Agencies, clients and who can see what
The tenancy model: one agency, many client brands, and the isolation boundary between them.
The hierarchy is two levels: an agency holds many brands. Every user belongs to exactly one agency, and every query in the platform is scoped to that agency before it touches data.
Roles
| Role | Can do | Cannot do |
|---|---|---|
| Owner | Everything, including billing, branding and provisioning users | — |
| Admin | Add and configure brands, prompts, competitors; invite users | Change billing |
| Member | Read every brand in the agency, run reports, export | Change configuration or provision users |
Isolation
Cross-tenant access is the control this product cannot get wrong: agencies compete with each other, and a leak between two of them is a business-ending event rather than an inconvenience. Every request resolves a tenant context server-side and every page inside the application resolves its own — a build-time test fails if a new page forgets.
A request for a brand belonging to another agency is refused as if the brand did not exist. It is not an authorisation error, because an authorisation error confirms the brand exists.
There is no self-serve sign-up
Users are provisioned by their agency. There is no public registration form, because there is no plan under which an unaffiliated individual has a workspace to land in.
See it against your own client list
A working demo runs your prompts, in your market, on live engines — not a sandbox with seeded data. Bring one client brand and three competitors.