Skip to main content
If you run a platform on Namespace, your customers should never see each other’s work. Tenants make that separation part of the infrastructure: each customer gets their own tenant, and everything they run lives inside it.

What is a tenant?

A tenant is an isolated space in Namespace that owns resources: instances, builds, volumes, caches, secrets, and the credentials that access them. The rest of Namespace calls the same thing a workspace. Tenants are isolated from each other:
  • Resources created in one tenant are invisible to every other tenant.
  • A tenant’s credentials only work inside that tenant.
  • Limits, such as how many instances can run at once, apply to each tenant separately.
A typical platform creates one tenant per customer, so each customer’s data and workloads stay separate from every other customer’s.

How your platform and its tenants work together

Your platform manages tenants with partner credentials. With them, it can: Work inside a tenant happens with a tenant credential. Your platform uses one to act for a customer, and it can give customers their own. With a tenant credential you can:
  • Run instances, builds, and other workloads.
  • Use storage, such as cache volumes, the container registry, and secrets.
  • Read the tenant’s policies.
  • Create revokable tokens for systems outside your platform.
In code, these two roles are a partner client and a tenant client. Partner and tenant clients explains how to create each one.

What a tenant looks like

Next steps

Quickstart

Create a tenant and act inside it with a tenant token.

Authentication

The credentials your platform and its tenants use.
Last modified on October 2, 2026