Control Packs · DAT-003 · v1.0.0
Tenant Data Isolation
Define storage, query, cache, and operational boundaries that prevent one tenant's data from appearing in another tenant's context.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Make tenant isolation explicit across storage, retrieval, caching, logging, deletion, and export paths.
- Tenant data is mixed across a boundaryStorage, cache, search, logs, or exports allow data from one tenant to be selected or disclosed in another tenant's context.
Versioned applicability rule
{
"all": [
{
"characteristic": "MULTI_TENANT",
"equals": true
},
{
"characteristic": "SENSITIVE_DATA",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which data paths require an explicit tenant-isolation check?Isolation can fail outside the primary database query, including caches, search, logs, and exports.DAT-003-Q1 · multi_select
Requirements for the coding agent
- DAT-003-R1Enforce tenant context at storage, retrieval, cache, search, logging, deletion, and export boundaries, and test cross-tenant denial.
Tests and evidence to retain
- TENANT_DATA_BOUNDARY_TESTVerify tenant-scoped reads, writes, cache keys, search filters, deletion, export, and denied cross-tenant access.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-3 · Access EnforcementNIST_SP_800_53_5_2_0 · partially addressesTenant context at authorization and data boundaries supports a defined access partition; it does not cover all access enforcement.
- AC-4 · Information Flow EnforcementNIST_SP_800_53_5_2_0 · partially addressesCross-tenant denial across storage, cache, search, logs, and export addresses selected information flows; it is not complete flow coverage.
- PT-5 · Processing Personally Identifiable InformationNIST_SP_800_53_5_2_0 · partially addressesTenant-scoped processing and deletion boundaries reduce inappropriate PII processing; they do not establish privacy compliance.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Privacy FrameworkGUIDANCE_DATA_MINIMIZATION
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_LEAST_AUTHORITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0