Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption.

MITAuto-check passedBackend & APIs

Install Multitenant

skills CLI
$ npx skills add TheBeardedBearSAS/claude-craft --skill multitenant -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TheBeardedBearSAS/claude-craft multitenant --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TheBeardedBearSAS/claude-craft.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/multitenant .claude/skills/multitenant && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
multitenant
GitHub stars
107
Token cost
~758 tokens
SKILL.md length
293 words
Files
2
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption.

  • Works in 5 steps: tenant_id propagé à chaque requête… → PostgreSQL Row-Level Security (RLS)… → Tests d'isolation obligatoires. Tenant A… → …
  • Working with multitenant applications
  • SKILL.md covers Trois tiers d'isolation, Cinq invariants non-négociables, Pattern minimal — Shared… and Anti-patterns critiques, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Multitenant is an agent skill from TheBeardedBearSAS/claude-craft. Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption. Use when working with multitenant applications, tenant isolation, data segregation.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `REFERENCE.md`).

It sits in Backend & APIs, covering Multi-tenancy and Authorization and RBAC. The repository describes itself as: Supercharge Claude Code with Expert Knowledge A comprehensive framework for AI-assisted development. Install standardized rules, agents, and commands for your projects across… The licence is MIT.

When your agent uses it

  • Working with multitenant applications
  • Tenant isolation
  • Data segregation

Example prompts

  • “/multitenant”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. tenant_id propagé à chaque requête (AsyncLocalStorage / SecurityContext / middleware).
  2. PostgreSQL Row-Level Security (RLS) activé sur TOUTES les tables. Filet de sécurité contre un oubli applicatif.
  3. Tests d'isolation obligatoires. Tenant A ne doit jamais lire/écrire les données de B — y compris via tri, requête nuée, agrégat.
  4. Audit trail isolé par tenant. Pas de log multi-tenant cross-référencé sans permission explicite.
  5. Field-level encryption sur PII / secrets sensibles (Halite PHP, Eloquent Casts, libsodium).

What it can do on your machine

Read from SKILL.md and the folder at commit 99c1ee3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql and php).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Multitenant loads about 758 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~758

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TheBeardedBearSAS/claude-craft at commit 99c1ee3, republished under its MIT licence (© TheBeardedBearSAS). 293 words, ~758 tokens.

Download SKILL.mdSave it as .claude/skills/multitenant/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
multitenant
description
Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption. Use when working with multitenant applications, tenant isolation, data segregation.
context
fork files: ["**/TenantFilter.php", "**/TenantScope.php", "**/middleware/Tenant*"]

Multitenant — Quick Reference

Servir plusieurs clients (tenants) sur la même base de code avec isolation stricte et un coût d'infra contrôlé.

Trois tiers d'isolation

TierIsolationCoûtCas d'usage
Tier 1 — Shared schemacolonne tenant_id partout, filtres SQL automatiquesFaibleStartups, free / petits clients
Tier 2 — Dedicated schemaun schéma PostgreSQL par tenantMoyenSMB, clients exigeants
Tier 3 — Dedicated DBune base entière par tenantÉlevéEnterprise, compliance stricte (HDS, FedRAMP)

Règle de migration : commencer Tier 1, migrer un client en Tier 2/3 quand il représente > 20 % du revenu OU exige un SLA spécifique.

Cinq invariants non-négociables

  1. tenant_id propagé à chaque requête (AsyncLocalStorage / SecurityContext / middleware).
  2. PostgreSQL Row-Level Security (RLS) activé sur TOUTES les tables. Filet de sécurité contre un oubli applicatif.
  3. Tests d'isolation obligatoires. Tenant A ne doit jamais lire/écrire les données de B — y compris via tri, requête nuée, agrégat.
  4. Audit trail isolé par tenant. Pas de log multi-tenant cross-référencé sans permission explicite.
  5. Field-level encryption sur PII / secrets sensibles (Halite PHP, Eloquent Casts, libsodium).

Pattern minimal — Shared schema + RLS

sql
ALTER TABLE invoices ADD COLUMN tenant_id UUID NOT NULL;
ALTER TABLE invoices ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON invoices
  USING (tenant_id = current_setting('app.tenant_id')::uuid);
php
// Symfony — middleware qui set la variable session pour RLS
$conn->executeStatement(
    'SET LOCAL app.tenant_id = :tid',
    ['tid' => $tenantId]
);

Anti-patterns critiques

  • ❌ Oublier le filtre tenant_id dans une requête raw → fuite cross-tenant.
  • ❌ Cache Redis sans préfixe tenant → données de A retournées à B.
  • ❌ Job worker async qui perd le tenant_id → impossible de retrouver le contexte.
  • ❌ Signed URLs / tokens sans tenant_id dans le payload → utilisable cross-tenant.
  • ❌ Field encryption avec une clé unique partagée → compromission = exposition totale (préférer keys per tenant).

RBAC / ABAC

  • RBAC : rôles globaux (admin, member, viewer) suffisent pour 80 % des cas.
  • ABAC : passer à des policies (Casbin, Cerbos, OPA) quand les règles dépendent d'attributs (région, montant, statut).

Pour aller plus loin

Patterns détaillés par tier, migration tier 1 → tier 2 sans downtime, tests d'isolation (Pest + tenant fixtures), RBAC/ABAC, exemples Laravel + Symfony, checklists par phase : voir @.claude/skills/multitenant/REFERENCE.md.

© TheBeardedBearSAS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/multitenant of TheBeardedBearSAS/claude-craft.

  • SKILL.md
  • REFERENCE.md

Open the folder on GitHubat commit 99c1ee3

Compare with similar skills

Multitenant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Multitenant compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Multitenant this skillTheBeardedBearSAS/claude-craft107—~758Automated safety check: PassMIT
Abp Authorizationabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Arandu Shared Modules Guidearandu-io/arandu281—~1.8kAutomated safety check: PassMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Backend AI Guidelablup/backend.ai-webui1331 repos~1.8kAutomated safety check: PassLGPL-3.0

Similar skills

  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed
  • Arandu Policy and Grants

    arandu-io/arandu

    Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

    281 GitHub stars~1.4k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from TheBeardedBearSAS/claude-craft

All 12 skills in this repo
  • Architect

    TheBeardedBearSAS/claude-craft

    Phase d'architecture systématique AVANT le code (TDD). An agent skill from TheBeardedBearSAS/claude-craft.

    107 GitHub stars~1.2k tokensUpdated 24 days ago
    Auto-check passed
  • Async

    TheBeardedBearSAS/claude-craft

    Architecture async-first avec messaging et queues (Symfony Messenger, Laravel Queue, Ecotone).

    107 GitHub stars~741 tokensUpdated 24 days ago
    Auto-check passed
  • Atomic Tasks

    TheBeardedBearSAS/claude-craft

    Pattern GSD (Get Shit Done) - découper en tâches atomiques avec contextes subagent frais pour combattre le context rot.

    107 GitHub stars~1.1k tokensUpdated 24 days ago
    Auto-check passed
  • Cqrs

    TheBeardedBearSAS/claude-craft

    CQRS - Command Query Responsibility Segregation. An agent skill from TheBeardedBearSAS/claude-craft.

    107 GitHub stars~833 tokensUpdated 24 days ago
    Auto-check passed
  • Design Md Convention

    TheBeardedBearSAS/claude-craft

    Convention DESIGN.md pour design systems AI-friendly. An agent skill from TheBeardedBearSAS/claude-craft.

    107 GitHub stars~1.1k tokensUpdated 24 days ago
    Auto-check passed
  • Docker Hadolint

    TheBeardedBearSAS/claude-craft

    Docker & Hadolint validation (2026). An agent skill from TheBeardedBearSAS/claude-craft.

    107 GitHub stars~498 tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Multitenant

What does Multitenant do?

Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption. Multitenant is an agent skill from TheBeardedBearSAS/claude-craft. Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption.

When should I use Multitenant?

Multitenant fits situations like: working with multitenant applications; tenant isolation; data segregation.

How do I install Multitenant in Claude Code?

Run `npx skills add TheBeardedBearSAS/claude-craft --skill multitenant -a claude-code`. Or copy the skill folder (.claude/skills/multitenant in TheBeardedBearSAS/claude-craft) into .claude/skills/multitenant in your project. Claude Code loads it when a task matches its description.

How do I install Multitenant in Codex?

Run `npx skills add TheBeardedBearSAS/claude-craft --skill multitenant -a codex`. Or copy the skill folder (.claude/skills/multitenant in TheBeardedBearSAS/claude-craft) into .agents/skills/multitenant in your project. Codex loads it when a task matches its description.

Can I use Multitenant in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheBeardedBearSAS/claude-craft --skill multitenant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/multitenant, .gemini/skills/multitenant, .github/skills/multitenant and .opencode/skills/multitenant in your project.

What does Multitenant need to run?

SKILL.md names no scripts, command-line tools or credentials: Multitenant is instructions for the agent only.

Does Multitenant access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Multitenant safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Multitenant use?

Multitenant is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Multitenant use?

About 758 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Multitenant?

Skills that share tags, products or a category with Multitenant: Abp Authorization (abpframework/abp, 14k stars), Django Access Review (getsentry/skills, 1k stars), Arandu Shared Modules Guide (arandu-io/arandu, 281 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Multitenant?

TheBeardedBearSAS (a GitHub organization) maintains it in TheBeardedBearSAS/claude-craft, which has 107 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 14, 2026.

Source: TheBeardedBearSAS/claude-craft on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.