What I have deliberately left out
No configuration, no policy definitions, no schema detail, no authentication implementation specifics. I think describing the shape of a security architecture is useful to other engineers. Describing its implementation is useful to someone else entirely.
The principle underneath
I design so that the most likely mistake is the least damaging one. A developer forgetting a tenant filter is not a hypothetical — it is a Tuesday. The architecture's job is to make that Tuesday boring.