Tenant isolation
Server-derived scope, API authorization, FORCE RLS and negative tests protect every boundary.
Tenant isolation, scoped provider credentials, deterministic guardrails, minimal telemetry and reversible enforcement are release gates, not optional features.
Each function has a narrow operating boundary and a state derived from evidence.
Server-derived scope, API authorization, FORCE RLS and negative tests protect every boundary.
Every decision records actor, reason, evidence, scope, TTL and rollback state.
Bodies, credentials and session tokens are not collected by default.
The visitor path remains short while control, evidence and rollback stay explicit.
No scan or active control starts without explicit scope.
Credentials and actions are scoped to one provider, tenant and service.
Release gates include failure and recovery, not only the happy path.
Every traffic activation requires ownership, certificate, origin and rollback checks.