MSSPs and Multi-Tenant Management
If your organization manages security for multiple client organizations, Navigator supports an MSSP account with access into multiple client tenants, each kept fully separate.
How it works
An MSSP tenant has no assets of its own. Instead, its members are granted access into one or more client tenants, each with its own isolated data, connectors, and members. Your own organization’s users are unaffected by anything happening in a client tenant, and vice versa.
Creating a client tenant
From Admin → Tenants, an MSSP admin can create a new client tenant directly:
- Go to Admin → Tenants → Create tenant.
- Enter the client organization’s name.
- Save. The new tenant is created, and you’re granted access to it immediately.
Invite the client’s own employees the same way you’d invite anyone else, from Admin → Members, once you’ve switched into that tenant.
Switching between tenants
Use Switch Tenant in the top navigation, or go to the full Tenants page if you manage enough clients that the dropdown gets unwieldy. Switching changes which tenant’s data you’re viewing and acting on: connectors, assets, members, everything in Navigator reflects whichever tenant is currently active.
Switching into a client tenant (as opposed to your own home tenant) is recorded in the audit log for both tenants involved.
Managing a client tenant
From Admin → Tenants, select a tenant to view or grant your team’s access to it, or to deactivate it. Deactivating a tenant blocks login for anyone whose home tenant it is; its data is preserved, and it can be reactivated at any time.
Related pages
- Admin: member roles and the audit log, inside whichever tenant is currently active.