Aeion Auth for B2B SaaS

Multi-tenant identity that scales without an identity tax. Per-tenant kernel-enforced data isolation, generic-OIDC federation for any customer's existing Okta / Auth0 / JumpCloud, immutable audit logs ready for SOC 2 evidence — included free in every Aeion deployment. The shape B2B SaaS teams reach for once their customer count crosses ~10 and per-connection identity fees become punitive.

The B2B SaaS Identity Problem

As your B2B SaaS scales, every enterprise customer wants to bring their own IdP (Okta is the dominant one — ~$3B ARR — followed by Auth0, Ping, OneLogin, JumpCloud). Three things land on your engineering team simultaneously:

How Aeion Auth Fits

Aeion Auth isn't a third-party broker — it's an integrated module in your operating system. The three B2B SaaS problems map directly:

Worked Math — 50-Tenant B2B SaaS

A real B2B SaaS at 50 customer-tenants, ~30 active users each, growing 50% YoY.

Per-Tenant Isolation — Kernel-Enforced

Aeion resolves the customer-tenant before any request-handling code runs, and every subsequent database query is automatically scoped to that tenant. There's no step where an engineer has to remember to add a tenant filter — it's applied underneath the application code, on every read and write, for every collection in the system. Cross-tenant access requires deliberate, explicit elevation — it's never the accidental default.

Customer-IdP Federation Flow

When your B2B customer wants to bring their Okta:

SOC 2 / ISO 27001 Evidence

Aeion Auth's audit log captures every auth event with IP, user agent, geolocation, device fingerprint, and a computed risk score. Pair with Aegis (/platform/aegis/compliance) for monthly evidence bundles.

B2B-SaaS Specific FAQ

Yes — every Aeion deployment supports configuring multiple OIDC providers, one per customer-tenant, entirely through the admin panel, at no extra cost. Customer A's tenant federates to Okta; customer B's tenant federates to Auth0; both work simultaneously without code changes.

Two paths. (1) SCIM-driven (recommended): connect the customer's IdP over SCIM 2.0 — when the IT admin disables the user in Okta/Entra, the IdP pushes the deprovisioning to Aeion and access is revoked in near-real-time. (2) Session-driven fallback: even without SCIM, when the user is removed from the IdP the next session refresh fails and Aeion automatically revokes local access.

Yes — Aeion Auth is $0 regardless of customer-tenant count or MAU, included free with whatever Aeion modules you're running. Multi-IdP slots, extended retention, and air-gapped deployment are all included, not gated behind an upgrade — you never cross an MAU threshold that changes your bill.

Tenant resolution is subdomain-based (`<customer-slug>.<your-deployment>.com`), so each customer-tenant already lands on its own isolated `/login` context by host. Per-tenant visual branding (logo/colors on the login page itself) isn't a dedicated auth-module feature today — talk to your account team if a fully white-labeled login UI is a hard requirement.

Yes — "Bring your own Okta / Auth0 / Keycloak" is a sales-friendly story. Customers' IT teams appreciate not having a WorkOS / Frontegg billing surprise on top of YOUR subscription.

Identity that scales with customer count, not against it.