Auth checklist
Tenant model
- What is the real customer boundary in this app?
Single tenant | Multi-tenant workspace | Hybrid or mixed model - Can one user belong to more than one customer, workspace, or account?
No | Yes | Not sure yet - Will users need to switch context inside the product?
No | Yes | Maybe later
User hierarchy
- How deep should the access hierarchy be at launch?
Flat users only | App admins and members | System admins plus workspace roles - Do teams, departments, or groups need to exist in version one?
No | Yes | Maybe later - Do internal operators need support or impersonation access?
No | Read-only support | Full support tools
Access and onboarding
- Which sign-in methods are needed first?
Email and password | Magic link | Social auth | Enterprise SSO - How should users get into the app?
Self-serve signup | Invite-only | Admin-created | Sales-assisted - What should happen when access changes later?
Soft disable only | Suspend and restore | Offboard with audit trail