SouRCe

Security

Supabase Auth identifies the human. SOURCE authorizes from organisation membership rows. Client-editable user metadata is never used for tenant, role, or admin decisions.