Tenancy boundary chosen deliberately
Shared schema, schema-per-tenant and database-per-tenant each carry different cost, isolation and compliance trade-offs. The decision is made explicitly against the product's actual requirements, and enforced consistently at the data access layer.