For the complete documentation index, see llms.txt.
Skip to main content
Version: 8.8

Multi-tenancy

Isolate data, configurations, and operations for multiple teams, departments, or organizations within a single Camunda 8 installation.

About​

Camunda 8 supports multiple multi-tenancy models, each with different isolation levels and operational characteristics.

All models run on the same platform and tooling. They differ in how much they isolate, from a shared database separated by a tenant ID, to a fully separate cluster per tenant.

Choose your model​

Choose the model that best fits your isolation requirements and operational constraints:

AspectLogical TenantMulti-Cluster
AvailabilitySelf-Managed and SaaSSelf-Managed and SaaS
IsolationLogical onlyFull physical isolation
Data sharingSingle shared databaseSeparate per cluster
Backup/restoreCluster-level onlyIndependent per cluster
CostMost efficientMost expensive
Operational complexityLowHigh
Use caseSmall teams, low-risk separationSeparate organizations, maximum isolation

Logical Tenants​

Lightweight tenant-ID based multi-tenancy for cost-efficient subdivision within a single cluster.

Logical Tenants share infrastructure but have logically isolated data, configurations, and access controls. This model is best for departments or teams within the same organization with low-risk separation needs.

Multi-Cluster​

Full isolation through dedicated infrastructure with separate clusters per tenant. Maximum isolation and operational independence, but highest infrastructure cost and complexity.

This model is best for separate organizations with maximum isolation requirements or strict data residency needs.

On SaaS, this means provisioning a separate cluster per tenant rather than configuring a distinct mode. See Clusters.

For example, a retail bank and an investment bank under the same parent company might each run their own dedicated cluster, with no shared processes, storage, or networking between them.

Next steps​