Verify by execution that, in a system where several customers share one database, no tenant can read or change another tenant's data. Use for multi-tenant or SaaS applications with row-level security, tenant_id columns, memberships, or per-organization roles, before accepting a delivery, before showing it to a real customer, and whenever policies, roles, or permissions change. Requires querying as each role instead of reading policies, and distinguishing "nothing happened" from "it is protected". Do not use for general application security or for judging a delivery against its full contract.