General
What is the Multi-tenant model?
What is the Multi-tenant model?
It's a model that lets a single client manage several organizations from one central account, called a tenant. From this tenant, a Tenant admin can create, structure, and govern all the organizations that belong to it, instead of managing each in isolation.
Who is the Multi-tenant model for?
Who is the Multi-tenant model for?
It's designed for two types of clients: large organizations (typically groups split into subsidiaries or across several countries) and MSSP clients (partners who resell the Patrowl solution and manage security for their own end customers).
Can I enable the Multi-tenant model myself from the platform?
Can I enable the Multi-tenant model myself from the platform?
No, and by design. Your tenant is configured once by your Patrowl contact, who also migrates your existing organizations under it. After that setup, you manage everything yourself. If the model fits your needs, reach out to your Patrowl contact to get started.
Managing organizations
What can I do with a tenant?
What can I do with a tenant?
You can create, edit, and delete the organizations that belong to your tenant, apply dedicated settings to each of them, and distribute your resources across them, all from a single place.
Can each organization have its own settings?
Can each organization have its own settings?
Yes. Every organization can have its own settings — for example a specific cybersecurity or usage policy — rather than sharing a single configuration across the whole tenant.
Are organizations I create automatically attached to my tenant?
Are organizations I create automatically attached to my tenant?
Yes. Organizations created by a Tenant admin are automatically attached to the tenant it was created in.
What happens to the data when I delete an organization? Can I undo it?
What happens to the data when I delete an organization? Can I undo it?
Deleting an organization is irreversible and removes all the data attached to that organization (assets, scans, history, and so on). This is a high-impact action, so make sure you're fully aware of the consequences before proceeding.
Is there a limit to the number of organizations per tenant?
Is there a limit to the number of organizations per tenant?
No. There is currently no limit on the number of organizations a tenant can hold, so the model scales with your portfolio.
Resources
Which resources can I split between organizations?
Which resources can I split between organizations?
You can allocate the following resources across the organizations of your tenant: EASM credits, Pentest slots, Greybox credits, and Retest credits.
What happens if an organization runs out of credits while the tenant still has some?
What happens if an organization runs out of credits while the tenant still has some?
You top it up yourself. A Tenant Administrator can allocate more resources to that organization straight away, as long as capacity is still available at the tenant level, with no need to contact support.
Can unused credits be reclaimed or redistributed to another organization?
Can unused credits be reclaimed or redistributed to another organization?
Yes. Credits or slots that were allocated to an organization but haven't been used yet can be pulled back and reassigned to another organization
Roles and permissions
How do roles work in the multi-tenancy model?
How do roles work in the multi-tenancy model?
Roles work on two independent levels: organization roles (what a user can do inside an organization — Auditor, Standard, or Organization admin) and the Tenant role (whether a user can reach the Tenant space). The two are managed separately and don't affect each other.
Can a user have a different role in each organization?
Can a user have a different role in each organization?
Not yet. A user currently keeps the same role across every organization they can access. Per-organization roles are planned for a future release.
How does a user get access to the Tenant space?
How does a user get access to the Tenant space?
A user needs the Tenant Admin role. This permission is granted separately from any organization role and is what unlocks access to the Tenant space.
Does being an Organization admin give access to the Tenant space?
Does being an Organization admin give access to the Tenant space?
No. Organization roles and the Tenant role are independent. Holding an organization role, even Organization admin, never grants access to the Tenant space on its own.
Who can grant or remove the Tenant Admin role, and where?
Who can grant or remove the Tenant Admin role, and where?
The Tenant Admin role is managed from the Users page in the Tenant space. To enable or disable the role, edit the profile of the user you want to update.
Can there be several Tenant Admins on the same tenant?
Can there be several Tenant Admins on the same tenant?
Yes. A single tenant can have as many Tenant admins as you need.
Can someone be a Tenant Admin without belonging to any organization?
Can someone be a Tenant Admin without belonging to any organization?
Yes. A user can be added as a Tenant Admin without being assigned to any organization. In that case, they’ll reach only the Tenant space (by logging in to the Dashboard) and won’t see the confidential content of any organization, such as assets, scans, or results.
What does a Tenant Admin without any organization actually see?
What does a Tenant Admin without any organization actually see?
They can see the names of the organizations in the tenant, so they can manage them, but nothing confidential inside those organizations, such as a specific vulnerability found in a given one. It's the right level of access for administering structure without exposure to security data.
Teams
Does multi-tenancy replace Teams?
Does multi-tenancy replace Teams?
No. Teams remain fully available inside each organization and continue to work as before. The tenant groups and governs several organizations, while Teams structure work into business units, departments, or any other subdivision. The two levels are complementary.
