Tenant and identity boundaries first
Tenant context comes from verified credentials and server-side membership, never from a client-supplied tenant identifier. Platform operators do not receive implicit access to tenant player data.
- Explicit tenant membership and RBAC
- Time-bound audited support grants
- Pseudonymous player identity
