b176a44627
Active docs/ was stub scaffolding while the real docs sat in docs/_archive/. Restore and correct them, and record the Phase 0 work. - docs/architecture/current.md: verified system map (from archived SYSTEM_OVERVIEW, 9 corrections against code). - docs/research/competitors.md: sourced competitor analysis (from archived PRODUCT_RESEARCH, feature matrix corrected). - docs/decisions/ADR-002-job-application-model.md: the Job/JobApplication split. - docs/application-discovery-report.md, docs/implementation-roadmap.md, docs/phase-0-foundation-report.md, docs/career-workspace-branch-assessment.md. - Remove 10 zero-byte placeholder files that advertised content that never existed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
51 lines
500 B
Markdown
51 lines
500 B
Markdown
# SaaS Security
|
|
|
|
## Future Requirements
|
|
|
|
When moving to SaaS:
|
|
|
|
Support:
|
|
|
|
- Multiple users.
|
|
- Subscription plans.
|
|
- Usage limits.
|
|
|
|
---
|
|
|
|
# Tenant Isolation
|
|
|
|
Every resource belongs to:
|
|
|
|
User
|
|
|
|
or
|
|
|
|
Organisation.
|
|
|
|
---
|
|
|
|
# Billing Security
|
|
|
|
Never trust client-side:
|
|
|
|
- Subscription status.
|
|
- Permissions.
|
|
- Limits.
|
|
|
|
Verify server-side.
|
|
|
|
---
|
|
|
|
# Admin Features
|
|
|
|
Protect:
|
|
|
|
- User management.
|
|
- AI providers.
|
|
- System settings.
|
|
|
|
---
|
|
|
|
# Principle
|
|
|
|
Prepare architecture without adding unnecessary complexity early. |