Skip to main content
DuoKey Cockpit — one shared platformtenant resolved from the signed token — cannot be forgedTenant AisolatedKeysAccess policiesAudit trailOrganizational unitsFinance · Engineering · …Tenant BisolatedKeysAccess policiesAudit trailTenant CisolatedKeysAccess policiesAudit trail
Every record carries a tenant id; the tenant comes from the signed token, and isolation is enforced at the data layer — with organizational units for in-tenant scoping.
Applies to:
Cockpit v2Row-level multi-tenancyHost-managed tenants

The multi-tenancy model​

Cockpit v2 is multi-tenant by design. Every request runs in the security context of an authenticated tenant, and all data access is automatically filtered to that tenant. Because the tenant identity is derived from the signed session, it cannot be forged by a client.

Isolation by construction

Data access is scoped to the tenant at the platform's data layer, not left to individual features to enforce.

Two scoping layers

Organizational units add a second, in-tenant scope so teams and departments can be isolated within one tenant.

Edition-driven entitlements

What a tenant can do is determined by its assigned edition — there are no per-tenant feature overrides.

The tenant record​

AttributePurpose
Unique nameA unique identifier for the tenant
Display nameHow the tenant is presented
Administrator contactPrimary administrator email
EditionThe assigned edition, which drives features and limits
SubscriptionBilling arrangement (pay-as-you-go, monthly, annual, custom or free)
Trial stateWhether the tenant is in a trial and when it ends
Active stateWhether the tenant is enabled

Lifecycle​

1

Create

A host administrator creates the tenant with its slug, name, admin email and edition. The tenant starts active and in trial; creation is written to the audit and activity logs.

2

Provision the admin

An initial administrator is provisioned for the new tenant so it can be managed independently.

3

Operate

The tenant can be enabled or disabled, its users managed, and its edition reassigned within compatibility limits.

4

Delete

Deletion is soft — the record is retained for audit and can be excluded from active use.

Edition reassignment is guarded

A tenant can only move to an edition its current usage already fits — no numeric quota exceeded, no in-use module turned off, no now-unavailable resource type present. All violations are reported together. See Editions.

Organizational units​

Within a tenant, organizational units form a tree that scopes resources and role assignments to teams or departments. An app (and other resources) can be bound to an OU; a null OU means the resource is visible tenant-wide. See Administration → Organizational units.

Host-managed administration​

Tenant management is a host-level capability — creating and configuring tenants, enabling or disabling them, reassigning editions, and performing host-side user recovery (such as unlocking accounts or resetting MFA). These actions are not available inside an ordinary tenant, and recovery actions are audited separately from impersonation so that sensitive operations remain accountable.

API reference
Detailed API endpoints are documented separately in the Developer Docs → Platform Administration API.