[Developers]

Systems Integrators Management

When systems integrators deliver the platform to their own customers, they need administrative control over their portion of the environment without reaching into other partners' tenants. The Systems Integrators Manageme

Category: ManagementLast Updated: Feb 5, 2026
managementcompliance

Overview#

When systems integrators deliver the platform to their own customers, they need administrative control over their portion of the environment without reaching into other partners' tenants. The Systems Integrators Management module provides that model: each SI gets a bounded namespace within the platform hierarchy, self-service tenant provisioning within their allocated quota, and their own activity dashboards, all governed by the platform operator's policies from above.

This is the operational foundation for a scalable partner ecosystem where oversight and autonomy coexist.

Key Features#

  • SI Lifecycle Management: Create, configure, suspend, reactivate, and decommission Systems Integrator organisations through structured workflows. Each SI maintains its own profile with contact information, business type, industry vertical, geographic region, and billing details.

  • Tenant Allocation and Control: Define how many tenants each SI can provision, set default tenant configurations, and manage tenant creation permissions. SI administrators self-service provision tenants within their allocated quotas, with optional approval workflows for additional capacity.

  • User Management: Control user limits per tenant and across the SI portfolio, manage administrator delegation, and configure cross-tenant access permissions. Track user distribution, activity patterns, and concurrent usage across the SI's tenant base.

  • Feature Access Control: Configure which platform features are available to each SI, from core capabilities through premium and beta features. Set feature-specific usage quotas and programmatic access controls to match licensing agreements and operational requirements.

  • Resource Quotas: Set and monitor resource allocation limits across storage, compute, network, and API consumption. Progressive alert thresholds provide early warning before hard limits are reached, with both soft (warning) and hard (blocking) enforcement options.

  • Billing and Licensing: Support pay-as-you-go, subscription, enterprise contract, and reseller pricing models. Track licence allocation, utilisation, and expiration across the SI's tenant portfolio with usage-based charge tracking.

  • Activity Monitoring: Real-time dashboards showing tenant activity, user login patterns, feature usage, API consumption, storage trends, and error rates across the SI's entire portfolio. Filter by time range, tenant, user, or feature.

  • Tenant Transfers: Transfer tenants between Systems Integrators while preserving all data, user accounts, investigations, and audit history. Transfers include compatibility validation, capacity verification, and notifications to both parties.

Use Cases#

  • Platform operators managing a partner ecosystem of systems integrators who each deliver the platform to government agencies, law enforcement organisations, or enterprise customers under their own brand.
  • White-label deployments where SIs brand and configure the platform for their customers with independent tenant environments, feature sets, and billing relationships.
  • Quota governance ensuring fair resource allocation across the partner ecosystem with proactive monitoring, graduated warnings, and enforcement that prevents any single SI from affecting platform performance for others.
  • Portfolio visibility giving platform operators insight into how the partner ecosystem uses the platform, identifying growth opportunities, at-risk relationships, and optimisation possibilities.

Open Standards#

  • OAuth 2.0 and JWT Bearer Token: Token-based authentication protects typed, auditable read and write workflows across the platform.
  • OAuth 2.0 / JSON Web Token (RFC 6749 / RFC 7519): service-to-service calls between the middleware and the auth service use the OAuth 2.0 client credentials flow, with RS256-signed JWTs carrying scoped claims (auth:tenant:read, auth:tenant:write) that are bound to the requesting tenant.
  • Role-Based Access Control (NIST RBAC / ANSI INCITS 359-2012): every admin endpoint enforces RBAC, with default role sets provisioned per tenant at creation and super-admin gates applied to sensitive operations such as revoking access or transferring tenants between SIs.
  • RFC 4122 UUID: all entity identifiers for SI organisations, tenants, configuration records, and audit entries are generated as version-4 RFC 4122 UUIDs, ensuring globally unique, collision-resistant keys across the partner hierarchy.
  • ISO 8601 datetime: created_at and updated_at timestamps are serialised and parsed as ISO 8601 strings throughout the SI and tenant APIs, providing unambiguous, timezone-aware timestamps for lifecycle events and audit records.
  • SHA-256 hash chaining (NIST FIPS 180-4): every state-changing administrative action is written to a tamper-evident, hash-chained audit log where each entry includes the SHA-256 digest of its predecessor, detecting any retrospective tampering with SI or tenant records.
  • HMAC-SHA-256 webhook signing: partner integration webhooks store a hashed secret derived with HMAC-SHA-256, allowing receiving endpoints to verify the authenticity and integrity of event payloads before processing quota or lifecycle notifications.
  • ISO/IEC 27001: the platform acknowledges ISO 27001 as a governing compliance framework for the multi-tenant environment, shaping audit-retention policies (30-day to 3,650-day configurable windows) and information security controls applied to each SI namespace.

Getting Started#

  1. Define SI Template: Establish default configurations, quotas, and feature sets for new Systems Integrator onboarding.
  2. Create SI Organisation: Provision the SI with profile details, administrator credentials, and initial resource allocations.
  3. Configure Features and Quotas: Enable appropriate features and set resource limits based on the SI's licensing agreement.
  4. Establish Monitoring: Configure activity dashboards and quota alert thresholds for operational visibility.
  5. Enable Self-Service: Allow SI administrators to provision and manage tenants within their allocated quotas.

Last Reviewed: 2026-02-05 Last Updated: 2026-04-14

Ready to Build?

Get started with our APIs or contact our integration team for support.