Multi-tenant management Organizations, agencies and sub-agencies

How Natalia Analytics maps your group structure: a tenant hierarchy of agencies and sub-agencies, deny-by-default data isolation, role scope that flows down the tree, and sub-agency creation from the dashboard.

  • One root organization per customer
  • Up to 10 nested levels
  • Deny-by-default isolation
  • Self-service sub-agencies (admins)

Organizations and hierarchy

Each customer gets one root organization — the group, brand or network. Under that root you create sub-organizations that mirror your real structure: regions, agencies, sub-agencies. The tree nests down to 10 levels (the root counts as level 1).

An agency network, for example, can model its head office, its regions and its local agencies as a single tree:

  • Head office — root organization
    • North region
      • Lille agency
      • Amiens agency
    • South region
      • Lyon agency

Per-tenant isolation

Data access follows a deny-by-default rule: without an explicit role on a node or one of its ancestors, nothing is visible. Sibling organizations and levels above stay invisible — neither their data nor their existence is exposed. Cross-tenant access is impossible by construction.

The technical side of this isolation — layer-by-layer partitioning, encryption, pseudonymization — is covered on the security page.

Roles and visibility scope

A role granted on a node applies to its whole subtree. A head-office administrator sees and administers every region and agency below; an agency administrator sees only that agency and its descendants — never its parent, never its siblings. Visibility flows down the tree, never up.

Two scopes are distinguished: administration (managing members and sub-organizations) and read access (consulting the analytics). The detailed application roles are described on the security page (RBAC).

Creating a sub-agency from the dashboard

Sub-agencies are created from the dashboard, and only by an administrator of the parent organization.

  1. From the Organization view, an administrator opens creation under the chosen node.
  2. They enter the sub-agency name and confirm.
  3. The sub-organization appears immediately under its parent and inherits the accesses already granted on its ancestors.

The depth limit (10 levels) is enforced server-side: a creation that would exceed it is rejected. Renaming an organization is self-service for its administrators. Creating a new root organization (a new customer) and deleting an organization are handled by the Natalia team.