Exchange this session for one in another tenant the same person holds an account in.
Tenant switch
Exchange this session for one in another tenant the same person holds an account in.
Carries nothing across but the person: the token names the other tenant’s user row, and that row’s own roles and site access are what RLS answers to. Refuses anything that is not a live account in a live tenant linked to this one, and says the same sentence for “no such organisation” as for “not yours”.
Applies the door rules of the tenant being entered rather than the one being left: an SSO-only tenant is refused with SSO_REQUIRED, and a tenant that asks for a second factor answers MFA_REQUIRED with a challenge api.verify_mfa finishes.

