A tenant design that treats the customer organisation as the primary access boundary rather than the individual user. It ties users, domains, policies, and lifecycle events to one durable structure so onboarding, role changes, and offboarding can be governed consistently as the customer evolves.
What the organisation-centric model is
An organisation-centric identity model treats the customer organisation, not the individual user, as the durable boundary for identity governance. That makes the tenant, its policies, and its lifecycle the stable unit of control, so access decisions stay consistent as people join, move roles, or leave.
This model is common where a platform must support many customer organisations with different internal structures, approval paths, and policy needs. It is less about a single person’s account history and more about how the organisation defines ownership, administrative scope, and continuity over time.
For product teams, the key design choice is that changes are evaluated against the organisation’s structure and rules rather than handled as isolated user events. That is what allows onboarding, role change, and offboarding to be governed as part of one account and policy boundary.
How the tenant boundary shapes access and governance
In an organisation-centric model, the tenant typically becomes the unit for membership, policy assignment, and administrative control. A user’s rights are therefore interpreted through their organisation context, which helps avoid fragmented decisions across disconnected accounts or ad hoc per-user exceptions.
This approach is especially useful when access depends on internal departments, delegated administrators, approval chains, or shared policy sets. It supports a clearer ownership model because the organisation can define who manages users, what roles exist, and which lifecycle events trigger review or revocation.
It also helps platforms keep identity and access logic aligned with the customer’s real operating model. Instead of treating every account as a standalone object, the system can preserve organisational continuity when employees transfer, contractors depart, or policies change centrally.
That is why broader identity operating-model guidance such as Identity Security Programme Guide is relevant here: the model only works cleanly when ownership, governance, and lifecycle responsibilities are defined at the organisation level.
Lifecycle management in an organisation-centric design
The practical strength of this model is that it makes onboarding and offboarding more deterministic. When the organisation is the primary boundary, the system can apply consistent defaults for new members, inherit approved role structures, and retire access when membership ends or status changes.
That matters because lifecycle mistakes are often caused by partial updates, duplicated records, or unclear responsibility after a user’s role changes. A durable organisation structure reduces that drift by keeping the policy source of truth tied to the customer entity rather than to transient user records.
In mature implementations, lifecycle handling also extends to domains, approvals, and delegated administration. The result is a cleaner path for recurrence checks, periodic review, and access closure when the organisation’s internal structure changes. The same lifecycle logic is a major theme in NHI Lifecycle Management Guide, which shows how durable ownership and offboarding reduce control drift across changing identities.
For readers mapping the model to access governance, Ultimate Guide to NHIs , Regulatory and Audit Perspectives is a useful navigation point because the same idea of durable ownership underpins reviewability and auditability.
Where the model is most useful, and where it can go wrong
Organisation-centric identity is strongest in B2B platforms, multi-tenant SaaS, and shared enterprise services where a customer’s internal hierarchy matters. It gives each customer a stable control plane for identity and policy, which simplifies administration and supports consistent enforcement across the tenant.
The trade-off is that the model can become too coarse if individual accountability, delegated exceptions, or cross-organisation collaboration are not designed carefully. If the tenant boundary is treated as a substitute for real authorisation logic, teams can end up with overbroad access, awkward exceptions, or weak separation between organisations.
It also requires clean mapping between organisation membership and actual privilege. When that mapping is stale or loosely governed, the model can hide access creep because the structure looks stable even while the underlying entitlements drift.
For practical orientation, Zero Trust Identity Guide is a good companion reference because it reinforces the idea that the boundary must be continuously verified, not assumed safe just because it is organisationally well formed.
Risk and Threat Considerations
Organisation-centric models reduce administrative chaos, but they also concentrate trust. If the tenant boundary, delegated administration, or lifecycle mapping is compromised, an attacker or careless administrator can affect many users and policies at once rather than a single isolated account.
Failure mechanism: Stale membership, overbroad tenant-level privileges, or weak offboarding can preserve access long after a user should have lost it, creating a scalable path for misuse or takeover.
Impact: The result can be broad privilege abuse, cross-user exposure, or organisational-wide access persistence that is harder to detect because the failure sits in the model’s control plane rather than in one individual account.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Covers lifecycle governance for organisation-scoped accounts and membership changes. |
| AC-6 — Least Privilege | Organisation-centric boundaries only work when tenant-level access is narrowly assigned. | |
| IA-2 — Identification and Authentication (Organizational Users) | Organisation-centric identity models still depend on strong user authentication inside the tenant boundary. | |
| Recommendation — Define tenant account lifecycle ownership and revoke access promptly when organisation membership changes. Limit tenant and delegated admin access to the minimum needed for each organisation role. Require strong authentication for organisational users before granting tenant access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Directly supports policy-bound tenant access and organisation-scoped authorisation decisions. |
| A.5.18 — Access rights | Supports review, removal, and governance of access as organisational roles change. | |
| Recommendation — Document and enforce organisation-scoped access rules for each tenant boundary. Review and remove access rights when organisational roles, membership, or ownership change. | ||
Practitioner Guidance
Governance implication: Treat the organisation as the primary policy owner, but make role mapping and offboarding explicit at the account and entitlement level. The model only works when the tenant boundary is paired with clear ownership, review cadence, and delegated administrative limits.
Practitioner takeaway: Use the organisational boundary to simplify control, not to hide complexity, because access still needs to be validated where people, roles, and entitlements actually change.
Related resources from NHI Mgmt Group
- What should organisations measure in an identity-centric operating model?
- Why do organisations need an identity-centric security model when a single compromised identity can create broad exposure?
- What are the signs that an organisation’s authentication model is failing against modern identity attacks?
- What is the difference between identity-centric ZTNA and an on-prem firewall VPN model?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org