# Best Practices

- Keep one Docker Compose stack per customer instance.
- Keep one volume per instance so customer data is isolated.
- Store only Dokploy IDs and status in the SaaS database.
- Use Stripe webhooks as the source of truth for subscription status.
- Keep provisioning idempotent where possible. If Dokploy returns an error after creating a stack, reconcile from the Dokploy dashboard before retrying.
- Use a dedicated Dokploy project for all customer Hermes instances.
- Give the app a Dokploy token with the smallest permission set that can create and manage compose apps.
