Tenant isolation
Customer data is scoped to the signed-in organization's membership. Application checks compare the session organization with the URL organization, and PostgreSQL row-level security blocks cross-tenant reads even if an organization id is forged.