Tenant isolation & access control
Each organization's records are separated by row-level security on the core clinical tables and enforced application-layer authorization across the platform, so records are returned only to a principal entitled to them. Access is role-based, organization-provisioned, and fails closed: if a permission cannot be confirmed, the request is denied rather than allowed.