Solutions·Agencies

One engine.
Many clients. Zero leaks.

Run every client on the same engine without ever crossing the streams. Brand-isolated workspaces, per-client SSO and identity provider, white-label portals, per-client audit, per-client billing. Onboard a new client in hours, offboard cleanly with full export.

  • SOC 2 Type II
  • ISO 27001
  • Per-workspace SSO
  • White-label portals
  • Per-client audit
  • GDPR · DPA on file
Agency · 6 client workspaces
isolated

Aurora Brands

CPG

142k assets

Northpoint Studios

Entertainment

88k assets

Cobalt & Co.

Fashion

54k assets

Prism Labs

B2B Tech

23k assets

Solstice Group

Travel

67k assets

Nordvik

Home Goods

18k assets

Engine routing · Aurora Brands · Migrated 412 hero shots
1.42 GB/s · 99.99%

Why agencies are a different problem

Single-tenant DAMs solve one client. You serve thirty.

Four constraints make agency operations different from any single-tenant migration. Univaultport is designed multi-tenant from the storage layer up — tenancy is not a permission, it is a workspace.

  • Cross-client leak

    Brand-isolation at scale

    One mis-permissioned tag, one shared template, one shared search index — and Client A sees Client B's assets. The blast radius scales with the client count. Generic tools don't encode tenancy at the storage layer; you find out at the worst possible moment.

  • Compliance fragments

    Per-client compliance

    One client demands SOC 2 Type II evidence. Another wants HIPAA. A third needs EU-only data residency. A fourth has a custom DPA. Single-tenant DAMs cannot satisfy all four at once; per-client workspaces can.

  • Branding cost compounds

    White-label overhead

    Some clients want to see their own logo, custom domain, and brand colours on the portal — not yours. Standing that up for every client manually means weeks per onboarding. Doing it cleanly across 30+ clients is its own engineering programme.

  • Growth ceiling

    Onboarding velocity

    Win a new client on Monday — should be operational Friday. That means provisioning a workspace, importing the source library, mapping their schema, configuring SSO against their IdP, and turning on white-label. If each step is manual, agency growth caps at the ops team's throughput.

Multi-tenant capabilities

Nine capabilities. All workspace-scoped, never global.

Every capability below is scoped to the workspace, not the agency-wide account. That is what makes the multi-tenant story survive a security review — the isolation is at the data layer, not just at the UI.

  • Brand-isolated workspaces

    Each client gets a separate tenant at the storage, identity, and audit layer. Storage prefixes are hard-isolated. Searches never cross workspaces. Misconfigurations cannot leak between clients.

  • Per-client SSO + IdP

    Each workspace authenticates against the client's own identity provider. Okta for one, Azure AD for the next, Google Workspace for a third. SAML 2.0 + SCIM provisioning per workspace.

  • White-label portals

    Client logo, brand colours, custom domain, custom email sender. The client team interacts with what looks like the agency's own product. Agency branding is one toggle away when needed.

  • Per-client compliance posture

    One workspace can hold SOC 2 evidence, another HIPAA BAA, a third EU-only residency, a fourth a custom DPA. Each posture is configured on the workspace, not the agency-wide account.

  • Cross-client templates

    Agency-side templates — migration runbooks, ingest configurations, taxonomy starter packs — apply across workspaces without leaking data. Configuration is shared; content is not.

  • Agency-level rollups

    See aggregated throughput, costs, and uptime across all client workspaces in one operator view, without ever exposing one client's assets to another. The dashboard is a metadata-only roll-up.

  • Per-client billing & chargeback

    Per-workspace usage metering for assets stored, bandwidth, API calls, and migration jobs. Export as chargeback CSV for client invoicing or showback for internal cost transparency.

  • Audit isolation per client

    Every workspace has its own immutable audit log. Each client can be handed a filtered export of their own activity for security reviews — no cross-pollination, no manual redaction.

  • Lifecycle automation

    Spin up a new client workspace from a runbook in under an hour. Offboard cleanly with full export + audit handoff in under a day. The onboarding playbook is a one-button operation.

Inside an onboarding

Five stages, one workspace, isolation verified at every gate.

Each new client workspace runs through the same five-stage lifecycle. Cross-tenant isolation is probed at every gate; if a probe ever returns a positive, the workspace is held until engineering reviews. The log below shows a typical onboarding run from kick-off to "live".

onboarding · workspace://aurora
target SLA · 1 hour · ETA 00:18:42● in-flight
  • Onboard

    Provision client workspace

  • Configure

    SSO · branding · compliance

  • Migrate

    Import client library

  • Operate

    Per-workspace metering + audit

  • Offboard

    Clean export + audit handoff

09:14:02aurorainfoONBOARD · provisioned workspace "aurora" · isolated storage prefix /tenants/aurora/
09:14:03aurorainfoCONFIGURE · SAML SSO bound to client Okta · SCIM provisioning enabled
09:14:04aurorainfoCONFIGURE · white-label portal · assets.aurorabrands.example · brand colors applied
09:14:05aurorainfoCONFIGURE · compliance posture · SOC 2 Type II + EU residency · DPA on file
09:14:08aurorainfoMIGRATE · importing from Bynder · 142,000 assets · 18 taxonomies · 3 workflows
09:14:11aurorawarnMIGRATE · rate-limited by source · backing off 1.2s · 3 retries left
09:14:14aurorainfoOPERATE · 8 user seats provisioned via SCIM · audit log streaming to client SIEM
09:14:18aurorainfoOPERATE · daily chargeback report queued · usage: 142.4 GB stored · 28 GB delivered
09:14:22aurorasuccessONBOARDING COMPLETE · workspace live in 0h 20m · isolation verified · cross-tenant probes: 0
isolation verified · cross-tenant probes 0 / 0 · audit isolated to workspaceoperator: agency.ops@ · run #4421

Multi-tenant primitives

Every primitive a multi-client deployment should ship with on day one.

Isolation, identity, white-label, compliance, billing, and lifecycle automation. Every category below is workspace-scoped and configurable per client — not a global agency-wide setting that leaks across tenants.

Isolation models

  • Per-workspace storage prefix
  • Per-workspace search index
  • Per-workspace audit log
  • Per-workspace encryption key· CMK / BYOK
  • Cross-tenant probe checks

Identity primitives

  • SAML 2.0 SSO · per workspace
  • SCIM 2.0 provisioning
  • OIDC for headless apps
  • RBAC + ABAC roles
  • Group inheritance · per IdP

White-label primitives

  • Custom domain · CNAME
  • Custom logo + favicon
  • Brand colour palette
  • Custom email sender + template
  • Hide agency branding · toggle

Compliance posture

  • SOC 2 Type II · per workspace
  • ISO 27001 evidence pack
  • HIPAA · BAA on file
  • GDPR · per-tenant DPA
  • Data residency · EU / US / APAC

Billing & metering

  • Per-workspace storage usage
  • Per-workspace bandwidth
  • Per-workspace API call count
  • Per-workspace job throughput
  • Chargeback CSV export
  • Showback report · monthly

Lifecycle automation

  • Onboarding runbook · 1-click
  • Workspace template · clone
  • Offboarding · full export
  • Archival mode · read-only
  • Audit handoff · ZIP package

Ecosystem

Talks to each client's stack on their terms.

Every workspace can bind to its client's own identity provider, DAM, work-management system, and billing tool. The agency operator sees a unified roll-up; each client sees only their own integrations.

White-label SDK

Custom integrations a single client needs — internal systems, regulated environments, agency-built tooling. Share the API contract; we ship a workspace-scoped connector in 2–4 weeks.

Discuss your agency stack

Identity providers · per client

  • Okta

    native

  • Auth0

    native

  • Azure AD · Entra

    native

  • Google Workspace

    native

  • OneLogin

    native

  • JumpCloud

    custom

  • Ping Identity

    custom

Client DAM / CMS stacks

  • AEM Assets

    native

  • Cloudinary

    native

  • Bynder

    native

  • Brandfolder

    native

  • Widen · Acquia

    native

  • Frontify

    native

  • WordPress

    native

  • Contentful

    native

Work management

  • Adobe Workfront

    custom

  • Asana

    custom

  • Monday.com

    custom

  • ClickUp

    custom

  • Wrike

    custom

  • Jira · Atlassian

    custom

Time & billing

  • Harvest

    custom

  • Toggl Track

    custom

  • FreshBooks

    custom

  • Bonsai

    custom

  • QuickBooks

    custom

  • Xero

    custom

Creative & design tools

  • Adobe Creative Cloud

    native

  • Figma

    custom

  • Sketch

    custom

  • Canva

    custom

  • Frame.io

    custom

Reference scenario

A creative agency's 22-client consolidation.

Composite shape. Numbers below match the median of mid-market agency engagements we've sized; the narrative is not a specific customer.

“We win a new pitch on Monday, the workspace is live on Tuesday with their Okta wired up, their brand colours on the portal, and their last DAM's library imported. That cadence is the moat — not the migration tooling itself.”

VP of Operations · Independent creative agency · Mid-market

  • 0 clients

    on one engine

  • 0 M+

    assets across workspaces

  • 0 min

    median client onboarding time

  • 0

    cross-tenant leak incidents

Workspace count

22 active

4 archived offboarded clients · read-only for evidence retention

Identity providers

11 distinct

Okta · Azure AD · Google Workspace · Auth0 · OneLogin · custom

White-label portals

14 deployed

custom domains · brand colours · client-owned look-and-feel

Per-client compliance

fully mixed

SOC 2 evidence · HIPAA BAA · EU residency · all in one engine

Frequently asked

The agency-ops questions that come up on every call.

  • Tenancy is enforced at four layers: storage prefixes (each workspace has its own object-store namespace, never co-mingled), search indexes (each workspace has its own index, queries cannot span workspaces), audit logs (per-workspace immutable logs), and identity (each workspace binds to its own IdP). Cross-tenant probes run continuously in CI and in production canaries — every release ships against a test suite that attempts cross-tenant reads and must fail at the storage layer, not at the permission layer.

Book an agency consultation

Talk to someone who has stood up 30+ client workspaces.

30 minutes. We sketch your tenancy model on the call, walk you through the onboarding runbook for your client size, and you leave with a written multi-tenant plan either way.

  • Tenancy model sketch (isolation + identity + branding)
  • Per-client compliance posture mapped to your client mix
  • Pricing band based on active client count
  • Honest fit assessment — we say no if we are not the right tool
Form data is confidential — used only to route you to the agency team.

By submitting you agree to our terms. We'll be in touch within one business day to schedule the call.

Run them all.
Without crossing the streams.

A 30-minute call with an agency-ops architect. Bring your client list and current stack; leave with a written tenancy plan and a per-client cost band you can hand to the partners.

Univaultport for Agencies · Multi-tenant. White-labelled. Audit-isolated.