Home/Labs/Tenancy Isolation Model Pricing
All 280 Labs
INTERACTIVE LAB🏢

Multi-Tenancy Architecture Lab (Interactive)

Price Pool, Bridge and Silo tenancy against tenant count, migration blast radius and a noisy neighbor load. Toggle PostgreSQL row-level security and scale tenants to see cost, onboarding, data-leak risk and compliance diverge by model.

Pool · Bridge · Silo Tenancy Isolation Lab

Price the three SaaS isolation models against tenant count, migration blast radius and a noisy neighbor.

Platform $/mo (per tenant)

$955 ($1.91)

Schema migration run

4 min

Shared-pool p99 inflation

×3.67

Tenant onboarding

instant (INSERT org row)

One Kubernetes fleet, one Postgres, one set of tables — every row carries a tenant_id column.

LOW — engine injects tenant filter into every plan
SET LOCAL app.current_tenant_id = 'a1b2...';
SELECT * FROM customer_orders;  -- engine rewrites the plan:
                                -- Filter: tenant_id = current_setting(...)::uuid
-- even a leaked ORM query without WHERE returns ONLY your rows

compliance: SOC2 + RLS audit trail: ✅ · strict residency: ❌

✅ Hybrid tiering: keep Free/Pro tenants in this RLS-guarded Pool; lift enterprise SLA customers to Silo.

How It Works Under the Hood

SaaS multi-tenancy trades isolation for density across three models. Pool shares compute and tables with a tenant_id column: cheapest and instant to onboard, but a single forgotten WHERE clause leaks a competitor, so PostgreSQL Row-Level Security must enforce the filter in the query engine. Bridge gives each tenant its own schema on a shared instance, which turns migrations into hours of sequential DDL past a few thousand tenants. Silo dedicates VPC and database per customer, delivering maximum compliance isolation and no noisy neighbors at ten-to-fifty times the cost. Real platforms tier them: Pool for Free/Pro, Silo for regulated enterprise.

Core Architectural Principles

  • Pool isolation depends on tenant_id filters that Postgres RLS rewrites into every plan, not app code.
  • Bridge migrations must run DDL across N schemas, saturating catalog locks at five-figure tenant counts.
  • Silo eliminates noisy neighbors and meets FedRAMP/HIPAA but multiplies per-tenant cost and on-call surface.
Interview Round Script

Propose the hybrid model first: Free/Pro tenants in a Pool secured by PostgreSQL Row-Level Security, enterprise and regulated tenants in dedicated Silos. Explain RLS concretely, that the engine injects the tenant filter so a buggy ORM query still cannot return another tenant, which impresses more than vague talk. Quantify the noisy-neighbor p99 inflation and the Bridge schema-migration wall-clock to justify why each model breaks at a particular tenant scale.

Key Trade-Offs

Pool maximizes density and margin, Silo maximizes isolation and compliance, and Bridge sits between but chokes on schema migrations at scale.

Related Curriculum Chapter

Multi-Tenancy Architectures: Shared vs Isolated Models

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs