How Organize keeps one studio's data separate from another
When a post house puts its bookings, client list and invoices into shared software, the first fair question is: who else is on the other side of that wall? This article explains how Organize keeps each studio's data separate, in enough detail that your IT or finance person can judge it, and without claiming more than the product does.
In this article
Every record belongs to one studio
In Organize, a studio is the account space you create when you sign up. Every user you invite belongs to that studio, and so does every record your team creates: clients, agencies, rooms, artists, projects, bookings, quotations, challans, invoices, recorded payments and uploaded output files.
There is no shared pool of records that studios draw from. A room you add exists for your studio only; a client you add is your client, not a global contact. Even reference data that looks generic, such as room types or artist roles, is created inside your studio.
Every request is scoped to the signed-in studio
When someone on your team signs in, Organize issues a signed session that includes the studio they belong to. From then on, every request the application makes to the database, whether it is loading the calendar, opening an invoice, saving a booking or generating a PDF, is filtered by that studio identifier.
This is not a filter applied in the browser, where it could be removed. It is applied on the server, before any data is read or written. The same rule covers the links between records: when a booking is saved, the room, artist and project it points to are checked against your studio first, so a record cannot be attached to another studio's data by mistake or by design.
What that means in practice
- You cannot see other studios, and they cannot see you. Lists only ever contain your studio's records.
- Guessing an ID does not help. If someone takes a record ID from one studio and tries to open it while signed in to another, the application answers "not found". Record IDs are also long random strings, not sequential numbers, so they are not guessable in the first place.
- Documents follow the same rule. Invoice, challan and quotation PDFs are generated from the same studio-scoped lookups as the screens.
- Emails go where you point them. Booking confirmations, challans and invoices are sent to the client or artist addresses your studio entered, and nowhere else.
Inside your own studio, a second layer applies: financial information is limited to the roles you choose. Separation between studios and permissions within a studio are different controls, and Organize has both.
Shared infrastructure vs. application isolation
It is worth being precise about what kind of separation this is, because vendors often blur it.
Organize runs on shared infrastructure. All studios use the same application, the same database service and the same file storage. What keeps them apart is the application's own scoping rules, described above. This is called application-level tenant isolation, and it is the standard design for software of this kind, from accounting tools to scheduling systems.
It is different from giving each customer a separate database, and different again from encrypting each customer's data with a key only they hold. Organize does not do either of those. We mention this not because the design is unusual, but because a buyer evaluating software should know which one they are getting.
A note on who can see what. Application isolation governs what users can reach through Organize. It does not make the data invisible to the people who operate the service: the Organize team has privileged access to the hosting and database accounts and is technically able to read stored data when needed to run, secure or support the service. We explain that on our Trust & data access page rather than leaving it unsaid.
What Organize does and does not claim
Organize does claim that:
- every record is associated with a single studio;
- application reads and writes are scoped to the authenticated studio on the server;
- a user in one studio cannot use the application to browse another studio's records;
- connections to Organize are encrypted (HTTPS, with HSTS), passwords are stored as hashes, and sessions live in HTTP-only cookies.
Organize does not claim:
- physically separate databases per customer;
- per-customer encryption keys or zero-knowledge storage;
- SOC 2, ISO 27001 or similar certifications of its own;
- that its staff are technically unable to see customer data.
The full list of what we do and do not claim is on the Security page, and the reasoning behind that approach is in why we removed security claims we couldn't prove.
How to check this for yourself
You do not have to take our word for it. During a trial:
- Create your studio and add a room, a client and a booking.
- Invite a second person with an operational role such as Studio Coordinator and confirm they see the schedule but not the billing pages.
- Ask us, at admin@organizeapp.org, any question your IT team would normally put in a vendor questionnaire. We will answer with what the product does, not with a brochure.
If your evaluation involves comparing vendors, our buyer's checklist lists the questions worth asking every one of them, including us.
Try it with your own studio's data
Set up rooms, artists and a first booking in minutes. Free to start, no card required.
Start Free