TenSaaS multi-tenant AI control plane

Put every team, AI application, and credit under one accountable boundary.

Create teams, install governed AI applications, assign access, and reconcile actual model usage in one control plane.

Tenant ownership map

TenSaaS platform

Sets platform policy, model pricing, contracts, and team grants.

Northstar Operations

Owns active members, installed applications, entitlements, and credits.

Application registry

Only approved team applications can run.

Team quota ledger

Reserve first, settle actual usage, release the remainder.

Every run resolves a team, member, application, entitlement, and receipt.

The team is the unit of AI operations

TenSaaS separates platform policy from team operations, so applications and spend never become ownerless shared resources.

Tenant isolation by construction

Every workspace request resolves the signed-in user and an active team membership before reaching team-scoped data.

Quota with an accountable ledger

Team grants, reservations, settlement, refunds, and adjustments remain attributable instead of collapsing into one balance.

A governed application registry

Teams install applications as managed assets, then open an approved experience directly from the browser.

Two levels of administration

Platform roles govern the service. Team owner, admin, and member roles govern only their own tenant boundary.

Receipts for control-plane actions

Membership, application, entitlement, and quota changes record the actor, team, target, and relevant metadata.

Server-owned policy decisions

The browser cannot choose credit cost or receive application secrets. Sensitive checks stay behind authenticated server routes.

One operating chain, three accountable roles

Platform administrators set the commercial and policy boundary. Team administrators configure the tenant. Members use only what their team has approved.

  1. Allocate contract grants

    The platform assigns a team contract, entitlements, and traceable credit sources.

  2. Install an approved application

    A team owner or administrator enables the application and its permitted model policy.

  3. Run inside the team boundary

    An active member with ai.use opens the browser experience without receiving application credentials.

  4. Reconcile actual usage

    The runtime reserves an estimated cost, settles provider usage, and releases unused credits.

Responsibility boundary

RoleOwned scopePrimary decision
Platform administratorPlatform policy, model prices, contracts, and global risk controlsDecide what the platform can offer
Team owner or adminTeam members, applications, entitlements, and delegated accessDecide what the team can use
Team memberApproved applications and the team quota attached to each runUse allowed capabilities within policy

Application state, membership, entitlement, and quota are checked again at execution time. A failed check stops the run.

Questions enterprise teams ask first

Clear ownership is more important than adding another model or application.

Start with one team and one governed AI application.

Prove the complete ownership, permission, quota, and audit loop before expanding the application catalog.