Tenancy is enforced below the API
The firm sits on every row and is applied in the layer that builds the query, not in the handlers. That gives scoping exactly one place it can be forgotten, and a build that forgets it fails rather than shipping.
- A read, list, search or download across firms answers as though the record does not exist
- That answer is deliberate: a refusal confirms the record is there, and a real engagement id is a fact about another firm’s client list
- A capability refusal is different and is answered as one — that caller is entitled to be in this firm
- A build fails if any firm-data function can be called without a scope, and the handful that genuinely run before one exists are listed individually with a written reason