Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Customer-Managed Tenant
Governance, Ownership & Risk

Customer-Managed Tenant

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Governance, Ownership & Risk

A customer-managed tenant is a cloud environment operated within the buyer’s own administrative boundary rather than a shared vendor tenancy. For regulated identity governance, it gives the organisation stronger control over residency, administration, and evidence generation while still relying on cloud-delivered application software.

What Customer-Managed Tenant Means in Practice

A customer-managed tenant is still a vendor-delivered cloud service, but the tenant boundary, administrative control, and operational evidence sit with the customer. That changes who can configure access, review activity, and demonstrate compliance, even when the underlying software remains shared.

This model is often chosen when the organisation needs clearer separation between its own controls and the provider’s shared service layer. It is not the same as running everything on-premises, because the application and hosting are still cloud-based; the practical difference is that the customer owns more of the administrative boundary.

Why Tenant Control Matters for Governance

The key value of a customer-managed tenant is governance. A NIST Privacy Framework lens fits because residency, admin boundaries, and evidence generation all affect how organisations govern data use and accountability inside the tenant.

For regulated environments, tenant control can determine who approves changes, where records are held, and how quickly an organisation can produce audit evidence. That makes the model especially relevant when the buyer needs to show that tenant administration, logging, and retention are under its own control rather than left entirely to a shared provider default.

Customer-managed tenancy also changes the operational meaning of “ownership.” The customer may not own the cloud stack, but it does own the configuration decisions that shape access, segregation, and the trust boundary around the hosted service.

Security and Access Implications

Security is usually improved by tighter control, but only if the tenant is actually governed well. A customer-managed tenant can reduce exposure from shared administration, yet it can also concentrate risk if privileged access, tenant settings, or recovery paths are not controlled carefully. The NIST Cybersecurity Framework 2.0 is relevant because the model depends on good governance, protection, detection, and recovery across the tenant boundary.

In practice, the main security questions are who can administer the tenant, how access is reviewed, and how logging is retained for investigation and assurance. If those functions are weak, the tenant may be customer-managed in name but still behave like a lightly governed shared environment.

This is also where cloud identity and privilege controls matter: the tenant boundary only helps if administrative rights are limited, monitored, and recoverable after compromise or misconfiguration.

When Customer-Managed Tenancy Becomes a Design Choice

Teams usually adopt this model when the tenant needs to satisfy regulatory, contractual, or internal control requirements without abandoning cloud software. It is a design choice about accountability, not just hosting, because it determines which controls the customer can directly operate and evidence.

That makes it useful for organisations that need stronger assurance over administration, auditability, and configuration drift. It is less valuable when the business wants simple consumption of SaaS with minimal operational responsibility, because customer-managed control brings real governance overhead.

In other words, the model trades convenience for authority. The more the organisation wants to own the control story, the more attractive customer-managed tenancy becomes.

Risk and Threat Considerations

Customer-managed tenancy can reduce dependency risk, but it also shifts more of the security burden onto the customer. Misconfigured admin roles, weak logging, and poor tenant segregation can turn the customer boundary into the primary failure point rather than the provider itself.

Failure mechanism: Excessive tenant privileges, inadequate review of configuration changes, or weak evidence retention can let an attacker or insider persist inside the customer boundary while appearing to operate within normal cloud administration.

Impact: Loss of tenant integrity can expose regulated data, undermine auditability, and create a false sense of control because the environment appears customer-owned even when its safeguards are poorly governed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextCustomer-managed tenancy defines a buyer-owned administrative boundary and accountability model.
GV.RM-01 — Risk Management StrategyThe model changes how control and dependency risk are accepted across the cloud boundary.
Recommendation — Define tenant ownership, admin boundaries, and evidence responsibilities in the governance model. Classify tenant control, shared responsibility, and recovery assumptions in the risk strategy.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeTenant administration depends on tightly scoped privileged access inside the customer boundary.
AU-2 — Event LoggingCustomer-managed tenants are often chosen to preserve audit evidence under customer control.
Recommendation — Restrict tenant administration to the minimum access needed for each operational role. Log tenant administration and security-relevant activity so evidence stays available for review.
ISO/IEC 27001:2022A.5.15 — Access controlCustomer-managed tenancy centers on who can administer and govern the tenant boundary.
Recommendation — Define and enforce tenant access rules for administrators, support, and reviewers.

Practitioner Guidance

Governance implication: Treat customer-managed tenancy as an accountability model, not a branding choice. The buyer should be able to point to the specific administrative, logging, retention, and access decisions it controls, because those are the controls that make the tenant meaningfully customer-managed.

What to watch for: Watch for blurred ownership between the vendor and the buyer, especially where support access, emergency access, and evidence collection are not clearly assigned. If those boundaries are vague, the tenant may satisfy procurement language without delivering the governance outcome the business expects.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org