Tenant isolation
APIs filter by restaurant. Users belong to one company. Superusers pass an explicit restaurant context for finance administration.
Multi-entity
Each company is a tenant. Branches execute locally. Roles, feature flags, and finance context stay inside the entity—platform operators can switch restaurants without mixing ledgers.

APIs filter by restaurant. Users belong to one company. Superusers pass an explicit restaurant context for finance administration.
Cashiers, kitchen, and riders bind to a branch. Owners see the entity. Accounting permissions can be granted beyond owner/admin.
Chart of accounts, periods, and journals are per tenant. Industry presets change operations without sharing financial data.
Yes. Restaurant/company records are tenants. APIs filter by tenant. Platform admins can switch context; operators cannot see other tenants.
Yes. Staff can be bound to a branch while owners see the entity. Finance can still post with branch and segment context.