Internal Engineering Demonstration
Multi-Tenant SaaS Starter
Internal engineering demonstration. This is not a client deployment. All scenarios, figures and outcomes are illustrative and created to showcase NorthFlow Studio's technical approach.
Business challenge
- Teams need a SaaS starting point without rebuilding auth, billing and tenancy.
- Tenant isolation is easy to get wrong.
- Onboarding should be self-serve.
Objectives
- Scaffold time: Ship a working SaaS scaffold in under 1 week
- Tenant isolation: Row-level security enforced by default, zero config
- Onboarding: Self-serve signup with Stripe billing out of the box
Architecture
Browser
│
▼
[ App (stateless) ] ──▶ [ Postgres + RLS ]
│
└─▶ [ Queue ] ──▶ [ Worker ] ──▶ email / billing
Stateless app + isolated data via RLS.
rls
create policy "tenant isolation" on invoices
for all
using (tenant_id = current_setting('app.tenant_id')::uuid);Technology
TanStack StartSupabasePostgreSQLStripeTypeScript
Features
- Supabase auth with email/password and OAuth providers (Google, GitHub)
- Tenant-scoped routing via middleware that sets Postgres RLS context
- Stripe checkout with webhook-driven subscription and invoice handling
- Role-based dashboard with minimal and admin views per tenant
Implementation
- 1Scaffold app router with marketing and app route groups.
- 2Wire Supabase auth and set tenant context per request.
- 3Add Stripe checkout + webhook worker for subscriptions.
- 4Build a minimal dashboard with role-based views.
Tradeoffs
Shared vs separate DB
Shared schema with RLS is simpler to start; split only when compliance requires.
Stripe vs custom billing
Stripe removes PCI scope and handles invoicing.
Performance
- Static marketing routes; dynamic app routes isolated.
- Indexes on tenant_id for hot queries.
Lessons learned
- Set tenant context from a verified session on every connection.
- Keep billing out of the request path.
Future roadmap
- Add feature flags and per-tenant config.
- Add a usage metering layer.
Demo video placeholder
Screenshot / GitHub placeholder
FAQ
Is this a real product?+
No. It's a reference demonstration we share, not a live client product.
Can we use it?+
Yes — it's linked from our Open Source page under a permissive license.
Want a walkthrough for your system?
Book a free strategy call. We'll map your bottlenecks to the right systems and send a clear roadmap — even if we don't work together.
Usually replies within minutes. Chat on Telegram: @northflowstudio
No obligation consultationFounder-led projectsInternational clientsFast responseSecure communication