State of IAM Survey

Free Demo Contact
What is a Multi-Tenant Platform? Cloud & IAM

What is a Multi-Tenant Platform? Cloud & IAM

A multi-tenant environment is a software or cloud architecture in which a single software instance serves multiple customer organisations simultaneously. Each customer is a tenant: they share the underlying infrastructure, but their data and configuration are kept entirely separate. The service provider manages the platform centrally, handles maintenance and updates, and guarantees availability. Customers focus on functional use rather than technical operations.

HelloID is a multi-tenant cloud solution. From a single platform, it manages account and access rights for multiple organisations, each with their own configuration and business rules, without any cross-tenant exposure.

Multi-Tenant vs Single-Tenant

When implementing a cloud solution, organisations broadly choose between two delivery models.

Multi-Tenant

Single-Tenant

Infrastructure

Shared across all customers

Dedicated to one customer

Management

Handled entirely by the service provider

Shared between provider and customer

Cost

Lower cost per user; shared operational overhead

Higher; dedicated infrastructure and management

Customisation

Configurable within platform limits

Greater scope for bespoke development

Deployment speed

Fast; configuration only, no installation required

Slower; customer-specific setup needed

Updates

Rolled out simultaneously for all tenants

Managed separately per customer

Best suited for

Small to medium-sized organisations; standard use cases

Large enterprises with critical or unique requirements

For the majority of organisations, a multi-tenant cloud solution is the right choice. They consume functionality as Software as a Service (SaaS), typically on a per-user monthly subscription, with no infrastructure to manage and no version inconsistencies to worry about.

Larger organisations, such as multinationals, large financial institutions, or government departments with strict data sovereignty requirements, sometimes require a single-tenant deployment. This provides greater control over configuration and development direction, and can support physical data segregation where regulatory obligations under UK GDPR or government data classification frameworks demand it. The trade-off is greater complexity and higher cost. For organisations where a business application is truly mission-critical or bespoke development is required, a single-tenant model can still justify that cost.

Benefits of Multi-Tenant

Benefit

What it means in practice

Cost savings

Shared infrastructure means lower cost per user and reduced operational overhead; platform management is distributed across all tenants

Rapid implementation

No customer-specific installation; a new tenant is operational through configuration alone, often within hours

Scalability

Users can be added without investing in new infrastructure; pay-as-you-go pricing reflects actual usage

Simplified maintenance

One software version means updates and security fixes roll out simultaneously across all tenants; no version drift

Centralised security and compliance

Security controls are applied at platform level; the provider can demonstrate compliance with relevant security and privacy standards centrally

Faster innovation

A single codebase means the development team concentrates entirely on one version rather than maintaining multiple divergent releases

Multi-Tenant IAM: HelloID

For IAM functionality, multi-tenant delivery is increasingly the preferred model. Organisations remove the need to manage technical and operational IAM infrastructure and can focus entirely on configuring and administering their accounts and access rights. HelloID delivers IAM as a multi-tenant Identity as a Service (IDaaS) platform.

Despite sharing a common platform, each customer retains full flexibility to implement their own approach:

  • User provisioning is fully automated and configured to each organisation's requirements. The software is standard, but business rules define precisely which users receive which accounts and rights, and under what conditions.

  • Service processes are configurable per request type. Each organisation sets up its own management screens, activates self-service capabilities as needed, and configures approval workflows to route requests to the right reviewers before changes are actioned.

  • Integrations are handled through a catalogue of over 200 standard connectors, covering a wide range of applications without any need to modify the platform software.

This gives organisations all the operational advantages of a shared platform while retaining the flexibility to configure it for their own environment.

Access Management for Multi-Tenant Applications

Most organisations now use multiple multi-tenant applications. Microsoft 365 is the most common example. Salesforce, HR platforms, CRM tools, and most modern business applications are delivered as multi-tenant cloud services. Managing access to each of these separately, with different processes and rules, quickly becomes unmanageable.

An IAM platform such as HelloID provides a single point of control across that multi-cloud environment. The same business rules and approval processes apply regardless of which cloud application is in scope. From one platform, administrators manage accounts and access rights across all connected services, with a consistent overview of every permission setting across every tenant application.

This is not limited to cloud applications. HelloID also manages single-tenant applications and any remaining on-premises systems through the same platform, giving organisations a unified access management layer across their entire IT estate.

What is the difference between multi-tenant and SaaS?

SaaS (Software as a Service) is a delivery model in which software is accessed over the internet rather than installed locally. Multi-tenant is an architectural decision within that model: most SaaS platforms are multi-tenant, meaning multiple customers share the same software instance. The two terms are closely related but not synonymous. Some SaaS solutions are single-tenant, providing dedicated instances per customer while still being delivered and managed over the internet.

Is a multi-tenant platform secure?

Yes, when properly architected. In a well-designed multi-tenant platform, each customer's data is logically segregated. Tenants share infrastructure but have no visibility into each other's data or configuration. Security controls are applied centrally at platform level by the provider, which typically results in a more consistent and rigorously maintained security posture than individual organisations could achieve independently.

When does single-tenant make more sense?

Single-tenant is worth considering when an application is truly mission-critical and requires direct control over deployment scheduling; when data must be physically rather than logically separated for regulatory or government security classification reasons; when significant bespoke development or integration work is required; or when the organisation needs to control its own upgrade and change management timeline independently of other customers.

What is IDaaS?

Identity as a Service (IDaaS) is the delivery of IAM functionality as a multi-tenant cloud service. Rather than deploying and managing IAM software on-premises, organisations consume provisioning, access management, governance, and self-service capabilities directly from the platform. HelloID is an IDaaS platform, serving multiple organisations from a single managed environment.

Can a multi-tenant IAM platform integrate with on-premises systems?

Yes. HelloID integrates with both cloud applications and on-premises systems through its connector catalogue. Source systems such as on-premises HR platforms and Active Directory connect to HelloID in the same way as cloud-based equivalents. Target systems, whether cloud SaaS applications or on-premises business applications, are managed through the same provisioning and governance layer.