Offers
Keycloak & multi-tenant access
Model tenants, SSO and permissions properly — instead of grown edge cases in every application.
“Every customer needs its own permissions — and every exception ends up in code.”
- Format
- 4–8 weeks, fixed-price frame after discovery
- Who it is for
- SaaS and product teams with multiple tenants, organisations with fragmented user management
Typical symptoms
- Every application has its own permission checks — one change needs five deployments.
- Tenant isolation lives in application logic instead of the token and the data model.
- Onboarding a new customer is manual back-office work instead of self-service.
- Nobody can reliably answer who has access to what today.
- Keycloak is running, but realms, clients and roles have grown organically and nobody touches them.
Outcome
- Role, permission and tenant model, documented and implemented
- Keycloak setup or remediation incl. realms, clients, token design
- Self-service admin UI for user and permission management
- Migration of existing users without a big bang
- Handover to operations: runbook, monitoring, rotation and recovery paths
How we work
01
Discovery (1–2 weeks)
We map user groups, tenants, systems and edge cases. The result is a target model with a migration path and an effort range.
02
Model & token design
Roles, permissions and tenants are modelled explicitly: what belongs in the token, what in policy, what in the domain. Decisions are captured as ADRs.
03
Implementation & migration
Keycloak setup or remediation, application integration, a self-service admin UI and incremental migration of existing users — no big-bang weekend.
04
Operations & anchoring
Runbook, monitoring, rotation and recovery paths, plus onboarding of your internal team. Afterwards you can continue without us.
Frequently asked
- Why Keycloak?
- Because identity and access are not something you should hand over. You keep control of users, roles and audit events instead of moving them into a third-party service whose pricing, data location and exit risk you do not steer. And because it can be customised deeply enough to model your real tenant structure, not just a standard variant of it.
- Does it have to be Keycloak?
- No. Keycloak is our default because it is open source, self-hostable and operable inside the EU. If your landscape fits Entra ID, Auth0 or Ory better, we say so during discovery.
- We already run Keycloak, but it is a mess.
- That is the most common case. We remediate existing realms, clients and role models step by step instead of rebuilding, with clear intermediate states.
- How does migrating existing users work?
- Incrementally: accounts are moved over in stages, password hashes migrated or renewed via a reset flow. Parallel operation is the norm, not a cut-off date.
- What does it cost?
- After discovery you get a fixed-price frame. Discovery itself is kept small and is credited when you continue.
Often combined with
Background in the article Multi-tenancy with Keycloak: what belongs in the token.