multi-tenancy.txt
My app serves multiple <organisations / teams>. Here's my schema and
some queries: <paste>

Review the isolation:
- Does every query filter by tenant, without exception? List any that
  don't — that's a data leak.
- Where is the tenant ID coming from? If it's from the request body or
  a URL parameter the user controls, that's the vulnerability.
- What happens if a user is a member of two tenants?
- Are IDs sequential and guessable across tenants?

Then recommend how to make this structurally safe rather than
relying on remembering — a scoped query layer, a database policy, or
whatever fits my stack.

"Remember to add the tenant filter" is not a strategy. It works until the one query somebody writes in a hurry, and that's the incident.