In my experience this very much depends on your target market and their requirements for regulatory compliance - at the sharpest end, even their metadata may leak information (table names, etc.) so that must stay within their boundary. But is your product a fit for that market? You will incur penalities in onboarding complexity to setup account boundaries, and time penalties during deployment as infrastructure builds in their account.
At the other end of the scale, if everything can run in your tenant then it can theoretically be available within seconds of signup, but cannot meet regulatory compliance for many industries - maybe you don’t target them though.
Serverless SaaS data processors like TinyBird, Decodable, RockSet and others go for the latter approach, some companies have offerings in multiple deployment form-factors, some just have what is effectively mPaaS or Cluster-as-a-Service BUT meet lots of regulatory compliance. Is that truly SaaS is a wonderful argument to have on the internet 😂