Overview#
Running a multi-tenant deployment means being responsible for the operational integrity of every organisation sharing your platform, without any one of them being aware of the others. The Tenant Management module handles that at scale: automated provisioning, quota enforcement with hard isolation boundaries, health scoring that surfaces at-risk tenants before they churn or escalate, and structured decommissioning that satisfies data retention regulations.
Each tenant operates in a fully isolated environment. Data isolation is enforced at the database schema level, with organisation ID scoping on every query. One tenant cannot see or affect another's data.
Key Features#
-
Automated Tenant Provisioning: Provision new tenant environments through automated workflows that handle configuration, resource allocation, administrator account creation, and initial data seeding. Template-based provisioning ensures consistency while supporting per-tenant customisation by industry and compliance requirements. Self-service provisioning portals with branded registration pages enable scalable onboarding.
-
Hierarchical Tenant Organisation: Support parent-child tenant relationships for enterprise accounts with departmental isolation. Settings inheritance flows from parent to children with override capabilities at each level, and consolidated billing simplifies financial management across tenant hierarchies.
-
Resource Quota Management: Enforce per-tenant quotas across compute, storage, network, and feature dimensions with real-time monitoring and automatic enforcement. Progressive alerts at configurable thresholds provide early warning, while soft limits warn and hard limits block operations to prevent resource exhaustion.
-
Tenant Isolation and Security: Complete data isolation through dedicated database schemas, application-level tenant context enforcement on every query, and network-level segregation. Tenant-specific encryption keys, authentication scoping, and audit trails ensure zero cross-tenant data access. Automated isolation verification tests run continuously.
-
Tenant Configuration Management: Centralised management of feature flags, integration credentials, branding assets, security policies, notification preferences, and backup retention. Global defaults cascade to all tenants with tenant-level overrides for customisation.
-
Graceful Decommissioning: Structured shutdown workflows with configurable notice periods, automated data export, user notification campaigns, progressive service degradation, and resource reclamation. Configurable retention and purge policies satisfy regulatory requirements, with certificates of data destruction available for audit purposes.
-
Tenant Health Scoring: Multi-dimensional health scoring based on usage consistency, growth trajectory, payment status, support engagement, feature adoption, and security compliance. Predictive analytics identify churn risk, upsell opportunities, and tenants requiring intervention.
-
Comprehensive Analytics: Real-time dashboards showing resource utilisation, feature adoption, performance metrics, and operational health per tenant. Executive dashboards aggregate platform-wide KPIs while tenant-specific views support operational management. Scheduled reports cover daily operations through quarterly business reviews.
Use Cases#
- Managed service providers operating white-label solutions for law enforcement agencies, government departments, and intelligence organisations with hierarchical tenant structures, self-service onboarding, and consolidated billing.
- SaaS platform operators managing hundreds of customer tenants with automated provisioning, quota enforcement, and health monitoring from a single administrative interface.
- Government departments operating isolated environments for different agencies or business units with shared platform infrastructure and centralised governance.
- Financial institutions maintaining regulatory isolation requirements between different business divisions with full audit trails and data residency controls.
- Healthcare providers ensuring patient data is strictly isolated per organisation, with encryption key management and audit trails supporting HIPAA and national data protection requirements.
Open Standards#
- OAuth 2.0 and JWT Bearer Token: Token-based authentication protects typed, auditable read and write workflows across the platform.
- SCIM 2.0 (RFC 7643 / RFC 7644): automated identity provisioning for new and existing tenants is handled through a dedicated SCIM 2.0 client that syncs user and group resources with external identity providers.
- OAuth 2.0 (RFC 6749 / RFC 6750): all write operations on tenant configuration are gated by scoped bearer tokens; the
auth:tenant:writescope is enforced on every internal service-to-service request that modifies tenant security settings. - JSON Web Token (RFC 7519): tenant-bound RS256 service JWTs are minted and validated for inter-service calls, with the
tenant scopeclaim pinned to prevent cross-tenant token reuse. - LDAP / LDAPS (RFC 4510, 4512): per-tenant directory integration supports both plaintext LDAP and TLS-wrapped LDAPS endpoints, with configurable base DNs for scoped authentication and group resolution.
- X.509 Public Key Infrastructure (RFC 5280): per-tenant PKI configuration accepts PEM-encoded CA certificates for client certificate authentication, enabling hardware token and smart card login flows.
- GDPR / EU NIS2 Directive / eIDAS Regulation: tenant security configuration carries an explicit compliance-framework tag (GDPR, NIS2, eIDAS, STANAG, EU AI Act) that drives data-residency zone enforcement and audit retention policies.
- RFC 4122 (UUID): every tenant is identified by a version 4 UUID, ensuring globally unique, unpredictable identifiers across all provisioning, audit, and cross-service references.
Getting Started#
- Define Tenant Templates: Create configuration templates for your standard tenant types with appropriate defaults, quotas, and feature sets.
- Provision Initial Tenants: Use automated workflows or the self-service portal to create your first tenant environments.
- Configure Quotas: Set resource limits and alert thresholds based on your infrastructure capacity and tenant tier agreements.
- Enable Monitoring: Activate health scoring, usage analytics, and alert notifications for operational visibility.
- Establish Governance: Define decommissioning policies, data retention rules, and access review schedules.
Last Reviewed: 2026-02-05 Last Updated: 2026-04-14