Ask a vendor how their multi-tenancy works and you will often find the answer is that the interface filters by tenant. Every customer’s data sits in one store, and the separation is a clause in a query that the application is trusted to add.
That holds until something goes around the application: a crafted search, a direct API call, a bug in a new feature, a misconfigured role. The consequence of any of those is not a defect report — it is one customer seeing another customer’s security data, which for an MSP is the kind of incident a business does not always survive.
GuardsArm enforces isolation at the data layer, with per-tenant document-level security on the index itself. A query that reaches past the tenant boundary returns nothing regardless of which interface, API or account issued it, because the boundary is not in the interface.