No path between tenants
Three tenants, three datasets, three identities. A request from one carries no credential that the others would honor. The column that scopes every row is not a filter a teammate can remove.
tenant A
Last 5 minutes · ticket #4471 · six actors on the record
A live audit feed. Customer, agent, assistant, connector, system: all on the same record.
Real engineering, scoped to one tenant, signed by one identity, read by one audit trail. The controls live in the data layer, the identity model, and the tool call, not in a separate security tab.
At a 40-person consumer brand, every assistant tool call in the first 90 days carried an identity, a scope, and a reversible permission. (Composite illustration.)
Tenant isolation
The tenant is the security boundary. Every query, every assistant action, every file lookup carries a tenant scope. There is no API path, no admin command, no assistant tool call that crosses from one tenant to another. The isolation lives in the data model, not in a policy a teammate could relax.
Where the boundary holds
Three tenants, three datasets, three identities. A request from one carries no credential that the others would honor. The column that scopes every row is not a filter a teammate can remove.
tenant A
Identity
One identity model for everyone who touches a ticket: your staff, the assistant, the automations, the connectors that reach out on their behalf.
mode A
BootDesk as IdP
Accounts live here. Sign in to BootDesk, sign in to everything.
mode B
Accept yours
Wire your corporate identity. Single sign-on in, sessions out.
mode C
Both at once
Internal staff on yours, contractors on ours, one workspace.
Who authenticates
Attribution · audit trail
Every assistant call, every staff message, every connector invocation runs under a scoped identity. Every grant, every file access, every tool call touches the same audit trail. When something goes wrong, you know who or what did it. Compliance teams can read it. Nothing happens off-record.
Audit export · tenant #8217 · 24h window
File security
Scan at intake. Sign in place. Expire on close.
Every file that enters a ticket is scanned before it can be opened. Documents edit inside the platform, nothing leaves to get a signature. Shares sign and expire. The file never travels somewhere unprotected to collect a mark.
Inbound · ticket #4471
3 filesrouting-slip-8830.docx
uploaded by customer · 248 kb
invoice-8830.pdf
uploaded by customer · 92 kb
payload.exe
The assistant operates under permissions your admins granted. It cannot exceed them. Every tool call is logged beside the ticket. You can revoke any permission at any time, and the assistant stops reaching for that tool on the next request.
Assistant · warehouse-ops
4 grants · 1 revokedstore.orders.read
Read order status, history, tracking.
store.orders.refund
Issue refunds up to $50. Above requires agent approval.
sms.outbound
Send transactional notifications to ticket contacts.
slack.post · #logistics-ops
Post updates to one channel. No DM access.
payments.dispute
Revoked 09:42 after policy review.
Grants are scoped to an assistant, a tenant, and a tool. No wildcard grants. No grant outlives the admin who issued it unless another admin renews it.
Enterprise tier
The controls below ship at the Enterprise tier. They layer on top of the tenant boundary, the identity model, and the audit trail you already have. Nothing here is a substitute for the foundations. It is the set of levers a security or compliance team expects to pull.
Full single sign-on as provider or consumer. Connect your corporate identity system to BootDesk, or let BootDesk issue identities to the apps around it. Group claims, scopes, and session lifetimes map cleanly.
Works with any standards-compliant identity provider your security team already operates.
sign-on · session · scopes
provider or consumer
Tamper-evident export to your SIEM. Streaming webhooks for real-time review.
tenant B
tenant C
no path · no override · no admin
The tenant column is part of the read path. A query without a tenant scope returns nothing, never the wrong tenant.
A connector invoked inside a ticket can only reach the tenant that ticket belongs to. The scope is bound at invocation.
Upload paths, signed URLs, and edit sessions all resolve against the invoking tenant. A link from tenant A opens nothing in tenant B.
Every staff member, assistant, and automation belongs to exactly one tenant. Cross-tenant membership is not a grant anyone can issue.
A note on the word structural. We mean it literally. The boundary does not depend on a developer remembering to add a where clause. The data layer carries the scope on every read.
BootDesk ships with its own identity server. It can act as your identity provider, or it can accept yours. Either way, staff, assistants, and automations authenticate through one identity model, and every authenticated session writes to the same audit trail.
There is no second class of credential for the assistant. No backdoor for the automation. If it touches a ticket, it carries a signed identity.
10 of 12,438 rows shown. Every actor carries a scoped identity. Every row is exportable.
A note on off-record. There is no off-record. The audit trail is the same surface compliance reads during a review and your engineer reads during an incident. One source of truth, no parallel log.
virus scan flagged · blocked from open
Edit · sign · share
nothing leavesedit · in platform
routing-slip-8830.docx
Opened in the workspace editor. Edits save back to the tenant. No download round-trip.
sign · inside the tenant
agreement-8830.pdf
Signature collected on a signed URL that resolves against this tenant only. Document never leaves to get marked.
share · expiring
share · /s/8a2f
Link expires in 72 hours. Revokes on ticket close. Read-only by default.
read order #8830 · under grant g_7741
posted update to #logistics-ops
refund $42.00 · approved by m.bennett
grant revoked at 09:42 · routed to agent instead
notification sent · receipt in audit trail
Scheduled JSON and CSV drops. Signed and timestamped. Ready for reviewer.
Per-record-type retention rules. Hold tickets on legal hold, expire the rest on schedule.
Pin a tenant to a region. Records, files, and audit rows stay in the region you chose. No cross-region leakage.
Outbound email signed and aligned to your domain. Inbound checked against published policy. Spoofed senders get quarantined, not threaded.
The assistant does not care which lab trained the weights. Point it at the model accounts you already pay for, in the region you already chose. Your keys stay in your tenant.
A note on tiering. The boundary, the identity model, and the audit trail are not Enterprise features. Every tier gets them. The list above is the set of levers a larger organization pulls on top.