Sortwood

The isolation tenant. Same origin as the page next door, different tenant, and deliberately no help centre behind it.

The page next door is served from this same origin and answers questions. This one will not, and that is the point: it bootstraps a different tenant, and that tenant has no help centre indexed behind it. Ask the launcher anything and it will hand you to a person rather than guess.

Nothing about the two pages differs except one attribute. The origin is identical, the script is byte-for-byte the same file, and the allowlist admits both. What decides which tenant answers — and therefore which corpus is even searched — is data-tenant-id, resolved server-side. One tenant cannot reach the other's documents, tickets or contacts, because Postgres will not return them.

The allowlist is a separate question from the tenant. Each of these two tenants admits an origin the other refuses, so a refusal is attributable to the tenant rather than to an origin nobody has heard of. Copy the snippet onto an unlisted origin and POST /widget/sessions refuses it outright.