Tenants
Row-level multi-tenancy, tenant lifecycle, OU sub-scoping and edition assignment.
The multi-tenancy model
Cockpit v2 is multi-tenant by design. Every request runs in the security context of an authenticated tenant, and all data access is automatically filtered to that tenant. Because the tenant identity is derived from the signed session, it cannot be forged by a client.
Isolation by construction
Data access is scoped to the tenant at the platform's data layer, not left to individual features to enforce.
Two scoping layers
Organizational units add a second, in-tenant scope so teams and departments can be isolated within one tenant.
Edition-driven entitlements
What a tenant can do is determined by its assigned edition — there are no per-tenant feature overrides.
The tenant record
| Attribute | Purpose |
|---|---|
| Unique name | A unique identifier for the tenant |
| Display name | How the tenant is presented |
| Administrator contact | Primary administrator email |
| Edition | The assigned edition, which drives features and limits |
| Subscription | Billing arrangement (pay-as-you-go, monthly, annual, custom or free) |
| Trial state | Whether the tenant is in a trial and when it ends |
| Active state | Whether the tenant is enabled |
Lifecycle
Create
A host administrator creates the tenant with its slug, name, admin email and edition. The tenant starts active and in trial; creation is written to the audit and activity logs.
Provision the admin
An initial administrator is provisioned for the new tenant so it can be managed independently.
Operate
The tenant can be enabled or disabled, its users managed, and its edition reassigned within compatibility limits.
Delete
Deletion is soft — the record is retained for audit and can be excluded from active use.
A tenant can only move to an edition its current usage already fits — no numeric quota exceeded, no in-use module turned off, no now-unavailable resource type present. All violations are reported together. See Editions.
Organizational units
Within a tenant, organizational units form a tree that scopes resources and role assignments to teams or departments. An app (and other resources) can be bound to an OU; a null OU means the resource is visible tenant-wide. See Administration → Organizational units.
Host-managed administration
Tenant management is a host-level capability — creating and configuring tenants, enabling or disabling them, reassigning editions, and performing host-side user recovery (such as unlocking accounts or resetting MFA). These actions are not available inside an ordinary tenant, and recovery actions are audited separately from impersonation so that sensitive operations remain accountable.