The moment you operate AppSec for more than one business unit — or more than one customer — two requirements start fighting: the operators need central control, and the tenants need hard boundaries. Most tooling picks one. Shared dashboards leak across customers; siloed per-tenant installs multiply every operating cost by the tenant count.

What isolation must cover

  • Configuration: each tenant's provider connections, mappings, and policies are theirs alone.
  • Credentials: provider secrets scoped per tenant, never pooled.
  • Data: posture, findings, and audit rows partitioned so no query can cross tenants.
  • Identity: customer users authenticate to their tenant; operators authenticate to a separate owner plane.

What central control must cover

The owner side needs the opposite lens: fleet-wide operations, provisioning, plan and entitlement management, and the ability to intervene in any tenant — through controlled, audited paths rather than shared admin passwords.

How Kangl is built for this

Kangl is multi-tenant by architecture, not by convention: tenant-partitioned data with row-level security in the database itself, per-tenant provider isolation, a separate owner console for platform operations, and audit records that capture which plane — owner or customer — performed every action. One deployment, many estates, no blurred boundaries.

KEEP READING