For the complete documentation index, see llms.txt.
Skip to main content
Version: 8.9

Tenants

Use Admin to manage Orchestration Cluster tenants and isolate data within a single cluster. Tenant management is available on both Camunda 8 SaaS and Self-Managed.

note

On SaaS, the Tenants tab is visible to organization admins on clusters running generation 8.8 and later, even before multi-tenancy checks are enabled. This allows admins to set up tenants and assignments before enforcing checks. Before enabling checks, confirm your tenant assignments so users retain the access they need.

About tenants

A tenant is a logical boundary for data within a Camunda 8 installation.

This enables multiple teams, departments, or clients to share a single environment while keeping data isolated.

tip

To learn more about tenants, see multi-tenancy.

You can manage your Orchestration Cluster tenants directly in Admin.

  • Multi-tenancy is enabled by default.
  • Multi-tenancy checks are disabled by default. All data maps to the <default> tenant.

This allows administrators to set up tenants and assignments before enforcing multi-tenancy checks.

How you enable multi-tenancy checks depends on your deployment model:

warning

Before you enable multi-tenancy checks, assign all users, groups, and roles that need access to their tenants and to the <default> tenant. Once checks are enforced, any principal not assigned to a tenant loses access to the resources scoped to that tenant.

Create a tenant

note

The <default> tenant is automatically created when Admin starts.

  1. Log in to Admin and open the Tenants tab.

    tenant-management-tab

  2. Click Create tenant. In the modal, provide the tenant ID, name, and optional description. Then click Create tenant.

    tenant-management-create-tenant-modal

  3. The tenant appears in the list. If not, refresh the page.

    tenant-management-new-tenant-in-table

  4. Click the tenant to open details and manage assignments.

    tenant-management-tenant-details-users-tab

Update and delete a tenant

Tenants cannot be updated after creation. To change a tenant's details, you must delete the tenant and then create a new tenant with the details you require.

To delete a tenant, click on the Delete option in the list of tenants, and confirm the deletion.

note

The <default> tenant is a system entity and cannot be deleted.

Tenant assignments

You can assign the following entities to a tenant:

You can manage these assignments by selecting the relevant tab on the tenant details page.

Assign users to a tenant

  1. Select the Users tab.

  2. Click Assign user. In the modal, enter the username and confirm. The username field has to match the value of the claim configured as username-claim.

    tenant-management-assign-users-modal

  3. The user appears in the list after assignment. Refresh the page if needed.

    tenant-management-assigned-users

Assign groups to a tenant

  1. Select the Groups tab.

  2. Click Assign group. Search for a group ID and confirm.

    tenant-management-assign-groups-modal

  3. The group appears in the list after assignment. Refresh the page if needed.

    tenant-management-assigned-groups

Assign roles to a tenant

  1. Select the Roles tab.

  2. Click Assign role. Search for a role ID and confirm.

    tenant-management-assign-roles-modal

  3. The role appears in the list after assignment. Refresh the page if needed.

    tenant-management-assigned-roles

Assign mapping rules to a tenant

note

Assignment of mapping rules is only available for OIDC authentication in Self-Managed. On SaaS, identity is managed by Camunda, so mapping rules cannot map claims from a customer identity provider.

  1. Select the Mapping rules tab.

  2. Click Assign mapping rule. Search for a mapping rule ID and confirm.

    tenant-management-assign-mapping-rules-modal

  3. The mapping rule appears in the list after assignment. Refresh the page if needed.

    tenant-management-assigned-mapping-rules

Assign clients to a tenant

  1. Select the Clients tab.

  2. Click Assign client. Enter the client ID and confirm.

    tenant-management-assign-client-modal

  3. The client appears in the list after assignment. Refresh the page if needed.

    tenant-management-assigned-clients