A client audit that stops at one programme
An outsourcer running eleven client programmes (illustrative)
Each client programme is provisioned as its own tenant, with its own retention window, compliance mode, audit trail and DNC list. Then one client's auditor asks the three questions auditors always ask: what was stored, who reached it, when was it erased. The answer is scoped to that tenant, and row-level security on 231 tables is what makes that scope real.
The audit is answered per programme instead of per platform. A defect in application code cannot pull another client's rows into the response, because the application is not what enforces the boundary.