Tenant scope should not be a prompt instruction

Dev.to AI
Generative AI

The most dangerous AI database bug is rarely a syntax error. It is the query that works, returns a polished answer, and quietly includes the wrong tenant. For MCP database servers, tenant scope should not live in the prompt: “Only answer for the current customer.” That is a preference, not a boundary.