Use cases · B2B SaaS

Every tenant stays inside its walls.

In a multi-tenant product, the most expensive bug is quiet: a route that answers a stranger, or a query that forgets which customer is asking. Bracel executes access rules on every pull request.

PR #1207 · Move admin routes to a new routerFAIL
  1. GET /admin/users · no credentials401
  2. PATCH /admin/roles/:id · no credentials403
  3. GET /internal/exports · no credentials200
http.auth-required@1 · unauthenticated-request-succeeded · illustrative

What breaks quietly

The bugs a review reads past.

Each of these looks reasonable in a diff. Each one only shows itself when the code runs.

  1. 01

    Unprotected routes

    A new internal or admin route, added during a refactor, that answers without credentials.

  2. 02

    Cross-tenant access

    A lookup by ID that no longer checks which tenant owns the record.

  3. 03

    Role drift

    An action that was admin-only becomes available to every signed-in user.

Coming soon

Rules to protect

Start with one. Add the next when it ships.

Rules are approved by your team and read from your base commit, so a pull request cannot change the rules that judge it.

  • Admin and internal routes refuse requests without credentials

    Available · http.auth-required@1

  • A tenant cannot act on another tenant’s records

    Planned · not yet a template

  • Admin-only actions refuse other roles

    Planned · not yet a template

How it runs

Inside your CI. Evidence on the pull request.

  1. 01

    A pull request touches a protected route.

  2. 02

    Your GitHub Actions runner builds and starts the application in isolation, without network access.

  3. 03

    Bracel executes the approved rules against it.

  4. 04

    The check states the verdict, what was expected and observed, and why.

How it works · Security and data · Check compatibility