How it holds

Three boundaries, each enforced somewhere you can't forget to check.

Conventions get forgotten. These are structural.

A schema per tenant, not a column.

Every tenant — including each reseller's own customers — is provisioned into a dedicated Postgres schema. Isolation sits at the schema boundary, so a forgotten WHERE clause cannot spill one customer into another. Routes resolve their database handle through a helper that throws rather than quietly falling back to the shared schema.

Schematenant_<slug>

One door, proven by the build.

All autonomous execution funnels through a single gate. That isn't a convention people have to remember — a guard walks the require graph at build time and fails if any path from autonomous code reaches the executor without passing through it. Authority lives in each tenant's own schema too, so no admin can widen another tenant's limits.

GateassertAutonomyAllowed()

The server makes the call. Always.

The browser never talks to a provider. It posts an intent, and the server builds the request, decrypts and injects the right credentials, follows redirects under SSRF checks, and returns what actually came back. Token endpoints are the interesting exception — inject a stale bearer into /oauth/token and the provider rejects it, so those receive nothing.

RoutePOST /api/execute

Testing

How it's tested.

Tests are mutation-checked rather than trusted: a tool flips one token at a time in the source and reports anything the suite failed to notice. It exists because a vacuous test — one that passes whatever the code does — reviews exactly like a good one.