SecurityAgent-ready
Multi-tenant access security criteria tightened
The security criteria governing multi-tenant access were strengthened, and the documentation for how tenant API keys are stored was corrected to reflect actual behaviour.
Access controls for multi-tenant workspaces were reviewed and the criteria for granting cross-tenant access were tightened.
- Tenant API key storage is now documented accurately, removing a description that did not match the live system.
- The conditions under which a stored routing policy applies are now stated explicitly, so integrators know when to override it in the request instead.