars and drivers belong. Code TEN.

  • DOC-Q2 (which time zones): a new rule, R-TEN-16: a pool's time zone is one of Indonesia's four.
  • DOC-Q6 (global tables): R-TEN-01 now names its exceptions as [Ref] Data model V13 lists them. profiles and permissions are global, with no organization. This makes the wording exact; the rule's meaning is unchanged.
  • DOC-Q11 (who reads an organization's row): its members. A new rule, R-TEN-17.

R-TEN-01 · Every row belongs to one organization, except in the tables the data model names

Section titled “R-TEN-01 · Every row belongs to one organization, except in the tables the data model names”
  • Status: planned
  • Example: given a new vehicles row, when it is saved without organization_id, then it is refused. Given a new permissions row, it has no organization_id column at all.
  • Refusal: none: not_null_violation (23502).
  • Who: every writer.
  • Source: [Ref] Data model V13, the columns left out of every table. The exceptions:
    • Global, no organization: organizations, profiles (a person may work for several organizations) and permissions (one catalogue for every tenant).
    • Belong through their parent: pool_settings, role_permissions and member_rental_companies.
    • Organization may be empty for system rows shared by every tenant: roles, charge_types, lead_sources, inspection_item_types and body_panels.

R-TEN-02 · A user sees no row of an organization they aren't a member of

Section titled “R-TEN-02 · A user sees no row of an organization they aren't a member of”
  • Status: planned
  • Example: given Deka, an admin of organization A only, when Deka reads vehicles, then no car of organization B comes back.
  • Refusal: none: hidden.
  • Who: every signed-in user, whatever their roles.
  • Source: [Ref] Roles, permissions and row-level security; the M0 acceptance checks.

R-TEN-03 · System rows of shared lookups (no organization) are visible to every organization

Section titled “R-TEN-03 · System rows of shared lookups (no organization) are visible to every organization”
  • Status: planned
  • Example: given the system charge type rent, which has no organization, when a member of any organization reads charge_types, then rent is among the rows.
  • Refusal: none.
  • Who: every member of any organization.
  • Source: [Ref] Roles, policy matrix (master data); the M0 acceptance checks.

R-TEN-04 · A unique value is unique within its organization, so two organizations may hold the same plate, NIK, code or document number

Section titled “R-TEN-04 · A unique value is unique within its organization, so two organizations may hold the same plate, NIK, code or document number”
  • Status: planned
  • Example: given organization A has plate B1234XYZ, when organization B saves a car with plate B1234XYZ, then it is accepted; a second B1234XYZ inside organization A is refused.
  • Refusal: none: unique_violation (23505), within one organization.
  • Who: every writer.
  • Source: D9 (P3).

R-TEN-05 · A row can't reference a parent row of another organization

Section titled “R-TEN-05 · A row can't reference a parent row of another organization”
  • Status: planned
  • Example: given a driver of organization A and a car of organization B, when a rental of organization A links them, then it is refused.
  • Refusal: none: foreign_key_violation (23503), from composite foreign keys (organization_id, id).
  • Who: every writer, jobs included: foreign keys ignore row-level security.
  • Source: D9 (P2). Due before the second tenant, on drivers, vehicles, rentals and charges.

R-TEN-06 · An organization's slug is unique across all organizations

Section titled “R-TEN-06 · An organization's slug is unique across all organizations”
  • Status: planned
  • Example: given an organization with slug optima, when another organization is saved with slug optima, then it is refused.
  • Refusal: none: unique_violation (23505).
  • Who: every writer.
  • Source: [Ref] Data model V13: organizations.
Section titled “R-TEN-07 · A legal entity's code is unique within its organization”
  • Status: planned
  • Example: given legal entity TOP, when a second TOP is saved in the same organization, then it is refused.
  • Refusal: none: unique_violation (23505).
  • Who: every writer.
  • Source: [Ref] Data model V13: legal_entities.

R-TEN-08 · A pool's code is unique within its organization

Section titled “R-TEN-08 · A pool's code is unique within its organization”
  • Status: planned
  • Example: given pool PML, when a second PML is saved in the same organization, then it is refused.
  • Refusal: none: unique_violation (23505).
  • Who: every writer.
  • Source: [Ref] Data model V13: pools.

R-TEN-09 · A pool's time zone defaults to Asia/Jakarta

Section titled “R-TEN-09 · A pool's time zone defaults to Asia/Jakarta”
  • Status: planned
  • Example: given a new pool saved without a time zone, when it is read back, then timezone is Asia/Jakarta.
  • Refusal: none.
  • Who: every writer.
  • Source: D9 (P11); [Ref] Data model V13: pools.

R-TEN-10 · An organization has at most one subscription

Section titled “R-TEN-10 · An organization has at most one subscription”
  • Status: planned
  • Example: given an organization with a subscription, when a second subscription is saved for it, then it is refused.
  • Refusal: none: unique_violation (23505).
  • Who: every writer.
  • Source: [Ref] Data model V13: subscriptions.
Section titled “R-TEN-11 · Legal entities and pools are readable by every member of the organization”
  • Status: planned
  • Example: given a satpam at pool PML, when he reads pools, then every pool of his organization comes back, PML and the others.
  • Refusal: none.
  • Who: every member, whatever their roles.
  • Source: [Ref] Roles, policy matrix.
Section titled “R-TEN-12 · Adding or changing a legal entity or a pool needs master_data:write”
  • Status: planned
  • Example: given a finance user, when she renames a pool, then nothing changes; an admin's rename goes through.
  • Refusal: none: insufficient_privilege (42501) on insert; no effect on update.
  • Who: super_admin, admin, maintenance and asuransi hold master_data:write.
  • Source: [Ref] Roles, policy matrix.
Section titled “R-TEN-13 · App users can't delete a legal entity or a pool”
  • Status: planned
  • Example: given a super_admin, when she deletes a pool, then nothing is deleted; a pool that closes is set inactive.
  • Refusal: none: no effect, as there is no delete policy.
  • Who: every app user, super_admin included.
  • Source: [Ref] Roles, policy matrix; D9 (P13).

R-TEN-14 · Reading the organization's subscription needs user:write

Section titled “R-TEN-14 · Reading the organization's subscription needs user:write”
  • Status: planned
  • Example: given an admin, when he reads subscriptions, then no row comes back; a super_admin sees the organization's plan.
  • Refusal: none: hidden.
  • Who: super_admin holds user:write.
  • Source: [Ref] Roles, policy matrix (subscriptions: owner only).

R-TEN-15 · App users can't change the organization's subscription

Section titled “R-TEN-15 · App users can't change the organization's subscription”
  • Status: planned
  • Example: given a super_admin, when she changes the plan to enterprise, then nothing changes.
  • Refusal: none: no effect, as there is no insert, update or delete policy.
  • Who: every app user. Billing changes come from a job or the migration.
  • Source: [Ref] Roles, policy matrix.

R-TEN-16 · A pool's time zone is one of Indonesia's: Asia/Jakarta, Asia/Pontianak, Asia/Makassar or Asia/Jayapura

Section titled “R-TEN-16 · A pool's time zone is one of Indonesia's: Asia/Jakarta, Asia/Pontianak, Asia/Makassar or Asia/Jayapura”
  • Status: planned
  • Example: given a new pool in Balikpapan, when it is saved with Asia/Makassar (WITA), then it is accepted; Asia/Singapore or a misspelt Asia/Jakart is refused.
  • Refusal: none: check_violation (23514).
  • Who: every writer.
  • Source: D9 (P11), which adds the time zone for pools in WITA and WIT cities. Asia/Jakarta and Asia/Pontianak are WIB, Asia/Makassar is WITA, Asia/Jayapura is WIT. Added for DOC-Q2. A pool outside Indonesia would need a change request.

R-TEN-17 · An organization's own row is readable by its members

Section titled “R-TEN-17 · An organization's own row is readable by its members”
  • Status: planned
  • Example: given Deka is a member of organization A only, when he reads organizations, then A's row comes back, so the app can show its name, and no other organization's.
  • Refusal: none: hidden.
  • Who: every member, whatever their roles.
  • Source: [Ref] Roles, The RLS pattern (organization-level tables use app.my_org_ids(): any member reads). Added for DOC-Q11.