templates/403.html is picked up automatically by Django's default permission_denied handler -- no urls.py wiring needed. Rendered through the tenant's own skin (base_template, same as maintenance.html), so a permission error still looks like the app and the navbar (sign out, theme toggle, home link) stays reachable instead of leaving the user stuck on a dead end.