Prompt
I'm building a multi-tenant app and need per-tenant vector search
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
A good way to do per-tenant vector search is to combine tenant isolation with a shared vector index or separate indexes/namespaces, depending on your scale and isolation needs.
Common approaches
1) Shared index + tenant_id filter
Store all vectors in one collection/index, with metadata like:
{
"tenant_id": "tenant_123",
"doc_id": "doc_456",
"embedding": [...]
}
Then every search query includes a mandatory filter:
WHERE tenant_id = 'tenant_123'
Pros
- Simple to operate
- Easy to scale initially
- Good for many tenants
Cons
- Must ensure every query enforces the filter
- Slight risk of accidental leakage if app logic is wrong
2) Separate namespace / collection / index per tenant
Each tenant gets its own logical partition or physical index.
Pros
- Stronger isolation
- Easier to reason about data access
- Useful for large or regulated tenants
Cons
- Operational overhead increases with tenant count
- Too many indexes can become expensive or hard to manage
3) Hybrid model
- Small tenants share an index with
tenant_id - Large or premium tenants get dedicated indexes
This is often the best practical approach.
Recommended design
For most multi-tenant apps:
- Use a shared vector store
- Always store
tenant_idin metadata - Enforce tenant scoping at the service layer
- Optionally use separate namespaces for stronger isolation
- Add authorization checks before search
- Test that cross-tenant retrieval is impossible
Example query flow
- Authenticate user
- Resolve their tenant
- Build search query with tenant constraint
- Return only results belonging to that tenant
Pseudo-code:
tenant_id = request.user.tenant_id
results = vector_db.search(
embedding=query_embedding,
filter={"tenant_id": tenant_id},
top_k=10
)
Extra security tips
- Never trust
tenant_idfrom the client directly - Derive tenant from auth/session/JWT claims
- Add tests for query isolation
- Log and monitor any query without tenant filters
- Consider encryption at rest and per-tenant access controls if compliance matters
If you want help choosing the right implementation
I can help you design this for a specific stack, like:
- Postgres + pgvector
- Pinecone
- Weaviate
- Qdrant
- Milvus
- Azure AI Search
- Elasticsearch/OpenSearch
If you tell me your stack and tenant scale, I can suggest the best pattern and schema.