One pane of glass.
Every customer you manage.
Orendyr's core hierarchy is MSP → Customer → Tenant. Rollups across a book of business aggregate metadata only, region-by-region. Raw identity data never leaves the region it was collected in. Bridge or Silo isolation — your pick per customer.
Built for the MSP → Customer → Tenant reality.
One MSP operating on behalf of many customers, each with one or more directory tenants. Rollups across a book of business are region-bounded. Raw identity data never leaves the region it was collected in.
Bridge
Default · shared application tierPer-tenant Postgres schema. Envelope encryption: each tenant gets its own DEK, wrapped by a shared KEK in KMS. The right balance of blast radius and unit economics for most customers.
Silo
Premium · dedicated storageDedicated Postgres cluster. Per-tenant KMS key. Nothing crosses tenant boundaries at rest or in flight. For customers with residency mandates that don't bend.
MSP operators see posture across every customer — as metadata. Raw identity data stays in-region. The rollup crosses customers; the data never does.
We're boring about what's underneath. On purpose.
No proprietary datastore. No homegrown event bus. Nothing here would surprise your platform team in a 30-minute architecture review. That's the point.
What MSPs get on day one
See violations, stale grants, and break-glass activity across every customer without switching tabs.
Publish a workflow once — roll it out to every customer tenant with per-customer overrides.
Region-bounded metadata rollups feed your invoicing. No raw identity data crosses customer boundaries.