DL-311
Multi-tenant isolation is one shared Postgres database with a tenant_id column and row-level security enforced per transaction (fail-closed SET LOCAL GUC scoping); a compliance-sensitive tenant may be promoted to a dedicated database running the identical schema (escape hatch, not a fork); the OSS core runs the same schema single-tenant with one bootstrap tenant row (RIG-2861 OQ-2 = RLS)
Status: Active (Matt, 2026-08-31)