Multi-tenant management Organizations, agencies and sub-agencies
How Natalia Analytics maps your group structure: a tenant hierarchy of agencies and sub-agencies, deny-by-default data isolation, role scope that flows down the tree, and sub-agency creation from the dashboard.
- One root organization per customer
- Up to 10 nested levels
- Deny-by-default isolation
- Self-service sub-agencies (admins)
Organizations and hierarchy
Each customer gets one root organization — the group, brand or network. Under that root you create sub-organizations that mirror your real structure: regions, agencies, sub-agencies. The tree nests down to 10 levels (the root counts as level 1).
An agency network, for example, can model its head office, its regions and its local agencies as a single tree:
- Head office — root organization
- North region
- Lille agency
- Amiens agency
- South region
- Lyon agency
- North region
Per-tenant isolation
Data access follows a deny-by-default rule: without an explicit role on a node or one of its ancestors, nothing is visible. Sibling organizations and levels above stay invisible — neither their data nor their existence is exposed. Cross-tenant access is impossible by construction.
The technical side of this isolation — layer-by-layer partitioning, encryption, pseudonymization — is covered on the security page.
Roles and visibility scope
A role granted on a node applies to its whole subtree. A head-office administrator sees and administers every region and agency below; an agency administrator sees only that agency and its descendants — never its parent, never its siblings. Visibility flows down the tree, never up.
Two scopes are distinguished: administration (managing members and sub-organizations) and read access (consulting the analytics). The detailed application roles are described on the security page (RBAC).
Creating a sub-agency from the dashboard
Sub-agencies are created from the dashboard, and only by an administrator of the parent organization.
- From the Organization view, an administrator opens creation under the chosen node.
- They enter the sub-agency name and confirm.
- The sub-organization appears immediately under its parent and inherits the accesses already granted on its ancestors.
The depth limit (10 levels) is enforced server-side: a creation that would exceed it is rejected. Renaming an organization is self-service for its administrators. Creating a new root organization (a new customer) and deleting an organization are handled by the Natalia team.