Networking can be VERY complicated within VCD. If you are running VCD internally and you're not worried about network security you can run all Organizations on the same VLANs. You can also setup different External Networks for each Organization and put them on their own VLAN. This can all be done by standard VLAN's or VXLAN, that is up to you and your network setup. There are physical switch requirements for VXLAN to work though so read up on that.
If you want your tenants to control what traffic comes into their Organization VM's you can deploy a vShield Edge device to their Organization. This allows that tenant to control Firewall and Nat rules to their entire Network.
-Eric