Customer cloud · projects and access

Give customer teams autonomy inside clear boundaries.

Tenant administrators organise resources into projects, invite colleagues, assign roles and issue credentials while LayerOne enforces operator policy and quota.

Your platform · one control planeOrg · Nordlichtisolated · own usersproject · trainingproject · inference5 users · admin delegatedquota40%Org · Meridianisolated · own usersproject · erpproject · data3 users · admin delegatedquota25%Org · Rheinfeldisolated · own usersproject · portal4 users · admin delegatedquota15%AUDIT · 14:02 quota expanded · 13:58 role granted · 13:41 project created
Workspace
Organisation
Customer account boundary
Structure
Projects
Resources grouped by purpose
People
Role-based
Delegated administration
Automation
Scoped credentials
API access by project
Scope

Access designed around how customer teams work.

Organisation and project structure carries through resources, usage, credentials and audit history.

Organisation administration

Give named tenant administrators control of their own workspace.

Project structure

Group services, people, budgets and credentials by workload or team.

Role assignment

Grant only the actions appropriate to administrators and members.

Scoped API access

Issue automation credentials with project and role context.

Operating workflow

Delegate routine administration without losing governance.

The operator defines the model; the customer manages day-to-day membership and projects.

  1. 01

    Create the tenant

    Establish the organisation and its first administrator.

  2. 02

    Create projects

    Separate resources by team, environment or workload.

  3. 03

    Invite and assign

    Add users and grant project-appropriate roles.

  4. 04

    Audit

    Keep user, API and resource actions attributable.

Two connected responsibilities

Operator control and customer action stay explicit.

Operator responsibility

What the operator governs

  • Tenant administrators
  • Role definitions and policy
  • Organisation and project quotas
  • Cross-tenant audit access
Service consumer

What tenant admins manage

  • Projects and membership
  • Role assignment inside the tenant
  • Scoped credentials
  • Their audit and resource context
Operational outcome

What this changes in the working model.

Outcome 01

Less operator administration

Customer teams handle routine membership and projects.

Outcome 02

Clear resource ownership

Every service and usage record belongs to a project.

Outcome 03

Safer automation

Credentials inherit explicit scope and role.

Return to customer cloud overview
Partner with us

Model the customer organisation, not just the account.

We will map teams, projects, roles and credentials into a delegated access model.