Skip to content

article

Client Visibility, Workspace Access, and Data Isolation

How StretchProjects keeps each organization's data private, what board visibility and the client-visible flag control, and how to share work safely.

Overview

StretchProjects is built for teams and, in agency settings, for sharing selected work with clients. This guide explains the three layers that govern who sees what: organization scoping (tenancy), board visibility, and the per-item client-visible flag.

Layer 1 — Organization scoping (tenancy)

Every board, column, item, and event on the workspace surface belongs to exactly one organization. Reads and writes are hard-filtered by organization, so:

  • You only ever see your own organization's boards and items.
  • One organization can never read or change another's data, even by guessing an ID.
  • Your organization is determined by your signed-in session — it is never taken from a URL or a form you fill in.

This is the foundation: tenancy isolation happens automatically and can't be turned off.

Layer 2 — Board visibility

Each board has a visibility setting that marks who it's intended for:

  • Workspace — client-facing boards that live on the workspace surface (this is how new project boards are created).
  • Internal — agency-owned boards, such as the master roadmap, kept on the admin surface.

Visibility separates the boards your clients might see from the internal planning boards they never should.

Layer 3 — The client-visible item flag

Within a board, an individual item carries a client-visible attribute. This lets you keep some cards on a shared board out of a client-facing view while still tracking them internally. Combined with internal notes (which are for your team only), you can run a single board that serves both internal tracking and a client-safe view.

Putting the layers together

Think of visibility as concentric circles:

  1. Tenancy decides which organization's data you can touch at all.
  2. Board visibility decides whether a whole board is workspace-facing or internal.
  3. Client-visible decides whether a specific card is surfaced to a client view.

To expose work to a client safely, you keep it on a workspace board, mark the specific cards client-visible, and keep sensitive context in internal notes rather than the description.

Example

An agency manages "Acme – Website Rebuild" as a workspace board. Most cards are marked client-visible so Acme can follow progress. A card titled "Renegotiate hosting contract," however, is left not client-visible and its context lives in internal notes — the agency tracks it on the same board without exposing it. Meanwhile the agency's own "Internal – Ops" roadmap is an internal-visibility board on the admin surface that no client can reach, and Acme's data is invisible to every other client because of tenancy scoping.

Tips

  • Never rely on obscurity — put anything a client shouldn't see behind the client-visible flag and in internal notes, not just an unlabeled card.
  • Keep client-facing boards on workspace visibility and reserve internal boards for planning your clients shouldn't see.
  • Because tenancy is automatic, you don't manage cross-organization permissions by hand — sharing across organizations isn't possible by design.
  • Review a board's cards for the client-visible flag before you first share it with a client.

FAQ

Can I move an item from one organization's board to another's?
No. Items are scoped to their organization; there's no cross-tenant move. Recreate the work in the target organization if needed.

If I share a board link with a client, can they see internal cards?
Only cards that are marked client-visible appear in a client-facing view, and internal notes never surface there. Keep sensitive work not-client-visible.

Who sets my organization?
Your signed-in session. StretchProjects derives your organization from your authenticated identity, not from anything you type, which is what makes the isolation reliable.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.