Expanded capabilities
- Define the hard wall every module and agent must operate inside
- Require identity + membership reconciliation on protected routes
- Block cross-tenant aggregation on ordinary command surfaces
- Keep impersonation visible when platform admins act
- Anchor ORACLE seekers and knowledge artifacts to one tenant




