Zscaler & Zero Trust operations glossary ยท Governance & sovereignty

What is multi-tenancy?

Definition

Multi-tenancy is a system's ability to manage several independent tenants, such as customers, subsidiaries or sites, in strict separation. Each tenant sees only its own data and configurations, even though the same platform runs underneath technically. For Zscaler operations, that means a managed service provider or a group with several Zscaler tenants can look after them all from one interface, without customer data or configurations ever mixing between tenants. Separation and consolidation are not mutually exclusive.

Multi-tenancy in detail

Technically, multi-tenancy means every request to the system is automatically scoped to the assigned tenant, regardless of which person is currently signed in. Users and roles are assigned to tenants, so a view across the tenant boundary is structurally impossible, not merely hidden by a display setting.

Multi-tenancy should be distinguished from plain role management: RBAC governs what a role is allowed to do within a tenant, while multi-tenancy governs which tenant is visible at all. For MSPs, cross-tenant access is often added on top, a controlled special right to view several tenants at once.

Why multi-tenancy matters in Zscaler operations

Anyone looking after several Zscaler tenants, whether as a group with multiple country subsidiaries or as an MSP with many customers, faces the same problem without a multi-tenant interface: logging in separately for each tenant, keeping track across many separate views, and maintaining configurations one by one. That costs time and raises the risk of missing something.

At the same time, strict separation is not negotiable: one tenant's customer data must never become visible to another, under any circumstances. Multi-tenancy resolves this apparent conflict between efficiency and separation structurally, rather than through organisational rules alone.

Common sources of error

Multi-tenancy in practice: what CentaurNexus contributes

CentaurNexus manages several Zscaler tenants from one interface, combined with RBAC domain scoping: standard roles see only their assigned tenant, and cross-tenant access stays a deliberately granted special right for MSP scenarios, not the default. For ZPA, the Microtenants feature goes a level deeper: it manages several ZPA microtenants on a multi-tenant basis from the same interface, and the separation stays structurally intact. That makes operating everything from one view possible, without softening any tenant boundaries. The following guide shows what this looks like in practice: Manage multiple Zscaler tenants from one interface.

See in the live demo how several tenants stay separated while still being managed centrally.Watch the live demo

Related terms

Frequently asked questions about multi-tenancy

What does multi-tenancy mean in practice?

A multi-tenant system manages several independent entities, such as customers, subsidiaries or sites, in strict separation. Each tenant sees only its own data and configurations, even though the same platform runs underneath technically. Mix-ups or accidental views across tenants are ruled out.

Why do MSPs need multi-tenancy?

Managed service providers typically look after many customers at once, each with their own Zscaler tenant. Without multi-tenancy, an engineer would have to log in separately for every customer and keep track across many separate interfaces. Multi-tenancy brings all of that into one view, without softening the separation of customer data.

How does multi-tenancy differ from RBAC?

RBAC governs which role has which rights within a tenant. Multi-tenancy additionally governs which tenant is visible at all. The two concepts complement each other: RBAC for the rights within one area, multi-tenancy for the separation between several areas or customers.

Is multi-tenant management automatically GDPR-compliant?

Tenant separation is an important technical building block for data protection, but it does not replace a complete GDPR assessment. Where the platform is hosted, and how data processing is contractually regulated, matter just as much for the overall assessment as the technical separation itself.

Can one tenant accidentally see another tenant's data?

A cleanly implemented multi-tenant system rules that out structurally, because every request to the data store is automatically scoped to the assigned tenant. Errors typically only arise from incorrect role configuration, not from the architecture itself.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.