Security By Tenant

Your theater stays your theater.

PlayhouseOps is designed so each customer operates in an isolated application environment with separate operational data and file storage.

Tenant Isolation

Tenant isolation is part of the architecture, not an account setting.

PlayhouseOps is designed so each theater operates in its own application environment with tenant-specific operational data and file storage. A small platform control plane handles platform-level identity, routing, memberships, and deployment state without becoming the theater's production database.

Isolated Application

Each tenant operates through its own application environment rather than sharing one unrestricted runtime with every PlayhouseOps customer.

Isolated Operational Database

Customer production and operational records are maintained in a tenant-specific database rather than a shared table structure containing every customer's theater data.

Isolated File Storage

Tenant files are maintained in tenant-specific storage rather than a common customer file repository.

PLAYHOUSEOPS PLATFORM
Authentication โ†’ Tenant Routing
TENANT AApplicationDatabaseFile Storage
TENANT BApplicationDatabaseFile Storage

The platform knows where to send you. It does not become your theater database.

PlayhouseOps uses a small platform control plane for platform-level information such as tenant identity, routing, memberships, and deployment state. Production records, performers, inventory, schedules, department work, and tenant files remain in the tenant environment.

Access follows identity, tenant, and role.

Authentication identifies the user. Tenant membership determines which theater environment the user can enter. Tenant-level authorization then determines what that person can do inside the theater environment.

  • Authenticate
  • Resolve tenant membership
  • Enter tenant
  • Apply tenant role and production access

Three Layers

Public, platform, and tenant stay separate.

Public Site

No tenant login required. No tenant operational data required to render the public site.

PlayhouseOps Platform Administration

Protected environment for platform administration and tenant routing.

Tenant Application

Protected customer environment containing tenant-specific operational data and configuration.

Configuration stays with the tenant.

Tenant-specific branding and operational configuration remain part of the tenant environment rather than being merged into the public PlayhouseOps identity. This supports universities and organizations that want their environment to feel like their own.

Need to review the architecture before a demo?

We can walk through tenant isolation, identity flow, data boundaries, and the deployment model with your technical or security team.