Aeion Platform for Enterprise Multi-Tenant Deployment

Large enterprises deploying SaaS across 5-50 business units, subsidiaries, regional offices, or franchise locations need multi-tenant infrastructure with cross-tenant data sharing, per-BU resource isolation, centralized backup, compliance evidence per BU, and tier-based feature gating. Aeion Platform handles tenant provisioning (Hetzner / Contabo / self-hosted), event-driven federation across BUs via Data Contracts, Aegis point-in-time restore per tenant, and SOC2 / ISO27001 / HIPAA compliance reporting natively.

The Enterprise Multi-Tenant Problem

A large enterprise rolling SaaS out across 5-50 business units, subsidiaries, or regional offices hits the same wall every time. Each BU wants its own customizations, access-control boundary, and reporting scope, and centralized IT can't hand-manage that many per-BU configurations. SSO and identity have to work across BUs so one employee can reach every tenant they're entitled to. BU A's database load can't be allowed to drag down BU B. And compliance fragments by unit: SOX for the finance BU, HIPAA for the health BU, GDPR for the EU subsidiaries — each demanding its own audit trail. Layered on top are per-BU backup retention (7-year for regulated units, 90-day for general), per-BU billing and chargeback for shared platform spend, and per-BU disaster recovery that can restore one unit independently of the rest.

Aeion Platform Federation Architecture

A corporate parent organization maps to a set of tenants, one per business unit, each pinned to the compliance posture and data residency it needs:

Walkthrough — 10-BU Global Enterprise

Consider a global enterprise with roughly $2B in revenue, 8,000 employees, and 10 business units spread across four regions. The goal is to retire eight separate SaaS deployments — Salesforce across three regions, Workday for HR, Coupa for procurement, NetSuite for finance, Marketo for marketing, and ServiceNow for IT — and replace them with a single Aeion deployment. The rollout runs over three months of setup and three more of migration and adoption.

FAQ

Aeion's multi-tenancy is per-database-row tenant_id isolation with optional per-tenant database when stricter separation is required. Each BU appears as its own tenant. Per-BU data is queryable only by users with that tenant's permissions; cross-tenant sharing requires an explicit Data Contract.

All cross-tenant sharing is explicit and driven by Data Contracts (`platform_data_contracts`): each contract names a provider tenant, a consumer tenant, a whitelist of allowed event names, and (for collection data) a whitelist of allowed fields. Default: zero cross-tenant access — nothing crosses without an active contract. FederationService forwards matching Neural Bus events only; it does not expose a live cross-tenant query API. Every forwarded event carries its originating tenant ID.

Per-tenant region pin. BU-Sales-EMEA pinned to EU = all data + backups + replicas stay in EU. For regulated tenants (HIPAA, FINRA), additional encryption + access controls apply.

Yes. Aeion is à la carte per module, so each tenant simply activates the modules it needs — finance/sales BUs typically run more modules, including tiered ones like finance ($49/$99/$199 by feature gate), while a smaller BU might run one or two flat-priced modules, or a tenant can standardize on the ~$399/mo All-Access plan if it wants everything included. Each tenant is billed independently; there's no built-in cross-tenant billing aggregation today, so centralized procurement means reviewing each tenant's invoice.

Aeion Auth supports SAML 2.0, OIDC, OAuth 2.0 across 10+ providers. Common enterprise IdPs: Okta, Azure AD / Entra ID, OneLogin, PingFederate, Auth0. SCIM provisioning supported for auto-add / auto-remove as employees join/leave.

Yes — each tenant generates its own audit trail + compliance reports independently. There's no single org-level rollup report today; for board reporting, an operator exports each tenant's evidence individually. Per-BU evidence is exportable for per-BU regulatory audits (SOX for finance, HIPAA for health, etc).

Shared core schema (out-of-box Aeion modules) + per-tenant custom fields + per-tenant custom collections. Per-BU customizations don't affect other tenants. Schema migrations propagate via Aeion's collection management.

Each tenant carries its own subscription plan and billing history in Aeion Billing, so a BU's platform spend is visible on its own tenant's invoice. There's no built-in automated chargeback-rule engine that aggregates and re-allocates costs across BUs today — IT/finance would reconcile per-tenant invoices manually for internal chargeback.

Per-tenant: Aegis provides continuous PITR, snapshots, and per-tenant backup verification for each BU independently. Recovery time objective (RTO) and recovery point objective (RPO) are configurable per tenant tier. Coordinating DR across multiple BUs for a catastrophic scenario is a process your IT team runs using each tenant's independent recovery tooling — there isn't a single org-level DR orchestration feature.

New tenant provisioned in 1-2 hours via PlatformProvisioningService. Singularity connectors handle data ingestion from acquired company's existing SaaS. Cross-tenant Data Contracts can be configured afterward for any event sharing the new BU needs. Most acquisition integrations complete in 4-8 weeks (vs 6-12 months traditional).

Multi-BU enterprise on a single platform.