--- kind: epic slug: multitenancy title: Tenant isolation for backlog and Cursor connections plan_slug: multitenant-cursor-sync status: ready priority: P0 tenant_id: global cursor_epic_id: null updated_at: "2026-04-26" --- # Epic objective Ensure every **plan, epic, task**, markdown path, and Cursor credential set is **scoped to a tenant**, with authorization enforced on all sync and CRUD paths. ## In scope / out of scope **In scope** - Tenant id on all backlog entities and mappings - Router guards: user ∈ tenant before read/write - Documentation of isolation guarantees in `docs/Glossary.md` **Out of scope** - Billing per tenant - Cross-tenant reporting ## Related tasks | Task | Link | |------|------| | Tenant-scoped Cursor connections | `./Task-tenant-scoped-cursor-connections.md` | ## Dependencies - Depends on: existing workspace / membership model in app DB - Blocks: Cursor sync layer (production) ## Acceptance criteria - [ ] Impossible for tenant A’s job to read tenant B’s `plans/` prefix or mapping rows (test with two tenants). ## Proposed timeline | Phase | Window | Notes | |-------|--------|-------| | Audit | Week 1 | List all routers touching objects/search | | Enforce | Week 2+ | Add membership checks |