DL-381
A bearer token carries its issuing tenant: tokens.tenant_id is stamped at issue from the issuer’s tenant context, and the auth interceptor takes the request tenant from that row in the same lookup that resolves the account, then scopes the request with store.WithTenant. A token without a tenant fails closed. Rejected: a request-path system role to read the token (contradicts DL-315’s no-BYPASSRLS-on-the-request-path) and a SECURITY DEFINER lookup function (a second privileged path to audit). Existing tokens are backfilled to the bootstrap tenant by the adding migration (RIG-4067 option 1)
Status: Active (Matt, 2026-09-28)