Closing your second client is good news. Running it is where the cost nobody budgeted for shows up, because if every client lives in an isolated installation the work for the second one is identical to the first. You build the same content twice and schedule the same calendar twice. By the tenth client that model no longer scales, and by the fortieth it does not scale by hiring more people either.
SMARTFENSE, a human risk management platform, cuts that multiplication with two capabilities worth keeping apart, because they solve different problems and are purchased separately:
- Multi-tenant separates by organization. One instance that administers others, each with its own autonomy and its data isolated from the rest.
- Multi-catalog separates by subject. Several awareness programs coexisting inside a single organization, each governed by its own team.
They can be used separately or combined. What follows is how each axis works, including what it does not do, plus a table at the end to decide which one you need.
Multi-tenant, several organizations from one management portal
What is the management portal?
The management portal is an instance dedicated to administering other organizations. It sits above them in a tree structure with unlimited levels, and from there it creates content and schedules campaigns that flow down to the organizations beneath it, which we call managed organizations.
The structure supports more than one real level. A partner can have its clients underneath, and one of those clients, if it is a business group or a multinational with subsidiaries, can in turn have its own portal with those subsidiaries below. Each level sees its own scope and whatever hangs from it, never what sits alongside. It is the practical application of the resource pooling that the NIST definition of cloud computing describes as a multi-tenant model. Resources are pooled to serve several consumers while staying isolated from each other.
The portal dashboard shows the aggregated totals for everything beneath it: campaigns already run, campaigns scheduled ahead, custom content created and the number of administrator users. Step into a specific organization and those figures become its own, and if it has its own portal it again shows the sum of its subsidiaries. The aggregated view exists only upward.
There is one detail worth knowing up front. On the first sale the partner receives two accounts, the client organization and the management portal, even with a single client so far. The portal is created from day one because its value shows up at volume, and setting it up later would mean rebuilding what was already done.
When are separate organizations worth it, and when are groups enough?
Not every business group needs separate organizations. A single tenant with people segmented into groups is enough for plenty of cases, and splitting is justified when at least one of these five criteria appears:
- Its own logo per company. If each company in the group has its own visual identity, the end-user view is personalized with that company’s logo, and that calls for separate instances.
- Its own domain and mail server. When each company wants notifications sent from its own infrastructure, that configuration lives in each instance.
- Different time zones. A group operating across several countries that wants the campaign to land at 9 in the morning local time in each one needs every instance to have its own time zone configured.
- Different infrastructures. Separate domains and environments mean separate whitelist implementations, and the same applies when each company has its own Entra ID or another independent identity directory. That kind of split at the base infrastructure level pushes toward dedicated instances.
- Different platform administrators. When one company runs the program with one team and another company runs it with a different team, each with its own roles and permissions, keeping every instance with its own administration setup avoids mixing accesses and responsibilities.
If none applies, a single tenant with solid group segmentation is simpler to run. Splitting for the sake of conceptual tidiness, with none of these reasons behind it, adds administration without giving anything back.

How is content inherited?
Custom content created in the portal flows down automatically to every organization beneath it, and appears in each one’s gallery as predefined content. A newsletter, an interactive module, a phishing or ransomware simulation you built once becomes available across forty organizations without building it again. Inheritance crosses levels, so it also reaches subsidiaries hanging off an intermediate organization.
From there, three moves open up depending on what you need:
- Partial reach. If you want content for a subset rather than everyone, you create it from that intermediate organization’s portal instead of the partner portal, and it only flows down to its subsidiaries.
- Its own version. If you want one organization to have its own variant of something inherited, inside that organization you take the predefined content as a template and create your own custom version.
- Global withdrawal. Deactivating content in the portal removes it from every organization that had received it.
This is what sustains a partner’s value-added service: content you produce once pays off across your whole book of business, and exceptions get resolved case by case. Having your own catalog also works as a differentiator against another partner that only offers SMARTFENSE’s stock content, because the subject matter and the voice you add on top become part of your proposition. Same configure-once-and-inherit principle that applies to branding when the program is served under each client’s own domain.
How do you schedule a campaign for several organizations at once?
From the portal calendar you schedule a campaign once and pick, on the tree structure, which organizations it goes to. Inside each one you narrow the audience by group, by functional area or by hierarchical level. On save, the campaign appears in each target organization’s calendar with its date, without anyone loading it there.
This turns building the annual program into a single pass. Instead of repeating the calendar in every client, you define the program in the portal and it is reflected across the whole book of business. When the group spans countries, each instance’s time zone does the rest and the campaign goes out at the same local hour in each one.
What does the management portal not do?
Here is the fine print, and saying it early saves implementation surprises.
- The parent instance does not hold or manage users. Its users and groups section has no import and no synchronization, because it is not meant for adding people there or sending them campaigns. It works as an administration and content-creation layer, sitting above the organizations that operate. Users live in the managed organizations, and that is where the roster and access get resolved, with each organization’s directory synchronization and SSO handled separately. And from the portal you cannot manage users of the child instances either.
- Inheritance is not total. What flows from the portal down to the organizations is custom content and campaign scheduling. Each instance’s configuration settings are not replicated, and get resolved in each one.
- It is not self-service. The SMARTFENSE team creates the organizations and the portal, and each organization receives the login details for its administrator user. For a book of business that grows gradually this rarely gets in the way, but if your plan is onboarding clients in batches, it belongs in the commercial process rather than the technical one.
Multi-catalog, several subject programs inside one organization
What multi-catalog is, and what it is not
Here is a frequent confusion worth clearing up. A catalog groups related content so it can be worked on in an organized way, and the content catalogs are already available in the platform, as the way SMARTFENSE organizes its material by subject.
Multi-catalog is something else. It is the ability to operate several catalogs in parallel inside a single organization, each managed independently through a system of roles and permissions. Catalogs are the what, content grouped by subject, and multi-catalog is the how it is governed, several programs coexisting in one organization with a separate owner each.
The platform already provides three predefined catalogs, and they can be managed out of the box. The multi-catalog component is what allows enabling and managing additional catalogs beyond those three, each operated separately.
Who is it for?
For organizations where more than one team runs awareness on different subjects. The typical case splits three fronts: information security in the security team, occupational health and safety in HR or prevention, and compliance or ethics in a third team. With multi-catalog each one works its catalog without stepping on the others.
How does it work with roles?
Each role is assigned one or more specific catalogs. The roles that support that assignment are content administrator, campaign administrator, awareness plan administrator and auditor.
Over their catalog, each owner manages their campaign calendar, generates reports, reviews statistics and personalizes content. A user with the awareness plan administrator role and permissions over industrial cybersecurity operates everything in that catalog without interfering with whoever manages the others. That is what lets a multidisciplinary team share one organization and work in an orderly way.
Which catalogs are there?
Content is organized into two families:
- Predefined catalogs, maintained and updated by SMARTFENSE: Information Security for end users, Information Security for advanced users and Industrial cybersecurity.
- Additional catalogs, for whatever subjects each organization needs, such as Health and Safety, Professional ethics or Environment. The organization defines which additional catalogs it wants enabled and loads its custom content onto them.
All predefined content can be edited 100% with no restrictions of any kind, and content can also be built from scratch with the platform’s built-in editors.
Which one do I need?
Multi-tenant and multi-catalog are independent and purchased separately. An organization can use multi-catalog without being multi-tenant, and a multi-tenant portal may or may not use multi-catalog in each organization beneath it.
| Multi-tenant (management portal) | Multi-catalog | |
|---|---|---|
| Separates by | Organization | Subject |
| Problem it solves | Administering many organizations without multiplying the work | Letting several teams run awareness on different subjects inside one organization |
| Unit of work | The organization, in a tree with unlimited levels | The catalog, governed by roles and permissions |
| Data | Each organization isolated; aggregated view only upward | Each catalog managed by its owner, without interference |
| Typical of | Partners, MSSPs and groups with subsidiaries | Organizations with multidisciplinary teams |
When the group also works across several languages, the two axes combine, and that is where it helps to read how a program with HQ in one country and subsidiaries abroad holds together.
Frequently asked questions
Can managed organizations see each other’s data?
No. The portal moves between them and keeps each one’s data separate, so each organization sees only its own information. The aggregated view exists only upward, in the portal, which shows the combined totals of everything beneath it.
How many levels of organizations can be created?
The tree structure supports unlimited levels, so the hierarchy follows the real shape of the book of business, including a client that is a business group and has its own portal with subsidiaries.
If the platform already works with several catalogs, what is the component for?
Out of the box the platform already manages the three predefined catalogs. The multi-catalog component is what allows enabling additional catalogs for whatever subjects the organization needs, and operating them separately through roles and permissions.
Can I send campaigns to people from the management portal?
Not to people in the portal itself, because it administers no roster of its own. You can schedule campaigns from its calendar aimed at the organizations beneath it, choosing within each one the groups, functional areas or hierarchical levels that will receive them.
Can one administrator user hold more than one catalog?
Yes. Each supported role can be assigned one or several catalogs, depending on how much scope that person needs. That covers both the owner dedicated to a single subject and whoever coordinates two or three.
If you are working out how to sustain an awareness program across a book of clients, a group of companies or several internal teams, the management portal and managing multiple catalogs cover one axis each.
Leave a Reply