P0: Row-Level Security policies for tenant isolation
Imported from GitHub issue El-SaMa/oma#9 by @El-SaMa.
Add RLS on all tenant-owned tables scoped by org membership; deny by default.
Done when: a user can only read their own org rows; tests prove cross-tenant denial.