#Data relationships
V7 relations are shown for reference V7 only. The V8 schema is not designed yet (R1: don't copy V7 tables). Arrows mean "has many" unless noted.
#User → organizations → members → roles → permissions
User
users (email, password, status, 2FA, IP whitelist, credits in V7)
Membership
organization_members (organization_id, user_idinvitation email + token, designation)
Organization
organizations (owner user_id, name, logo, main)
Roles
organization_roles (owner, admin, custom) — member_role (many-to-many)
Permissions
permission catalog — permission_role (many-to-many) — plan gating per tier
- A user is a member of many organizations. An organization has many members.
- A member has many roles (V7). A role has many permissions.
- V8 recommendation: grants carry an access level (
none|view|manage) on the pivot, matching OSS. Assumption D-7
#Organization → subscription → plan → usage
Organization (V7: owner User)Subscription (status, cycle, period)Plan (tier, price, limits, features)Usage (servers, applications) compared with limits
| Relation | V7 | V8 |
|---|---|---|
| Subscription owner | User (new_subscription_plans.user_id) + main organization_id | Conflict D-3 |
| Per-server subscription rows | new_subscriptions.server_id → plan | Probably not needed (no per-server pricing in the request) Open question |
| Plan definition | Hard-coded constants | Plan catalog table Missing |
| Usage | Counted live from servers/applications | Servers from Central, applications from OSS Open question D-6 |
| Money | users.credits → wallet_histories, transactions, charges, invoices | Missing D-4 |
#Organization → servers
OrganizationServer link (name, api_url, encrypted central key, status, last_seen, oss_version)OSS panel (live: facts, apps, databases, users, services…)
#Provider → VPS → server
OrganizationProvider account (encrypted token)VPS (provider instance id, region, size)OSS installed (CENTRAL_TOKEN)Server link
#Blueprint → server → deployment
Blueprint (Central, owner: user or org — D-14)Server linkWordPress application (OSS)Add-on run (OSS run id, status, steps)Central deployment record (who, when, result)
#User → audit logs
User (actor)Audit entry (organization, action, resource, status, details, ip) < Organization
The actor's name and email are copied into the entry, so the log stays readable after the user or resource is deleted.
#Entity summary (proposed V8 Central tables)
| Entity | Belongs to | Notes |
|---|---|---|
| users | — | Phase 2/3 fields (2FA, IP whitelist, login history, sessions, preferences) |
| organizations | owner user | soft delete, main |
| organization_members | organization, user (nullable while invited) | status, invited_by, expires_at |
| roles, role_permissions | organization | access level per permission |
| plans | — | catalog (admin-managed) |
| subscriptions | organization or user (D-3) | status, cycle, period, cancel flag |
| wallets / transactions / charges / invoices | user or organization (D-4) | |
| provider_accounts | organization | encrypted secrets |
| servers | organization | link only |
| blueprints | organization or user (D-14) | |
| blueprint_runs | blueprint, server | OSS run id, result |
| audit_logs | organization | structured |
| notifications, notification_channels | user |