Access Control

The whitepaper explicitly punts access control to the provider layer and/or API gateway. For a multi-tenant scenario — multiple teams or projects sharing one OASIS instance — is there any built-in mechanism to scope a given agent or user to only their own holons? Or is tenant isolation entirely the caller's responsibility?