Security By Tenant
Your theater stays your theater.
PlayhouseOps is designed so each customer operates in an isolated application environment with separate operational data and file storage.
Tenant Isolation
Tenant isolation is part of the architecture, not an account setting.
PlayhouseOps is designed so each theater operates in its own application environment with tenant-specific operational data and file storage. A small platform control plane handles platform-level identity, routing, memberships, and deployment state without becoming the theater's production database.
Isolated Application
Each tenant operates through its own application environment rather than sharing one unrestricted runtime with every PlayhouseOps customer.
Isolated Operational Database
Customer production and operational records are maintained in a tenant-specific database rather than a shared table structure containing every customer's theater data.
Isolated File Storage
Tenant files are maintained in tenant-specific storage rather than a common customer file repository.
The platform knows where to send you. It does not become your theater database.
PlayhouseOps uses a small platform control plane for platform-level information such as tenant identity, routing, memberships, and deployment state. Production records, performers, inventory, schedules, department work, and tenant files remain in the tenant environment.
Access follows identity, tenant, and role.
Authentication identifies the user. Tenant membership determines which theater environment the user can enter. Tenant-level authorization then determines what that person can do inside the theater environment.
- Authenticate
- Resolve tenant membership
- Enter tenant
- Apply tenant role and production access
Three Layers
Public, platform, and tenant stay separate.
Public Site
No tenant login required. No tenant operational data required to render the public site.
PlayhouseOps Platform Administration
Protected environment for platform administration and tenant routing.
Tenant Application
Protected customer environment containing tenant-specific operational data and configuration.
Configuration stays with the tenant.
Tenant-specific branding and operational configuration remain part of the tenant environment rather than being merged into the public PlayhouseOps identity. This supports universities and organizations that want their environment to feel like their own.
Need to review the architecture before a demo?
We can walk through tenant isolation, identity flow, data boundaries, and the deployment model with your technical or security team.
