access token -> claims verify -> org/user binding -> feature + incident policy
| | | |
v v v v
auth context role + scope tenant isolation safety guardrails
| |
v v
rate + quota control -> RAG answer -> usage meter -> billing line -> audit/event log
Why this matters: every query is treated as a governed platform transaction, not just an LLM call.