rls-multi-tenant
Builds tenant isolation on Azure SQL Database that a test can prove, with a row level security policy whose filter predicate and block predicate are written together, because a filter alone still accepts a cross-tenant write and hides the row from the app that made it. Use when asked to add row level security, isolate tenants in a shared table, write a security policy or predicate function, set the current tenant through SESSION_CONTEXT or a database user per tenant, or prove one tenant cannot read another; and when a multi-tenant app returns the wrong tenant's rows under load, retrieval returns another tenant's chunk, a policy is in place and all rows are still visible, or error 33504 appears on an insert or update. Covers pooling against a session-scoped tenant id, who can turn a policy off, and the isolation test. Identity is entra-id-auth, the table design design-azure-sql-schema.
Pinned to revision eeb1c6867c2d, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/rls-multi-tenant/SKILL.md
- skills/rls-multi-tenant/references/block-predicates-pooling-and-bypass.md
Every link opens the file at its source, pinned to the revision this page describes.