Use cases · B2B SaaS
Every tenant stays inside its walls.
In a multi-tenant product, the most expensive bug is quiet: a route that answers a stranger, or a query that forgets which customer is asking. Bracel executes access rules on every pull request.
- GET /admin/users · no credentials401
- PATCH /admin/roles/:id · no credentials403
- GET /internal/exports · no credentials200
What breaks quietly
The bugs a review reads past.
Each of these looks reasonable in a diff. Each one only shows itself when the code runs.
- 01
Unprotected routes
A new internal or admin route, added during a refactor, that answers without credentials.
- 02
Cross-tenant access
A lookup by ID that no longer checks which tenant owns the record.
- 03
Role drift
An action that was admin-only becomes available to every signed-in user.
Rules to protect
Start with one. Add the next when it ships.
Rules are approved by your team and read from your base commit, so a pull request cannot change the rules that judge it.
-
Admin and internal routes refuse requests without credentials
Available · http.auth-required@1
-
A tenant cannot act on another tenant’s records
Planned · not yet a template
-
Admin-only actions refuse other roles
Planned · not yet a template
How it runs
Inside your CI. Evidence on the pull request.
- 01
A pull request touches a protected route.
- 02
Your GitHub Actions runner builds and starts the application in isolation, without network access.
- 03
Bracel executes the approved rules against it.
- 04
The check states the verdict, what was expected and observed, and why.