Conventions get forgotten. These are structural.
A schema per tenant, not a column.
Every tenant — including each reseller's own customers — is provisioned
into a dedicated Postgres schema. Isolation sits at the schema boundary,
so a forgotten WHERE clause cannot spill one customer into
another. Routes resolve their database handle through a helper that throws
rather than quietly falling back to the shared schema.
Schematenant_<slug>
One door, proven by the build.
All autonomous execution funnels through a single gate. That isn't a
convention people have to remember — a guard walks the require graph at
build time and fails if any path from autonomous code reaches the executor
without passing through it. Authority lives in each tenant's own schema
too, so no admin can widen another tenant's limits.
GateassertAutonomyAllowed()
The server makes the call. Always.
The browser never talks to a provider. It posts an intent, and the server
builds the request, decrypts and injects the right credentials, follows
redirects under SSRF checks, and returns what actually came back. Token
endpoints are the interesting exception — inject a stale bearer into
/oauth/token and the provider rejects it, so those receive
nothing.
RoutePOST /api/execute