Isolation you can demonstrate
A key from one organisation gets a 404 on another organisation's execution — not a 403, so the response does not confirm the record exists.
One organisation per client, one policy per organisation, one budget per key — with isolation enforced at the query rather than remembered by a developer.
Agencies run many clients through shared infrastructure and shared keys. When cost, data and policy all blend together, a client question about their spend or their data cannot be answered precisely.
A key from one organisation gets a 404 on another organisation's execution — not a 403, so the response does not confirm the record exists.
Each client organisation carries its own residency, provider and cost rules. Composition is one-directional, so a project policy can tighten a client's rules but never loosen them.
Every execution records its measured cost and the pricing snapshot in force, so an invoice line can be traced to the requests behind it.
There is no agency-level dashboard spanning client organisations, and no bulk provisioning. During beta each organisation is set up individually.