chardb(). Organization mode accepts tables from forOrg(auth) and forOrgUser(auth). User mode accepts only forUser(auth). CharDB rejects a schema that mixes the two modes.
Own rows with an organization
This is the exact schema generated by the packaged initializer.src/schema.ts
forOrg(auth) adds organizationId as a non-null Drizzle reference to auth.organization.id. CharDB uses that schema reference to derive ownership; shard migrations do not install a physical foreign key to the Catalog-owned auth table. The column selects the partition, and the policy decides which current members may read or write each column.
Query definitions keep organizationId because the router needs one exact partition. The configured @chardb/react client reads the active organization from Better Auth and adds it to query and mutation arguments. CharDB still verifies the JWT and current membership before using it.
CharDB fills organizationId and authorId from verified authority during inserts. Mutation handlers omit both values. Defining organizationId yourself is a type error and a runtime error.
Own rows with a user
Chooseownership: "user" for a Worker whose rows follow the signed-in user rather than an active organization.
src/preference-schema.ts
forUser(auth) adds userId, partitions by it, and fills it from the verified JWT subject. The configured React client adds that owner to client operations, and the server rejects any value that does not match the verified subject. The implicit self policy grants the owning user access.
Own a row with an organization and user
In an organization-owned Worker, useforOrgUser(auth) for rows owned by one member inside the organization.
src/draft-schema.ts