Shared-tenant operations

Give every company room to operate without giving away the tenant.

Runseal runs a governed scope for each company in a shared tenant today, and is building toward a single deployment where central IT delegates approved enterprise actions to each company, while keeping control over permissions, policies, execution identities and evidence.

Where this stands Available today: a governed, isolated scope per company in the shared tenant. On the roadmap: cross-company delegation in a single deployment.

Shared tenants create operational boundaries that native roles do not always understand.

A subsidiary may be responsible for its own workspaces, applications or identities without being entitled to administer the wider tenant.

Traditional delegation often grants access to the platform itself. Runseal is designed to delegate predefined outcomes instead.

  • Several legal entities using the same Entra ID tenant
  • Separate owners and approval chains
  • Different budgets and operational responsibilities
  • Central security policies
  • Local teams requiring controlled autonomy
  • Central IT becoming a provisioning bottleneck
  • Native roles providing broader access than the business boundary requires
Central group governance delegates approved actions to each company. Requests pass through the Runseal governance boundary, which evaluates identity, entity, action, target and approval, then performs the action through a constrained execution identity. The shared Microsoft tenant is the common destination.

Central group governance

Action contracts · policy · approvals · execution identities

  • Company A

    Approved actions

    Assigned resources

  • Company B

    Approved actions

    Assigned resources

  • Company C

    Approved actions

    Assigned resources

Runseal governance boundary

  1. Identity
  2. Entity
  3. Action
  4. Target
  5. Approval
  6. Execution identity

The constrained execution identity performs the action. No local user receives a Microsoft administrative role.

Shared Microsoft tenant

Every request, evaluated in context

In the delegation model Runseal is building, a cross-company request would be evaluated by:

  1. Caller identity

    Who is requesting the action?

  2. Group company

    Which legal entity or organisational scope does the caller represent?

  3. Requested action

    Is the caller permitted to request this governed action?

  4. Target resource

    Does the resource belong to the caller's permitted scope?

  5. Risk level

    Does the action require additional review or approval?

  6. Approval policy

    Which local or central authority must approve it?

  7. Execution identity

    Which constrained workload identity is permitted to perform the action?

= A governed decision to execute or refuse.

Example scenarios

The action types the delegation model would cover. Actions marked Roadmap are not yet built; the others exist as Runseal actions today, with cross-company delegation of them on the roadmap.

Identity and application lifecycle

  • Request an application registration
  • Provision an enterprise application
  • Rotate an authorised credential Roadmap
  • Initiate ownership recertification Roadmap
  • Deprovision an application within the entity's scope Roadmap

Collaboration services

  • Request a Team or SharePoint site Roadmap
  • Assign an approved owner Roadmap
  • Apply entity-specific naming and lifecycle policies Roadmap
  • Initiate expiry review Roadmap

Temporary access

  • Request time-bound access to a sensitive service Roadmap
  • Apply the correct local and central approval chain Roadmap
  • Remove the access automatically or surface it at expiry Roadmap

Delegation can be withdrawn without redesigning tenant roles.

In this model, central IT will be able to remove an entity's permission to request an action, change its approval policy or revoke its assigned scope, without granting or removing broad Microsoft administrative roles from each user.

The delegated capability would exist through Runseal's governed action model, not through permanent access to the underlying platform.

Where this stands, and what it is not.

Cross-company delegation in a single deployment is on Runseal's roadmap. Today, Runseal delivers this as a separate governed scope per company in the shared tenant.

Governed delegation is not tenant isolation. The model is designed to enforce explicit organisational and resource boundaries where the underlying Microsoft services expose a reliable scope that can be validated, relying on administrative units, subscriptions, resource groups, ownership groups, explicit entity mappings, metadata or separate execution identities.

Where an action cannot be safely scoped, Runseal refuses it rather than simulate isolation through naming conventions alone.