Tenant
In identity and access management, a tenant is a distinct, logically isolated space within a shared system that belongs to a single organization or customer. It keeps one organization's users, data, and settings separate from those of other organizations that use the same underlying platform. This concept is different from the everyday legal meaning of a tenant as someone who rents property from a landlord.
The evidence packet provided defines 'tenant' only in its real-property legal sense (a person or entity who temporarily occupies or possesses real estate belonging to a landlord under a lease), and contains no source material describing the IAM meaning of the term. In IAM practice, a tenant typically denotes a logically isolated administrative and data boundary within a multi-tenant identity platform, scoping a customer's or organization's directory, users, policies, and configuration; however, the specific technical characteristics of tenant isolation cannot be substantiated from the sources provided here and are noted as out of scope for this evidence set.
Why it matters
In multi-tenant identity platforms, the tenant boundary is the primary line separating one organization's users, data, and configuration from another's. When many customers share the same underlying identity infrastructure, the integrity of that logical isolation directly determines whether a misconfiguration or defect in one organization's space can expose or affect another's directory, policies, or credentials. For security architects and IGA leads, understanding what a tenant scopes is foundational to reasoning about blast radius and containment.
Because the tenant is often the top-level container for an organization's directory, users, policies, and settings, administrative and governance decisions are typically made within its boundary. Access reviews, provisioning, and policy administration are generally scoped to a tenant, so treating the tenant as the authoritative boundary matters for both runtime enforcement and lifecycle governance. Conflating tenants, or failing to enforce their separation, can undermine assumptions that downstream controls depend on.
It is worth flagging that the evidence set provided here defines 'tenant' only in its real-property legal sense and contains no source material substantiating the specific technical characteristics of tenant isolation in IAM platforms. Readers should therefore treat the IAM description here as a general characterization and consult vendor and standard documentation for the isolation guarantees of any particular platform.
Who it's relevant to
Inside Tenant
Common questions
Answers to the questions practitioners most commonly ask about Tenant.