Skip to content
Skip to main content
Novel Systems home
Decision log
D-096August 6, 2026

The demo tenants were the source of the invented customer names, so the disclosure moved into the name

Affects: lib/tenant-workspaces.ts, components/auth/workspace-tour-modal.tsx, components/CPQSandbox.tsx

Decision

Rename the three demo tenants to Sample Workspace — <trade> Contractor, delete the customerSince field from TenantWorkspace entirely, replace the two city headquarters with regions, and change the CPQ account-name placeholder so it stops naming a company.

What forced it

D-094 removed five named companies from lib/customer-proof.ts. Immediately afterwards the served HTML of / and /integrations was probed for each of those names, and one was still there:

/integrations → "6 of 15 connected in Apex Commercial" / → placeholder="e.g. Apex Commercial Electrical"

Three of the five removed case-study companies had taken their names from this module. That is also the mechanism behind the reviewer's first bullet: a set of customer names that changes as a block changes because somebody edited the block, and the block was here.

Why not leave them, given they were disclosed

/integrations did carry a disclosure — "the connected states and sync times above describe a sample workspace, not a live tenant" — and it is accurate. It was also four lines below the sentence containing the name, which is the placement failure already recorded in D-069 and D-071 and reargued in D-095.

It is worse here than in either of those, because the name travels and the caption does not. shortName renders in the workspace switcher, the mobile header, the portal breadcrumb and the connector count. A caption written on one page cannot qualify a string rendered on four. So the disclosure went into the value: any surface that renders the tenant at all now renders the word "sample", whether or not the author of that surface remembered.

customerSince was deleted rather than reworded. It rendered as "customer since March 2024" underneath a company name and a headquarters city — an assertion that a commercial relationship began on a date, about a company that does not exist. There is no caption that fixes that sentence, and no version of the product tour that needs it. Deleting the field means it cannot be quietly repopulated later; blanking the strings would have left the shape waiting.

What was deliberately not changed

Tenant ids and subdomains — apex, vanguard, metro. They are routing keys. apex.novelsystems.ca asserts nothing about a company to anyone who has not read this file, and rewriting them would break host-based tenant resolution and the seed data for no gain in honesty.

The fixtures themselves — work orders, quotes, metrics, utilisation figures — also stay. A product demo needs a tenant to be a demo of. What had to go was the plausibility of the tenant as a real firm, not the realism of the data shape.

When this is wrong

If a real customer ever agrees to have their workspace shown, this module is not where that goes; it goes through docs/legal/CASE-STUDY-INTAKE.md with a committed consent record, like anything else with a real name on it.