Organization hierarchy and assignment
An Organization sits at the centre of two independent mappings, not at the end
of a chain. One mapping says which roles belong to the organization; the
other says which schemas it may use. Both point at
cypex.t_organization, and neither knows about the other:
pg_roles cypex.t_module
(login identity, grants) (schema registry)
│ │
│ cypex.t_role_organization │ cypex.t_module_organization
│ (role_name ↔ organization) │ (module_id ↔ organization)
│ │
└──────────► cypex.t_organization ◄──────────┘
(the tenant boundary)
A user sees a row only when both mappings agree: their role is mapped to the organization, and the schema holding the object is granted to that same organization. Satisfying one without the other produces an empty result, not a partial one.