01 Isolation is enforced in the database
PostgreSQL has Row Level Security enabled: the engine decides which rows each tenant can see, not the application layer.
psychology Because a rule living in code depends on every query remembering it, and one is enough to break it. If it lives in the database, the forgetful query simply gets no foreign data.