Most of what your security review is worried about is the seams — the eleventh integration, the fourth copy of the staff list, the export that lives in somebody’s downloads folder. There are fewer seams here because it is one platform: one identity, one permission model, one audit history, one bill.
Same login, same data, same deployment. Each role carries its own menu, so nobody wades through fourteen areas to reach the two they use. It is configuration, not a separate build — and it is a convenience, not the security. Hiding an area never grants a way around its permissions.
Everything, including who else sees what.
What procurement, security and IT usually want in writing — and where it sits in the product rather than in a promise.
Most teams bolt an agent onto a finished API and spend months writing tool definitions by hand, then discover the model can claim to be anybody. Here, marking a method callable is enough — the platform publishes it, describes it, and injects the identity itself.
list_services → 41 callable methodsget_schema("lead") → 22 fields, 4 requiredcreate("lead", { … }) → lead_9f2aorgId + user ← injected by registryThe organisation is resolved per request — including by hostname, so a customer on their own domain reaches their own data without a separate deployment. Every call carries that context, and the AI layer has it injected rather than supplied, so an agent cannot cross a tenant even if it is asked to.