Organization isolation
Row Level Security scopes organization records by membership and permission.
SECURITY
Fourth Rein separates organization access from Fourth Rein platform administration and keeps privileged operations server-side.
Row Level Security scopes organization records by membership and permission.
Organization Owners/Admins and Fourth Rein global administrators use authenticator-based MFA for privileged sessions.
Production/customer files stay in private object storage and are accessed with time-limited signed URLs.
The private global-admin application is not linked from the organization product and uses a dedicated platform-admin identity.
Production locks, customer approvals, project history and platform-admin actions are designed to retain an accountable record.
Database service credentials, deploy hooks and provider tokens stay in server environment variables, not browser code.