Every surface under /app/[orgSlug] is strictly scoped.
getAppContext(orgSlug) in the layout resolves the org, member, and role or returns 404.getOrgDb(ctx) + an explicit eq(....orgId, ctx.org.id) filter.orgAction (zod schema → resolve context →assertCan → handler).Accessing another org’s data always returns 404 (never 403). This is intentional — it makes enumeration attacks useless and keeps error handling simple.
User-facing unique fields use composite UNIQUE(org_id, ...) constraints at the database level. The application catches the typed error instead of doing check-then-insert.