Cross-company delegation in a single deployment is on Runseal's roadmap.
Today, Runseal delivers this as a separate governed scope per company in
the shared tenant.
Governed delegation is not tenant isolation. The model is designed to
enforce explicit organisational and resource boundaries where the
underlying Microsoft services expose a reliable scope that can be
validated, relying on administrative units, subscriptions, resource
groups, ownership groups, explicit entity mappings, metadata or separate
execution identities.
Where an action cannot be safely scoped, Runseal refuses it rather than
simulate isolation through naming conventions alone.