SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Platform

Multi-Tenancy & MSP White-Label

One platform, many customers, complete isolation.

Run a single GuardsArm deployment and deliver managed security to many clients, each seeing only their own data, under your own brand.

  • Document-level security
  • Client portal
  • Re-brandable UI
One platform deployment serving several isolated customer tenants, each separated at the data layer and presented through a re-brandable console

What is at stake

For a service provider, a single cross-tenant exposure is not a defect report — it is the kind of event a business does not reliably survive.

An isolation claim that survives a customer’s security review

Enforcement at the data layer rather than in the interface is a materially different answer when a prospect’s auditor asks how separation works, and it is the question that decides enterprise deals.

Sell the platform as yours

A re-brandable console means you are not introducing your supplier to your customer. For most providers this is the commercial difference between reselling and having a product.

Margin that improves as you add customers

One deployment serving many tenants, with scriptable onboarding, means operational cost does not scale linearly with the customer count — which is the entire economic case for managed delivery.

Who carries this

The service-provider principal. This is a commercial module more than a technical one, and it is usually evaluated alongside the pricing model rather than the detection content.

The problem

Most multi-tenancy is a filtered view with good intentions

Ask a vendor how their multi-tenancy works and you will often find the answer is that the interface filters by tenant. Every customer’s data sits in one store, and the separation is a clause in a query that the application is trusted to add.

That holds until something goes around the application: a crafted search, a direct API call, a bug in a new feature, a misconfigured role. The consequence of any of those is not a defect report — it is one customer seeing another customer’s security data, which for an MSP is the kind of incident a business does not always survive.

GuardsArm enforces isolation at the data layer, with per-tenant document-level security on the index itself. A query that reaches past the tenant boundary returns nothing regardless of which interface, API or account issued it, because the boundary is not in the interface.

Interface-only separation fails the first time a query is issued outside the console. That is not a hypothetical; it is how these incidents happen.

Capabilities

What multi-tenancy provides

Isolation at the data layer

Each customer is a tenant and agents map to a customer group. Tenants are separated at the data layer and by RBAC — not by hiding rows in the interface.

Operator tenant switching and a client portal

Operators switch between tenants from one console, and each customer gets a dedicated portal view of their own estate.

Re-brandable console

The interface is re-brandable for white-label delivery, so the platform carries your identity rather than ours.

Idempotent onboarding and offboarding

Customer onboarding creates the organisation, isolation, enrollment and welcome pack as one repeatable operation — and offboarding reverses it cleanly.

How it fits the platform

Data-layer isolation is what makes the multi-tenant claim defensible under scrutiny. An interface-only separation fails the first time a query is issued outside the console.

Isolation

Where the tenant boundary is actually enforced

Four layers. The third is the one that decides whether the claim survives scrutiny.

LayerInterface-only multi-tenancyGuardsArm
The interfaceFilters the view to the tenant the user belongs to.Does this too — but it is the last line, not the only one.
Role-based access controlGoverns which screens and actions a user reaches.RBAC policies apply on top of data-layer isolation rather than instead of it.
The data layerUsually nothing. The index holds every tenant and trusts the query.Per-tenant document-level security on your own infrastructure. A query that reaches past the tenant boundary returns nothing, whoever issued it.
The failure modeA bug, a crafted query or a direct API call exposes another tenant.The boundary is enforced where the data lives, so it holds outside the console as well as inside it.

How it works

Onboarding a customer, end to end

Idempotent throughout, because an MSP onboards customers often enough that it has to be scriptable.

  1. Create the organisation

    A new customer becomes a tenant. Onboarding is idempotent, which matters more than it sounds for anyone scripting it: re-running a partially failed onboarding converges rather than duplicating.

  2. Establish isolation

    Document-level security and RBAC policy are applied for the new tenant at the data layer, so separation exists before any data arrives rather than being configured after.

  3. Enrol the endpoints

    Agents map to the customer group using expiring enrolment tokens. Group membership is what determines both configuration and tenant attribution.

  4. Issue the welcome pack

    Onboarding produces the customer-facing material as part of the same process, so a new tenant is deliverable rather than merely configured.

  5. Offboard the same way

    Offboarding is equally idempotent. Removing a customer cleanly is the step most platforms treat as an afterthought and most MSP contracts treat as an obligation.

The commercial case

What changes for an MSP

Written for the person deciding whether this can be resold rather than only operated.

AspectReselling a cloud MDRDelivering GuardsArm
Deployments to runOne per customer. Operational cost scales linearly with the customer count.One deployment serving many tenants.
Cost shapePer-customer metering, typically passed through with a margin on top of a margin.Self-hosted licensing on infrastructure you own. Your margin is yours.
Whose brand the customer seesThe vendor's.Yours. The console is re-brandable.
Where customer data sitsIn the vendor's cloud, under their terms.On your infrastructure, under yours — which is frequently what makes a regulated customer addressable at all.

Terms

The four that matter in an MSP evaluation

Document-level security (DLS)

Access control enforced on individual documents in the index rather than in the application above it. This is the mechanism behind the tenant-isolation claim, and it is the one worth asking any multi-tenant vendor to describe.

Tenant switching

An operator moves between customer contexts without logging out or running parallel deployments. One console, many customers, with the active tenant always explicit.

Client portal

A customer-facing view of their own environment — incidents, assets, threat map, vulnerabilities, compliance, service and reports. A deliverable your customer logs into, not a PDF you email.

White-label

The console is re-brandable, so the product your customer sees is yours. For an MSP this is frequently the deciding feature, because the alternative is introducing your supplier to your customer.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

How are tenants actually isolated?

At the data layer, through per-tenant document-level security in your own infrastructure plus RBAC — not by hiding rows in the interface. An interface-only separation fails the first time a query is issued outside the console.

Can we put our own brand on it?

Yes. The console is re-brandable for white-label delivery, and each customer gets a dedicated client portal view of their own estate.

What does onboarding a new customer involve?

Onboarding creates the organisation, isolation, enrollment and welcome pack as one repeatable operation, and offboarding reverses it cleanly.

Does one deployment serve every client?

Yes — that is the model. Note that multi-node high-availability clustering is on the roadmap rather than generally available, so deployments are single-node today.

See Multi-Tenancy & MSP White-Label running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.