Similar to what Brad recommends, I add a TenantID field all my BO's which populates from the RegularUser.TenantID field based on the instance owner. In my case I also have a Tenant.BO which groups multiple user by company(tenant).
I Then and set a rule in all my BO's
If
BO.TenantID<>LoggedInRegularUser.TenantID AND BO.TenantID>1
Then
READ PROTECT Objectives FROM ALL EXCEPT SYSTEM AND Administrator
This hides all the other tenants data from the logged in user.
Note: you may need to add a similar rule to some queries since Documents do not respect read protect (at least last time I checked)