Tenant isolation by construction
Every workspace request resolves the signed-in user and an active team membership before reaching team-scoped data.
TenSaaS multi-tenant AI control plane
Create teams, install governed AI applications, assign access, and reconcile actual model usage in one control plane.
TenSaaS platform
Sets platform policy, model pricing, contracts, and team grants.
Northstar Operations
Owns active members, installed applications, entitlements, and credits.
Only approved team applications can run.
Reserve first, settle actual usage, release the remainder.
Every run resolves a team, member, application, entitlement, and receipt.
TenSaaS separates platform policy from team operations, so applications and spend never become ownerless shared resources.
Every workspace request resolves the signed-in user and an active team membership before reaching team-scoped data.
Team grants, reservations, settlement, refunds, and adjustments remain attributable instead of collapsing into one balance.
Teams install applications as managed assets, then open an approved experience directly from the browser.
Platform roles govern the service. Team owner, admin, and member roles govern only their own tenant boundary.
Membership, application, entitlement, and quota changes record the actor, team, target, and relevant metadata.
The browser cannot choose credit cost or receive application secrets. Sensitive checks stay behind authenticated server routes.
Platform administrators set the commercial and policy boundary. Team administrators configure the tenant. Members use only what their team has approved.
The platform assigns a team contract, entitlements, and traceable credit sources.
A team owner or administrator enables the application and its permitted model policy.
An active member with ai.use opens the browser experience without receiving application credentials.
The runtime reserves an estimated cost, settles provider usage, and releases unused credits.
| Role | Owned scope | Primary decision |
|---|---|---|
| Platform administrator | Platform policy, model prices, contracts, and global risk controls | Decide what the platform can offer |
| Team owner or admin | Team members, applications, entitlements, and delegated access | Decide what the team can use |
| Team member | Approved applications and the team quota attached to each run | Use allowed capabilities within policy |
Application state, membership, entitlement, and quota are checked again at execution time. A failed check stops the run.
Clear ownership is more important than adding another model or application.
Why tenant boundaries, application permissions, and quota receipts shape a dependable enterprise AI platform.
Prove the complete ownership, permission, quota, and audit loop before expanding the application catalog.