Skip to content

Guide

What is tenant isolation?

Tenant isolation gives each customer organization its own copy of the software and data, so no customer can see or slow down another. Here is what that means, and where an agency's clients fit.

What does isolation mean on a multi-customer platform?

Each customer on the platform is a tenant. Isolation means each tenant's records, users and settings live apart from every other tenant's, so that a mistake, a heavy workload or a departing customer in one place does not reach the others.

What are the levels of isolation?

Multi-customer software sits somewhere on this scale, from most shared to least:

  1. Shared tables. Every customer's records sit in the same tables, told apart by a customer column. Cheapest to run. One missing filter can show one customer another's data.
  2. Separate schemas. One database, a separate set of tables per customer. Harder to leak by accident, but customers still share the database server's users, limits and safety copies.
  3. Separate databases. Each customer has its own database. Records cannot meet in a query. The application in front of them may still be shared.
  4. Separate instances. Each customer has its own copy of the application and its own database. Nothing the customer's users touch is shared with another customer.

Most multi-customer tools sit at the first level, because it is the cheapest to run. The further down the list, the more each customer costs to host, and the smaller the chance that one customer's problem becomes another's.

How can you check a vendor's claims?

Ask for the level in writing, then ask what is shared anyway: the server, the sign-in system, the network edge, the safety copies. A vendor that answers only with the word "secure" has not answered.

How does SyncedOffice isolate each customer organization?

Each customer organization (a tenant) gets its own isolated environment: its own Kubernetes namespace, database cluster, sign-in realm and ERP instance. That is the last level on the scale:

  • Every customer organization's workspace runs in its own Kubernetes namespace, with its own resource quota.
  • Every customer organization's workspace has its own PostgreSQL database cluster. No database is shared between organizations.
  • Every customer organization's workspace has its own sign-in realm, so its users and roles are kept apart from every other organization's.
  • Every customer organization's workspace runs its own ERP instance, built on Moqui and MarbleERP. No ERP is shared between organizations.

Customer organizations share the server, the identity server (each organization with its own realm on it) and the web edge. Scheduled backups with tested restores are not in place yet. (Roadmap)

Where do an agency's clients fit?

An agency is one customer organization, so its clients sit inside its workspace. They are planned as business profiles: records told apart by organization inside the agency's one ERP instance. On the scale above, that is the first level, applied within one customer's own workspace. (Roadmap) A separate environment for each of an agency's clients is also planned. (Roadmap) Read how security works.

Questions and answers

Is a separate database per customer always better?

Not always. It costs more to run, and it matters most when the customers must never see each other. Inside one business, a lighter separation between departments or brands is often enough.

What should I ask a vendor about isolation?

Ask what each customer gets of its own (database, users, application), what is shared, where the data is hosted, how it is copied for safekeeping and whether a copy has ever been used to recover it, and how a customer's data is removed when it leaves.

What does SyncedOffice share between customer organizations?

Customer organizations share the server, the identity server (each organization with its own realm on it) and the web edge.

Want your organization in an isolated workspace?

Join the pilot