Multi tenant architect
Skill IrfanSadiqRahat/constellation/agents/multi-tenant-architect
Row-level vs DB-per-tenant, isolation, noisy neighbor mitigation.From its SKILL.md
npx -y skills add IrfanSadiqRahat/constellation --skill multi-tenant-architectAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
1.4 KB, 305 tokens by cl100k_base, as published. Nobody here has run it
multi-tenant-architect
Operating principles
- Isolation level is a strategic choice: shared schema (RLS) < shared DB per-tenant schema < DB-per-tenant < cluster-per-tenant. Each step = +cost, +isolation.
tenant_idon every row. Enforced by RLS or middleware. Never trust the app layer alone.- Resource quotas per tenant. Rate limits, query timeouts, storage caps.
- Noisy neighbor: detect + isolate. Move heavy tenants to dedicated pool.
- Per-tenant encryption keys for sensitive verticals (health, finance).
- Tenant-aware observability. Every metric tagged with tenant id (cardinality budget).
- Onboarding + offboarding runbooks. Including data export, deletion verification.
- Tenant identity in JWT or session, verified at every boundary.
Smell-check
where tenant_id = ?in app code without RLS → cross-tenant leak risk- One tenant's slow query degrading others → no resource quota
- "We're multi-tenant" with shared cache without tenant-scoped keys → leak
- Tenant offboarding = "we deleted the rows" → audit trail missing
Hand-off contract
db-architect provides storage. rate-limit-engineer enforces per-tenant quotas. security-architect audits isolation.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most architecture codebase skills give in 305 tokens
Counted across 811 of the 1,134 authors here whose files we hold, read 2026-08-07
- Ask the user which candidate to explorein 45 of 811, across 15 files
- Apply the deletion test to suspected shallow modulesin 43 of 811, across 15 files
- Read any relevant architecture decision records firstin 31 of 811, across 8 files
- Use exact glossary terms in every suggestionin 30 of 811, across 10 files
- Accept dependencies instead of creating themin 24 of 811, across 5 files
- Include before and after visualisations for each candidatein 24 of 811, across 5 files
- Read the domain glossary before exploringin 24 of 811, across 6 files
- Return results instead of producing side effectsin 23 of 811, across 4 files
- Explore the codebase for shallow modules and frictionin 23 of 811, across 3 files
- Introduce seams only where things varyin 22 of 811, across 3 files
- Reduce the number of methodsin 21 of 811, across 2 files
- Design deep modules with small interfacesin 21 of 811, across 3 files
Said here and by no other author read
- isolate tenants strategically
- put tenant_id on every row
- enforce tenant_id using rls or middleware
- set resource quotas per tenant
- detect and isolate noisy neighbors
- use per-tenant encryption keys for sensitive verticals
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.