Each organisation’s data is isolated at the schema level rather than by a tenant column that application code has to remember to filter on. The distinction matters: a missed WHERE clause cannot leak data across organisations if the query cannot reach the other schema at all.
Roles, record-level scopes and field-level access are platform capabilities, not per-product settings — so a permission granted in Flow behaves identically in Books, and there is one place to review it. Every write is recorded in an audit trail that spans products, because the record is shared.
If you believe you have found a security issue, please report it privately rather than opening a public issue. We will confirm receipt, keep you updated, and credit you if you would like.