Shape one: the org that falls back to "default"
A request that runs as a logged-in user knows its tenant. The user's session carries an organisation id, and the code reads it. Fine.
The trouble starts where there is no user. A background job. A scheduled task. A worker draining a queue. A completion hook that fires after the request has ended. None of these has a session to read, so the code that was written for the request path reaches for the tenant and finds nothing, and someone, sensibly, added a fallback so the job would not crash:
const orgId = context.orgId || 'default'
It looks harmless. It is not. Now every tenant's background work is tagged to one shared bucket called default. The lineage of who ran what, the summary the platform builds, the "learning" it crystallises from completed runs: all of it collapses into a single tenant that does not exist. One customer's completed work becomes visible in another's history, because as far as the store is concerned they are the same org. Nobody attacked anything. A default did its job.
The fix is not a bigger default. It is threading the real tenant through the paths that lost it: the job carries the originating run's organisation id, the hook receives the context that spawned it, and the genuine last-resort fallback is reserved for work that truly belongs to no tenant, and audited when it fires.