Skip to content
Notifications
Clear all

We're an MSP - how does multi-tenancy really work?

1 Posts
1 Users
0 Reactions
1 Views
(@alexm23)
Trusted Member
Joined: 6 days ago
Posts: 48
Topic starter   [#21470]

Hey everyone! 👋 I've been diving deep into Delinea's Secret Server for the past few months, coming from a background of mostly working with standalone PAM setups for single enterprises. Now I'm at an MSP, and the game has completely changed. We're evaluating platforms specifically for their ability to handle multiple, strictly isolated clients from a single pane of glass.

I've read the whitepapers and sat through the sales demos, but you know how it goesβ€”the real-world, day-to-day operational truth is often different. The marketing says "true multi-tenancy," but I'm trying to unpack what that actually means for us as an MSP in the trenches.

Specifically, I'd love to hear from other MSPs or consultants using Delinea about:

* **Client Isolation:** How granular does it get? Can we truly customize branding, policies, and authentication methods per tenant without any cross-client visibility? We've had issues with other platforms where "logical separation" still meant shared underlying resources or admin views.
* **User Management & Roles:** We have our own internal MSP techs who need varying levels of access *across* different client vaults. Then, we have client-specific administrators who should only ever see their own ecosystem. How flexible are the role-based access controls in a multi-tenant setup? Is assigning a tech to "Client A's Admins" and "Client B's Viewers" groups a smooth process?
* **Onboarding/Offboarding Tenants:** What's the workflow like for spinning up a new client's environment? Is it a templated process, or does it require manual configuration each time? Conversely, when a client leaves, can we cleanly export their entire data set and remove them without impacting others?
* **Reporting & Auditing:** This is huge for compliance. Can we run forensic audits per tenant? If there's a security event, are our logs absolutely segregated so we can provide a client-specific trail without any risk of leaking another client's data?

We're particularly sensitive to anything that might blur the lines between tenants, even at a UI level. Our clients demand and deserve that ironclad separation.

If you've got experience, I'd really appreciate any insightsβ€”the good, the messy, and the "I wish I'd known this before we scaled" details. How does it hold up when you have 10, 20, or 50+ tenants under management?

Happy testing!


Happy testing!


   
Quote