The cause of the latter may be the shared security responsibility model. Security for SaaS is delivered by the shared responsibility model. The provider is responsible for the security the cloud - it secures the core application and the infrastructure it runs on. The customer is responsible for security the cloud - their own data, user accounts and access, and correctly configuring the security settings offered by the individual provider.
Multi-tenant authorization effectively manages user permissions across accounts, ensuring that each tenant operates within its own isolated environment and has tailored access controls.