Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
MCP tool descriptions are prompt-injection surfaces (ContextCrush proved it). Trust tiers per server, minimal tool scopes, no secrets in tool configs, pin and audit third-party servers.
The settled shape: API gateway → orchestrator (typed tools, retries) → model router (cheap/frontier) → verified structured outputs; Postgres + pgvector for state/memory; OTel genai spans; evals in CI; cost per feature tracked.
Name things right: commands (targeted, expect response), events (facts, past tense, many consumers), queries (read models). Outbox pattern for atomic publish; schema registry for contracts; idempotent consumers everywhere.
Three viable models: shared tables + tenant column (+ Postgres RLS for enforcement), schema-per-tenant (dozens of tenants), database-per-tenant (regulated, few). Enforcement belongs in the data layer, not app code discipline.