What Happened
- The PR introduces workspace-scoped authorization for platform issue, project, and agent operations by validating `workspace_id` on `get`, `update`, and `delete` flows, which blocks cross-tenant requests that previously could pass through with broader scope.
- The PR introduces workspace-scoped authorization for platform issue, project, and agent operations by validating `workspace_id` on `get`, `update`, and `delete` flows, which blocks cross-tenant requests that previously could pass through with broader scope.
- 1 evidence item attached for review.