I have been grappling with this issue for months. How to offer a multi-tenant app with AIM and allow Tenants to create their account of the fly.
In my C/S app where I use PSQL, I can on the fly create a separate set of data for each tenant. All data is segregated and no tenant has any capability to access any other tenants data.
With AIM and SQL it seems there are only two realistic options. 1 is to manually create a BSV for each tenant and they can have their own data. This is only feasible for a small set of tenants.
The other option, is you must create a Tenant ID. Every query, process, etc must include the tenant id since all the data is in one database. User cannot use industry standard query tools. You must also look into the READ PROTECT.
To me I do not like mixing one tenants data with another due to the risk of inadvertant exposure. However, I believe AIM untilizing a Tenant Id combined with the Read Protect should be secure. Although this is not my preferred method but it looks like there is no other option and AIM is the best tool for web.
Anybody who has other ideas on a different multi-tenant approach where data is able to be segregated by tenant, please let me know as I am starting shortly on a mulit-tenant app.
Mark