Multi-tenancy
Every Restow installation is multi-tenant internally, even the Community edition, which simply runs as a single tenant. What changes between editions is how many tenants you can run and whether you can delegate their management.
- Provider administrators manage tenants at the installation level and invite tenant administrators. This role only exists meaningfully once you manage more than one tenant.
- Tenant administrators manage sources, schedules, storage, restores and users within their own tenant.
- Tenant users (end users) see and act on only their own mailbox/OneDrive data.
Data isolation
Section titled “Data isolation”Each tenant’s data is isolated by PostgreSQL Row Level Security on a dedicated application database role (isolation is enforced by the database, not only by application logic), and each tenant has its own data-encryption key, wrapped with the installation’s master key.
Whoever operates the server (you) holds that master key and can, technically, unwrap and decrypt any tenant’s data with it. The isolation above stops one tenant reaching another’s data, not the operator reaching either. The application only ever unwraps a tenant’s key through logged operations (a restore, an export), never silently; there is no separate “operator cannot see tenant data” guarantee beyond that.
Editions
Section titled “Editions”- Community and Business: one organization (one tenant).
- Service Provider: any number of tenants in one installation, with delegated tenant administrators, per-tenant reporting, and the integration API available tenant-wide through a provider key. White-label branding is planned for this edition, not built yet.
Import folder and endpoints
Section titled “Import folder and endpoints”Mail files for import can come from a server-side folder. There is one import folder for the installation, and every tenant gets its own subfolder, <folder>/<tenant slug>/, which you create. An administrator of one tenant cannot list or import the files in another tenant’s subfolder: the API and the worker both check that a path lies inside the tenant’s own subfolder. Servers and clients backed up with the agent belong to one tenant each, with their own restic repository in that tenant’s storage target, whose password is sealed with that tenant’s key (Endpoint backup).
Impersonation
Section titled “Impersonation”When an administrator restores or accesses data on behalf of a user (rather than the user doing it themselves), that is impersonation, and it is always logged in the audit log: who acted, when, on whose data, what was done, and from which IP.