One engine.
Many clients. Zero leaks.
Run every client on the same engine without ever crossing the streams. Brand-isolated workspaces, per-client SSO and identity provider, white-label portals, per-client audit, per-client billing. Onboard a new client in hours, offboard cleanly with full export.
- SOC 2 Type II
- ISO 27001
- Per-workspace SSO
- White-label portals
- Per-client audit
- GDPR · DPA on file
Aurora Brands
CPG
142k assets
Northpoint Studios
Entertainment
88k assets
Cobalt & Co.
Fashion
54k assets
Prism Labs
B2B Tech
23k assets
Solstice Group
Travel
67k assets
Nordvik
Home Goods
18k assets
Why agencies are a different problem
Single-tenant DAMs solve one client. You serve thirty.
Four constraints make agency operations different from any single-tenant migration. Univaultport is designed multi-tenant from the storage layer up — tenancy is not a permission, it is a workspace.
- Cross-client leak
Brand-isolation at scale
One mis-permissioned tag, one shared template, one shared search index — and Client A sees Client B's assets. The blast radius scales with the client count. Generic tools don't encode tenancy at the storage layer; you find out at the worst possible moment.
- Compliance fragments
Per-client compliance
One client demands SOC 2 Type II evidence. Another wants HIPAA. A third needs EU-only data residency. A fourth has a custom DPA. Single-tenant DAMs cannot satisfy all four at once; per-client workspaces can.
- Branding cost compounds
White-label overhead
Some clients want to see their own logo, custom domain, and brand colours on the portal — not yours. Standing that up for every client manually means weeks per onboarding. Doing it cleanly across 30+ clients is its own engineering programme.
- Growth ceiling
Onboarding velocity
Win a new client on Monday — should be operational Friday. That means provisioning a workspace, importing the source library, mapping their schema, configuring SSO against their IdP, and turning on white-label. If each step is manual, agency growth caps at the ops team's throughput.
Multi-tenant capabilities
Nine capabilities. All workspace-scoped, never global.
Every capability below is scoped to the workspace, not the agency-wide account. That is what makes the multi-tenant story survive a security review — the isolation is at the data layer, not just at the UI.
Brand-isolated workspaces
Each client gets a separate tenant at the storage, identity, and audit layer. Storage prefixes are hard-isolated. Searches never cross workspaces. Misconfigurations cannot leak between clients.
Per-client SSO + IdP
Each workspace authenticates against the client's own identity provider. Okta for one, Azure AD for the next, Google Workspace for a third. SAML 2.0 + SCIM provisioning per workspace.
White-label portals
Client logo, brand colours, custom domain, custom email sender. The client team interacts with what looks like the agency's own product. Agency branding is one toggle away when needed.
Per-client compliance posture
One workspace can hold SOC 2 evidence, another HIPAA BAA, a third EU-only residency, a fourth a custom DPA. Each posture is configured on the workspace, not the agency-wide account.
Cross-client templates
Agency-side templates — migration runbooks, ingest configurations, taxonomy starter packs — apply across workspaces without leaking data. Configuration is shared; content is not.
Agency-level rollups
See aggregated throughput, costs, and uptime across all client workspaces in one operator view, without ever exposing one client's assets to another. The dashboard is a metadata-only roll-up.
Per-client billing & chargeback
Per-workspace usage metering for assets stored, bandwidth, API calls, and migration jobs. Export as chargeback CSV for client invoicing or showback for internal cost transparency.
Audit isolation per client
Every workspace has its own immutable audit log. Each client can be handed a filtered export of their own activity for security reviews — no cross-pollination, no manual redaction.
Lifecycle automation
Spin up a new client workspace from a runbook in under an hour. Offboard cleanly with full export + audit handoff in under a day. The onboarding playbook is a one-button operation.
Inside an onboarding
Five stages, one workspace, isolation verified at every gate.
Each new client workspace runs through the same five-stage lifecycle. Cross-tenant isolation is probed at every gate; if a probe ever returns a positive, the workspace is held until engineering reviews. The log below shows a typical onboarding run from kick-off to "live".
Onboard
Provision client workspace
Configure
SSO · branding · compliance
Migrate
Import client library
Operate
Per-workspace metering + audit
Offboard
Clean export + audit handoff
Multi-tenant primitives
Every primitive a multi-client deployment should ship with on day one.
Isolation, identity, white-label, compliance, billing, and lifecycle automation. Every category below is workspace-scoped and configurable per client — not a global agency-wide setting that leaks across tenants.
Isolation models
- Per-workspace storage prefix
- Per-workspace search index
- Per-workspace audit log
- Per-workspace encryption key· CMK / BYOK
- Cross-tenant probe checks
Identity primitives
- SAML 2.0 SSO · per workspace
- SCIM 2.0 provisioning
- OIDC for headless apps
- RBAC + ABAC roles
- Group inheritance · per IdP
White-label primitives
- Custom domain · CNAME
- Custom logo + favicon
- Brand colour palette
- Custom email sender + template
- Hide agency branding · toggle
Compliance posture
- SOC 2 Type II · per workspace
- ISO 27001 evidence pack
- HIPAA · BAA on file
- GDPR · per-tenant DPA
- Data residency · EU / US / APAC
Billing & metering
- Per-workspace storage usage
- Per-workspace bandwidth
- Per-workspace API call count
- Per-workspace job throughput
- Chargeback CSV export
- Showback report · monthly
Lifecycle automation
- Onboarding runbook · 1-click
- Workspace template · clone
- Offboarding · full export
- Archival mode · read-only
- Audit handoff · ZIP package
Ecosystem
Talks to each client's stack on their terms.
Every workspace can bind to its client's own identity provider, DAM, work-management system, and billing tool. The agency operator sees a unified roll-up; each client sees only their own integrations.
White-label SDK
Custom integrations a single client needs — internal systems, regulated environments, agency-built tooling. Share the API contract; we ship a workspace-scoped connector in 2–4 weeks.
Identity providers · per client
Okta
● native
Auth0
● native
Azure AD · Entra
● native
Google Workspace
● native
OneLogin
● native
JumpCloud
● custom
Ping Identity
● custom
Client DAM / CMS stacks
AEM Assets
● native
Cloudinary
● native
Bynder
● native
Brandfolder
● native
Widen · Acquia
● native
Frontify
● native
WordPress
● native
Contentful
● native
Work management
Adobe Workfront
● custom
Asana
● custom
Monday.com
● custom
ClickUp
● custom
Wrike
● custom
Jira · Atlassian
● custom
Time & billing
Harvest
● custom
Toggl Track
● custom
FreshBooks
● custom
Bonsai
● custom
QuickBooks
● custom
Xero
● custom
Creative & design tools
Adobe Creative Cloud
● native
Figma
● custom
Sketch
● custom
Canva
● custom
Frame.io
● custom
Reference scenario
A creative agency's 22-client consolidation.
Composite shape. Numbers below match the median of mid-market agency engagements we've sized; the narrative is not a specific customer.
“We win a new pitch on Monday, the workspace is live on Tuesday with their Okta wired up, their brand colours on the portal, and their last DAM's library imported. That cadence is the moat — not the migration tooling itself.”
VP of Operations · Independent creative agency · Mid-market
0 clients
on one engine
0 M+
assets across workspaces
0 min
median client onboarding time
0
cross-tenant leak incidents
Workspace count
22 active
4 archived offboarded clients · read-only for evidence retention
Identity providers
11 distinct
Okta · Azure AD · Google Workspace · Auth0 · OneLogin · custom
White-label portals
14 deployed
custom domains · brand colours · client-owned look-and-feel
Per-client compliance
fully mixed
SOC 2 evidence · HIPAA BAA · EU residency · all in one engine
Frequently asked
The agency-ops questions that come up on every call.
Tenancy is enforced at four layers: storage prefixes (each workspace has its own object-store namespace, never co-mingled), search indexes (each workspace has its own index, queries cannot span workspaces), audit logs (per-workspace immutable logs), and identity (each workspace binds to its own IdP). Cross-tenant probes run continuously in CI and in production canaries — every release ships against a test suite that attempts cross-tenant reads and must fail at the storage layer, not at the permission layer.
Book an agency consultation
Talk to someone who has stood up 30+ client workspaces.
30 minutes. We sketch your tenancy model on the call, walk you through the onboarding runbook for your client size, and you leave with a written multi-tenant plan either way.
- Tenancy model sketch (isolation + identity + branding)
- Per-client compliance posture mapped to your client mix
- Pricing band based on active client count
- Honest fit assessment — we say no if we are not the right tool
Run them all.
Without crossing the streams.
A 30-minute call with an agency-ops architect. Bring your client list and current stack; leave with a written tenancy plan and a per-client cost band you can hand to the partners.
Univaultport for Agencies · Multi-tenant. White-labelled. Audit-isolated.