Skip to content
Web Development23 min read

SaaS Product Development in Australia: From Idea to Scalable Software

How to build a SaaS product in Australia: discovery, multi-tenancy, SSO, billing and GST, Xero and Peppol integrations, security, data location and scaling.

01

What does SaaS product development in Australia involve?

SaaS product development turns a repeatable business problem into subscription software that many customer organisations share. In Australia the core engineering is the same as anywhere. What changes is the buying context: GST on subscriptions, accounting integrations such as Xero and MYOB, Privacy Act obligations, customers asking where data lives, and government security expectations if you sell to the public sector.

This guide is for founders, product owners and technology leads deciding how to build a SaaS product for Australian customers. It works from business needs outward: who buys, how they pay and what they must prove to their own customers or regulators. From those needs it moves to product decisions and then to architecture. For the generic depth, see our guides to SaaS product design, subscription billing architecture and AI-powered SaaS development. This page covers the decisions that change in an Australian market, and our digital product development guide for Australia sets out the wider path from idea to platform.

Facts are sourced and dated. Recommendations are labelled as ours, and the example is hypothetical. Nothing here is legal, tax or financial advice: for those questions, go to the OAIC, the ATO, the ACCC or a qualified adviser.

02

Key takeaways

  • Write the business need before the architecture. Buyer type, payment model and compliance profile decide tenancy, identity and hosting.
  • Most early SaaS products should start with a pooled model, tenant context enforced in one place, and a planned path to silo storage for tenants who need it.
  • Offer SSO through OIDC and SAML when buyers with IT teams ask for it, and follow RFC 9700: PKCE for public clients and no implicit grant.
  • Billing needs GST handling and per-customer tax settings, and from 1 July 2027 it needs an online cancellation path to match online sign-up.
  • Integrations with Xero, MYOB and, for invoice-heavy products, Peppol eInvoicing are product features that Australian buyers evaluate.
  • Treat the Essential Eight as guidance, plan for an IRAP assessment only if government buyers require one, and design incident response around the Notifiable Data Breaches scheme.
  • AWS, Azure and Google Cloud all have Sydney and Melbourne regions (Azure's are in New South Wales and Victoria). APP 8 makes you accountable for personal information you send offshore, including to tools.
03

The need-to-architecture map: deciding from the business outward

Many SaaS architecture debates are really unresolved business questions. Teams argue about databases when they have not agreed whether the first customers are sole traders paying by card or government agencies buying through procurement. Those two customers need different products and different platforms.

We use a simple chain: business need, then product decision, then architecture choice, with a note on when to revisit each choice. The table below shows common Australian patterns. Read across a row: if the need is real, the product decision follows, and the architecture serves the product decision. If you cannot fill in the first column with evidence, the rest is guesswork.

Business needProduct decisionArchitecture choiceRevisit when
Sell to small businesses on a self-serve basisSelf-serve sign-up, card billing, guided onboarding, no sales callPooled tenancy with a tenant ID on every record; hosted billing provider; email or passkey login with optional MFAAccount sizes grow or buyers start asking for SSO
Sell to mid-market firms with IT teamsAdmin console, SSO, role templates, audit log, data exportOIDC and SAML through an identity layer, per-tenant identity settings, append-only audit eventsA contract asks for dedicated data storage
Sell to government agenciesSecurity documentation, Australian hosting commitment, assessment readinessAustralian regions, controls mapped to the ISM, readiness for an IRAP assessment, possibly a siloed deploymentProcurement terms are known
Handle health or other sensitive informationCollect less, design consent and retention, restrict who sees whatEncryption, field-level access control, silo or bridge for sensitive stores, breach runbook mapped to the NDB schemeThe data you collect changes
Customers invoice or pay staff through your productOutputs that reconcile with their accounting and payroll systemsXero or MYOB connectors, Peppol through an accredited access point, idempotent sync jobsYour buyers include Commonwealth entities
Usage varies sharply between tenantsTiered or usage-based pricing with clear limitsMetering pipeline, per-tenant rate limits, ability to move heavy tenants to dedicated resourcesOne tenant drives a large share of load
Plan to sell overseas soonMulti-currency prices and per-market tax settingsRegion-aware tenancy, a tax abstraction in billing, per-tenant data locationThe first offshore customer signs

Pro tip

Our rule of thumb: every architecture decision record should name the customer type it serves. If nobody can name one, the decision is probably premature.

04

Product discovery: find the workflow someone will pay to replace

B2B SaaS almost always replaces something: a spreadsheet, an email chain, a desktop product or a manual job someone does every Friday. Discovery is the work of finding which of those workflows is painful enough, frequent enough and owned by someone with a budget.

Talk to the doer and the approver separately. The person who does the work and the person who signs the subscription often want different things. The doer wants fewer steps. The approver wants risk, cost and reporting answered. A product that pleases only one of them stalls in trials.

Map the systems around the workflow. In Australia the workflow often touches an accounting ledger, a payroll system, or government reporting. Single Touch Payroll is a good example: the ATO requires payroll software to send tax and super information each pay day. If your product calculates pay, you are entering a regulated reporting chain, and that changes the build. Find these dependencies in discovery, not in sprint six.

Look for commitment, not compliments. A paid pilot, a signed letter of intent or a customer giving you real data is stronger evidence than enthusiasm in an interview. Our guides to user research methods and validating a product idea before building cover the methods in depth. For the step from evidence to a first release, see MVP development in Australia.

  • What does the customer use today, and what does it cost them in time, errors or risk?
  • Who approves the purchase, and what must they see to approve it?
  • Which systems must the product read from or write to on day one?
  • Does the workflow involve personal, health or financial information?
  • Is any buyer likely to be a government agency or a regulated entity?
  • What would a customer commit (time, data or money) before the product exists?
05

UX research for a product with two audiences

A SaaS product serves at least two audiences: the administrator who sets up the tenant, invites users and manages billing, and the everyday user who does the work. Research both, and design onboarding for each. Administrators need a clear path from sign-up to a configured workspace. Everyday users need to reach the first useful outcome without reading a manual.

Test the unglamorous screens. Empty states, permission errors, failed imports and expired sessions decide whether a trial converts. Test them with real users, using the methods in our usability testing guide. Our SaaS product design guide covers navigation, data tables and dashboards in detail.

Set an accessibility target early. WCAG 2.2 has been a W3C Recommendation since 5 October 2023. The Australian Human Rights Commission's April 2025 guidelines on equal access to digital goods and services sit under the Disability Discrimination Act. They are not legally binding, and vendor coverage reports that they recommend WCAG 2.2 Level AA. If Commonwealth agencies are buyers, note that the Digital Service Standard requires their digital services to meet the latest version of WCAG. Building to WCAG 2.2 AA in your design system is cheaper than retrofitting it. Our website accessibility guide for Australia covers the detail.

06

Multi-tenancy: silo, pool and bridge

AWS's SaaS Lens defines three tenancy models, and they are a useful shared language. In a silo model, ‘tenants are provided dedicated resources’. Even so, AWS notes that a silo ‘still relies on a shared identity, onboarding, and operational experience’. In a pool model, ‘tenants share resources’, which AWS calls ‘the more classic notion of multi-tenancy’. A bridge model is ‘a mixed mode where some of the system is implemented in a silo model and some is in a pooled model’.

AWS gives an example of why a bridge emerges: ‘the regulatory profile of a service's data and its noisy neighbor attributes might steer a microservice to a silo model.’ That is the common Australian pattern. A product starts pooled for small businesses, then a health provider or government buyer needs its data held separately.

Enforce tenant context in one place. Resolve the tenant from the authenticated session, not from a request parameter, and apply it in the data access layer so no query can run without it. AWS's tenant isolation whitepaper, now kept for historical reference, puts it plainly: ‘Tenant isolation is fundamental to the design and development of software as a service (SaaS) systems.’

Test isolation like a feature. Write automated tests that sign in as tenant A and try to read, update and export tenant B's records through every API. Run them on every release.

Plan the escape hatch. Keep tenant data addressable by tenant ID, so one tenant's data can move to dedicated storage without rewriting the application. That seam turns a pool into a bridge when a contract demands it.

ModelStrengthsCostsFits
PoolLowest running cost per tenant; one deployment to update; simple onboardingIsolation depends on code discipline; noisy neighbours share capacitySelf-serve small business products; early MVPs
SiloStrong isolation; per-tenant data location and maintenance windowsHigher cost per tenant; more deployments to manageGovernment, health or enterprise tenants with contractual isolation needs
BridgeIsolation where it matters, shared services elsewhereTwo operating patterns to monitor and supportProducts with a mix of small and high-assurance tenants
A bridge model: shared control plane, mixed data tier
            Shared control plane
  +----------------------------------------+
  | identity | onboarding | billing | ops  |
  +----------------------------------------+
         |                     |
   Pooled app tier       Pooled app tier
         |                     |
  +--------------+     +------------------+
  | shared store |     | dedicated store  |
  | tenants A,B,C|     | tenant D (agency)|
  +--------------+     +------------------+
07

Authentication: SSO, OIDC, SAML and current OAuth practice

Self-serve products can start with email and password or passkeys, plus optional multi-factor authentication. Once you sell to organisations with IT teams, single sign-on becomes a buying requirement. Support OpenID Connect for modern identity providers and SAML for enterprise directories that still rely on it, configured per tenant so each customer connects its own provider.

Follow RFC 9700. The IETF's OAuth 2.0 Security Best Current Practice (January 2025) says ‘Public clients MUST use PKCE’ and that clients ‘SHOULD NOT use the implicit grant’ because it is vulnerable to token leakage and replay. If your product has a single-page app or mobile app, use the authorisation code flow with PKCE.

Decide how you price SSO. Some vendors put SSO only in their top tier. CISA's Secure by Design guidance argues the opposite: make ‘MFA, logging, and SSO available at no extra cost’. Multi-factor authentication is also one of ASD's Essential Eight strategies. We recommend at least offering MFA on every plan. Whether SSO sits in every plan is a commercial decision, but expect security-conscious buyers to ask.

Plan for user lifecycle. Larger customers will want users added and removed automatically when staff join or leave, often through a provisioning standard such as SCIM. Design user records so that an external identity can own them from the start.

08

Permissions and tenant administration

Start with a few role templates (owner, admin, member, read-only) and make every permission check go through one policy layer. Custom roles can come later. A scattered permission model is the hardest thing to fix after launch.

The OWASP API Security Top 10 (2023) explains why this matters. It lists ‘Broken Object Level Authorization’ first and ‘Broken Function Level Authorization’ fifth. Both describe users reaching records or actions they should not, which in SaaS can mean one customer reaching another's data. Check permissions on every object, not only on every screen.

Record administrative actions in an append-only audit log. OWASP's Logging Cheat Sheet recommends logging authentication outcomes, access-control failures and high-risk actions such as privilege changes. Expose the log to tenant administrators. It answers many support and security questions before they reach you.

CapabilityFirst releaseMid-market buyersGovernment or enterprise
RolesFixed role templatesTemplates plus a few custom rolesCustom roles, approval steps for sensitive actions
Sign-inEmail or passkey, optional MFASSO via OIDC or SAML, enforced MFASSO, automated provisioning, session policies
Audit logAdmin actions recordedSearchable log in the admin consoleExport or streaming to the customer's security tools
DataExport to CSVScheduled exports and API accessData location commitments, deletion on exit with confirmation
09

Billing, GST and subscription rules

Payments. Stripe lists Australia among its supported countries, so hosted subscription billing, invoicing and card collection are available without building a payment stack. Whatever provider you use, keep the billing provider's subscription separate from your own entitlements, meaning what each tenant may use. Plans change more often than code should.

GST. The ATO sets the GST registration threshold at A$75,000 of GST turnover (A$150,000 for non-profit bodies), and the GST rate is 10%. Since 1 July 2017, offshore suppliers of digital services to Australian consumers have had to register and charge GST once their Australian sales reach the threshold. In product terms, your billing system needs tax settings per customer, tax shown on invoices, and records your accountant can reconcile. Your own position depends on your circumstances, so confirm it with the ATO or a registered tax agent.

Card surcharges. If you planned to pass card fees to customers, note that the Reserve Bank's March 2026 decision removes surcharging on eftpos, Mastercard and Visa cards from 1 October 2026. American Express and buy now pay later are outside that decision for now.

Subscription and pricing rules from 2027. Australia's unfair trading practices reforms passed Parliament in 2026. According to Allens, the regime commences on 1 July 2027. It includes subscription rules under which online sign-up requires online cancellation that is ‘easy-to-find and straightforward’, plus a new drip pricing provision. A self-serve product should already have a clear cancellation flow and transparent pricing, so build them now. Ask a lawyer how the rules apply to your contracts.

Technical hygiene. Use idempotency keys on payment API calls. Stripe documents that a repeated request with the same key returns the first result rather than charging twice. Verify webhook signatures against the raw request body, and expect duplicate events: Stripe says endpoints ‘might occasionally receive the same event more than once’ and retries for up to three days. Our subscription billing architecture guide covers proration, invoices and state machines.

Worth noting

This section describes product capabilities, not tax or legal positions. GST treatment, registration and the 2027 subscription rules should be confirmed with the ATO, the ACCC's guidance or a qualified adviser.

10

Integrations Australian buyers ask about

For many B2B products, integrations decide the sale. The table lists the ones most likely to come up and what each changes in the build. Our guide to API integration in Australia goes deeper on design and vendor choice.

  • Commonwealth entities must pay Peppol eInvoices within 5 calendar days where both parties use Peppol, compared with 20 days for other invoices, under Finance's RMG 417. Check updated terms, which take effect on 1 January 2027.
  • Treat every sync as retryable: use idempotent writes, store external IDs, and keep a reconciliation screen for customers.
  • Respect rate limits. HTTP 429 may come with a Retry-After header (RFC 6585), so back off with jitter rather than retrying in a tight loop.
  • Show integration health in the product. A broken connection the customer can see and fix costs less than a support ticket.
IntegrationWhat it isWhen it mattersDesign note
XeroAccounting API and an Australian payroll API, authorised with OAuth 2.0Your product creates invoices, records payments or runs payrollStore tokens per tenant, encrypted; handle reconnection when a customer revokes access
MYOBThe MYOB Business API, plus APIs for AccountRight, EXO and AcumaticaYour target customers use MYOB productsConfirm which MYOB product your customers run before building
Peppol eInvoicingAn international eInvoicing network; the ATO is Australia's Peppol Authority, and businesses are usually identified by ABNYou issue invoices to businesses or Commonwealth entitiesConnect through an accredited access point provider; B2B use is voluntary
Single Touch PayrollPayroll software reports tax and super information to the ATO each pay dayYour product calculates or pays wagesUsually integrate with an existing payroll product rather than becoming one
Australia PostShipping and Tracking APIs for labels, orders and tracking (an eParcel or StarTrack contract is needed)Your product manages dispatch or deliveriesPlan for each customer's own contract and credentials
11

Security: a baseline Australian buyers will recognise

Essential Eight as guidance. ASD's Essential Eight lists eight strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. It is guidance, not a legal obligation for private businesses, and it targets your organisation's own environment rather than your product's code. It is still a recognisable baseline for the laptops, cloud accounts and admin access behind your platform. ASD defines maturity levels one to three. As an example, its November 2023 model reportedly expects patches for critical internet-facing vulnerabilities, or those with working exploits, within 48 hours at level one.

IRAP if you sell to government. ASD's Infosec Registered Assessors Program endorses assessors to carry out independent security assessments against the Information Security Manual, including of cloud services. Assessors do not accredit or certify systems on ASD's behalf. Separately, the Digital Transformation Agency's Hosting Certification Framework governs which hosting providers agencies may use for sensitive data. Both are procurement matters, so they only change your product if government agencies are buyers. If they are, decide early, because ISM-aligned controls and Australian hosting are much harder to add later.

Notifiable data breaches. The OAIC received 1,205 notifications in calendar 2025, the highest since the scheme began in 2018, and 716 resulted from malicious or criminal attacks. Health service providers reported the most, with 225. The NDB scheme is enacted law under the Privacy Act. As a SaaS provider you often hold data on behalf of customers who have their own notification duties. Agree in contracts how quickly you will tell them about an incident, and rehearse it.

Ransomware payment reporting. Since 30 May 2025, businesses with annual turnover over A$3 million (per Home Affairs) must report a ransomware or cyber extortion payment to ASD within 72 hours of making it. Put this step in your incident playbook.

Application security. Use the OWASP API Security Top 10 as the checklist for your API, and treat tenant isolation tests as security tests. Our guide to website and application security in Australia covers testing, hosting and incident response. If you add AI features, our AI governance guide for Australia covers the policy side.

12

Data location: Australian regions and APP 8

All three major cloud providers run Australian regions, so local hosting is a practical default rather than a premium option. The details below come from each provider's region documentation.

  • APP 8 requires reasonable steps before disclosing personal information to an overseas recipient, and the Australian entity stays accountable for that recipient's handling of it.
  • The OAIC's guidelines say overseas cloud storage can count as a ‘use’ rather than a ‘disclosure’ when a binding contract limits the provider's handling, subcontractors are bound the same way, and you keep effective control.
  • Your primary database is only one location. List where backups, logs, analytics, support tools, email services and AI model APIs process data too.
  • Publish a sub-processor list. Buyers' security questionnaires will ask for it.
  • If you host in one Australian region, decide whether disaster recovery uses the second Australian region or one offshore, and record why.
ProviderAustralian regionsNotes
AWSAsia Pacific (Sydney) ap-southeast-2; Asia Pacific (Melbourne) ap-southeast-4Both have three Availability Zones; Melbourne is opt-in
Microsoft AzureAustralia East (NSW) paired with Australia Southeast (Victoria); Australia Central and Central 2 (Canberra)Australia East has availability zones; access to Central 2 is restricted
Google Cloudaustralia-southeast1 (Sydney); australia-southeast2 (Melbourne)Three zones in each region

Worth noting

Privacy obligations depend on your organisation, your customers and the data involved. Use the OAIC's APP guidelines and a privacy lawyer for your specific position.

13

Analytics: product, tenant and revenue

SaaS analytics has three layers, and teams often build only the first. Product analytics shows what users do: activation, feature adoption, drop-off. Tenant health shows how each customer account is doing: active seats, connected integrations, time since an admin last logged in. Revenue analytics shows recurring revenue, expansion, contraction and churn by plan and cohort.

Define your activation event before launch. It should be the first moment a tenant gets the value you sell, such as a first invoice synced to Xero or a first job completed, not merely a login. Then track the share of new tenants reaching it within a set number of days.

Collect less. Event data often contains personal information. Under the Australian Privacy Principles you should collect what you need for a stated purpose, so instrument actions rather than recording everything a user types.

  • Tenant created, admin invited, first user active.
  • Activation event reached, with time from sign-up.
  • Integration connected, failed and reconnected.
  • Plan changed, payment failed, payment recovered, cancellation started and completed.
  • Support contact raised, with tenant and feature tags.
14

Monitoring and operations

Tag every log line, metric and trace with a tenant ID. When one customer reports a problem, you need to see their requests without wading through everyone else's. Tenant-tagged telemetry also exposes noisy neighbours before they cause an outage.

Alert on what customers feel. Track error rates and latency on key journeys (sign-in, the core workflow, integration syncs, billing webhooks) per tenant as well as overall. A 1% error rate across the platform can mean 100% failure for one tenant.

Back up and test restores. Regular backups are one of the Essential Eight strategies. For SaaS, also test restoring a single tenant's data to a point in time, because that is the request you will get after a customer's mistake.

Cover Australian business hours. Customers across the country run from UTC+8 in Western Australia to UTC+11 on the east coast during daylight saving. Set support and maintenance windows with that spread in mind, and publish them on a status page.

15

Scaling without a rewrite

Scale problems in SaaS are rarely about raw traffic at first. They are usually uneven tenants, slow reports and integrations that queue up. Respond to the signal you actually see, not to a forecast.

SignalLikely response
One tenant's activity slows othersPer-tenant rate limits and queues; move that tenant's heavy workloads to dedicated resources (bridge)
Reports and dashboards slow the main workflowMove reporting to a read replica or separate analytics store
Integration syncs back up at month endQueue-based processing with backoff, idempotent jobs and visible sync status
A large contract requires isolated dataSilo storage for that tenant behind the shared control plane
First customers outside AustraliaRegion-aware tenancy and per-market tax settings, not a second copy of the product
Release cadence slows as the team growsClearer service boundaries and automated tests, before splitting into more services

Key takeaway

Pooled first, isolated where justified, and split into services only when team or load forces it. That order keeps the product changeable while you are still learning what customers pay for.

16

Hypothetical example: job management software for trades businesses

This example is hypothetical and simplified. A founder wants to build job scheduling and invoicing software for small trades businesses such as electricians and plumbers.

Need to decision. Discovery shows the owner approves the purchase and wants invoices to land in the accounting system without re-keying. Field staff use phones on site. The product decisions follow: self-serve sign-up, card billing with GST shown on invoices, a mobile-first job screen, and a Xero connector at launch because most interviewed customers use it. MYOB waits until demand is proven.

Decision to architecture. A pooled tenancy model in an Australian cloud region, tenant ID enforced in the data layer, isolation tests in the release pipeline, OAuth tokens for Xero stored per tenant, and an idempotent invoice sync with a reconciliation screen.

A year later. A local council asks about using the product for its maintenance crews. That is a new buyer type, so the team revisits the map. They need an audit log, SSO, security documentation and possibly dedicated storage. Because tenant data was always addressable by tenant ID, the council's data can move to a dedicated store behind the same control plane. That is a bridge model, adopted when a contract justified it rather than on day one.

17

Common mistakes

  • Choosing tenancy and hosting before naming the first buyer type.
  • Passing the tenant ID from the browser instead of deriving it from the session.
  • No automated cross-tenant access tests.
  • Hard-coding GST logic in invoices instead of keeping tax settings per customer.
  • A cancellation path that requires emailing support, which the 2027 subscription rules target.
  • Treating SSO and audit logs as enterprise extras, then losing mid-market deals over them.
  • Building integrations as one-off scripts with no retries, idempotency or visible status.
  • Hosting the database in Australia while logs, analytics and AI calls go offshore without anyone recording it.
  • Assuming the Essential Eight or IRAP is mandatory for every SaaS, or ignoring them when government buyers are the target.
18

Sources

Architecture: AWS SaaS Lens, silo, pool and bridge models; AWS, SaaS tenant isolation strategies; Microsoft, architect multitenant solutions.

Identity and API security: IETF RFC 9700, OAuth 2.0 Security Best Current Practice; OWASP API Security Top 10 2023; OWASP Logging Cheat Sheet; CISA Secure by Design; RFC 6585, HTTP 429.

Billing and tax: Stripe global availability; Stripe idempotent requests; Stripe webhook signatures; ATO, registering for GST; ATO, how Australian GST works for non-residents; Allens, Australia's new unfair trading practices regime; RBA media release 2026-10.

Integrations: Xero developer documentation; MYOB developer portal; ATO, identifying businesses on the Peppol network; Department of Finance, RMG 417; ATO, what is Single Touch Payroll; Australia Post Developer Centre.

Security and privacy: ASD, Essential Eight Maturity Model (November 2023); ASD, IRAP; Hosting Certification Framework; OAIC, NDB statistics for 2025; Home Affairs, ransomware payment reporting factsheet; OAIC, APP 8 guidelines.

Regions and accessibility: AWS regions; Microsoft Azure regions list; Google Cloud regions and zones; W3C, what's new in WCAG 2.2; Australian Human Rights Commission, guidelines on equal access to digital goods and services.

Some ATO, ASD and finance.gov.au details come from official pages we could identify but not fully load, and the Essential Eight timeframe is reported rather than quoted. Regulations, region availability and provider features change, so re-check before relying on them. Nothing here is ZSpace client data, and nothing is legal or tax advice.

19

Conclusion

A SaaS product for Australian customers is built with the same engineering as anywhere else. The difference is which decisions you face early. Name the buyer, and the need-to-architecture map tells you how to approach tenancy, identity, billing, integrations and hosting. Start pooled with tenant isolation enforced and tested. Add SSO, audit logs and dedicated storage when buyers justify them. Treat GST settings, accounting connectors, breach response and data location as product features, not afterthoughts.

Revisit the map whenever a new type of customer appears. That habit is what turns an idea into software that can scale without a rewrite.

Shaping a SaaS product?

ZSpace Labs is an India-based, remote-first technology studio working with Australian and international businesses on web platforms and custom software and product and UX design. AEST is UTC+10 and IST is UTC+5:30, a 4.5-hour difference (5.5 hours during AEDT), which leaves a shared working morning on the east coast. If a second opinion on your product or architecture would help, we are happy to talk it through.

Start a Project
FAQ

Common questions.

Multi-tenant SaaS is software where many customer organisations, called tenants, use the same product while their data and settings stay separate. Microsoft's architecture guidance stresses that tenants are distinct from users: one tenant can have many users. Tenants may share infrastructure (a pool model), get dedicated resources (a silo model) or a mix of both (a bridge model). The choice affects cost, isolation, compliance and how easily you can scale.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.