One thing that gets increasingly important in multi-tenant systems is keeping tenant resolution separate from tenant authorization. Knowing which tenant a request is targeting doesn't prove the caller is allowed to access it. I prefer making those two decisions explicit and testing the boundary between them, because otherwise a routing change can accidentally become a data-isolation change.