Cross-tenant exposure and privilege defects โ one tenant's data reachable from another.
Applied top to bottom; each rung breaks only the ties left above it.
๐ What this deliberately ignores: issue age and filing order; how cheap or well-understood a fix looks; how much of an issue is already merged.
None recorded โ track:security carries an empty decided list in track-order.json. The load-bearing open ruling is the default-grant convention decision (#2938); record it in track-order.json when made, so the next session reads it instead of re-asking.
#2968 was found while draining the _v1_substrate_xfail allowlist (batch 4), not caused by that work. The index was recreated verbatim from its pre-tenant form in 20260320163011_rename_groups_to_sources.sql; tenant_id landed three days later (20260323000000_tenant_id_everywhere.sql) and the recreated index was never rescoped.
#2037 surfaced during the Regina disclose() + email-spoofing audit (docs/investigations/2026-06-21-regina-email-spoofing-report.md), on the ADR-097 impersonation track.
#2445 surfaced during the ADR-096 read-projection work (#2437). Phases 0โ2 merged 2026-07-16; Phase 2d and the follow-up remain.
#2938 surfaced by the adversarial review on #2936 (ADR-135 stage 4a). tenant_health_snapshot sat world-grantable for three weeks before #2936 revoked it for that one table.
Impersonation (#2037): person node 61b97263-dd6f-484e-aa32-20d361e33b5c ("Kareem") is flagged is_impersonation=true on prod (tenant e9d96b09โฆ). The verdict that flagged it cites a message actually sent from oldenglishsuperstores.com โ a correct phish identification keyed on the forged From and stamped onto the real owner. No evidence or reason is stored on the node (impersonation_evidence/impersonation_reason are null), so the suppression is silent.
Default grants (#2938): measured 2026-08-01 on tenant_health_snapshot โ relacl showed anon=arwdDxtm and authenticated=arwdDxtm (every privilege) with RLS enabled and zero policies.