secnostic platform handles tenants, identities, roles, access, and onboarding in one place, so no app has to reinvent any of it.

No app builds its own login, tenant separation, or permissions anymore. That makes running several applications easy to scale and easy to audit.

platform modules

Tenancy

Tenants

Every subject and grant is scoped per tenant, cleanly separated, with no data mixing.

Capabilities

Permissions

The granular capabilities that can be granted within a tenant, each with a name and description.

Bundles

Roles

Bundles permissions into a role that lists its permissions with effect, priority, and target.

Sign-on

Authentication

Configure OpenID Connect providers like Microsoft Entra for single sign-on.

Environments

App Environments

Apps register environments, and tenants get access to specific ones, such as production or test.

Onboarding

Tokens

Registration tokens are issued per team for onboarding.

One foundation for every app

Every app needs login, tenants, roles, and access. When each one builds that alone, the effort multiplies and mistakes creep in. secnostic platform handles this foundation once for all of them: tenants with their own login, registered apps, permissions, and plans per customer. You onboard new customers in one place, control who sees what, and maintain a full overview even as the portfolio grows.

From sign-in and app to governed access

secnostic platform is the shared control plane behind the secnostic apps. A request from inventory, focusAlert, or another app travels through the platform layer by layer: identity, tenant, access, entitlements, and finally the app itself. No app has to rebuild sign-in, tenant isolation, permissions, and plans.

Access and tenancy in detail

Two mechanisms carry the platform: a grant resolver that decides every request, and the tenant separation that keeps everything within the context of exactly one tenant.

In practice

SaaS portfolio

A software vendor onboards a new customer as an isolated tenant and enables two apps in the production environment.

  1. Invite
  2. Tenant active
  3. App access
  4. Provisioning

Own sign-in

A customer routes all sign-ins through its own Microsoft Entra ID instead of local accounts.

  1. Provider
  2. Redirect
  3. User
  4. Session

Licensing & limits

A product manager raises a customer's plan tier and reviews usage against the new limit.

  1. Definition
  2. Set value
  3. App resolves
  4. Usage

A look inside the platform

Permissions, roles, grants, and sign-in stay separate by task and share the same tenant model.

FAQ

Key questions about a shared control plane for tenants and apps.

Do customers have to give up their existing logins?

No. Each tenant configures its own OAuth and OIDC providers, with a preset for Microsoft Entra ID. Users authenticate through their own identity provider, and the platform then issues a session, acting as the relying party.

How isolated is each tenant's data?

A tenant is an isolated workspace. Users, roles, permissions, sign-in providers, and entitlement values apply only in its context. A permission for tenant A never applies in tenant B, so different customers' data and access never mix.

Can customers tamper with their own limits?

Only those the operator explicitly releases. Every entitlement is defined as global for the app or per tenant, and each can be visible, hidden, or tenant-configurable. The settings that control usage limits and billing are managed only by the operator; the platform stays the single source of truth, and apps query the current value at runtime instead of keeping their own editable copy.

What does it take to add a new app?

The app implements a documented integration protocol: a configuration file plus endpoints for info, status, OAuth, and its permission, entitlement, and metric definitions. On registration it receives a secret and OAuth credentials, after which the platform re-syncs the catalogs on a schedule.

Run an app portfolio on one shared control plane

We clarify which tenants, apps, roles, and entitlements should converge first and where the platform immediately cuts effort and one-off solutions.

Discuss platform scope