Offers

Keycloak & multi-tenant access

Model tenants, SSO and permissions properly — instead of grown edge cases in every application.

“Every customer needs its own permissions — and every exception ends up in code.”

Format
4–8 weeks, fixed-price frame after discovery
Who it is for
SaaS and product teams with multiple tenants, organisations with fragmented user management

Typical symptoms

  • Every application has its own permission checks — one change needs five deployments.
  • Tenant isolation lives in application logic instead of the token and the data model.
  • Onboarding a new customer is manual back-office work instead of self-service.
  • Nobody can reliably answer who has access to what today.
  • Keycloak is running, but realms, clients and roles have grown organically and nobody touches them.

Outcome

  • Role, permission and tenant model, documented and implemented
  • Keycloak setup or remediation incl. realms, clients, token design
  • Self-service admin UI for user and permission management
  • Migration of existing users without a big bang
  • Handover to operations: runbook, monitoring, rotation and recovery paths

How we work

  1. 01

    Discovery (1–2 weeks)

    We map user groups, tenants, systems and edge cases. The result is a target model with a migration path and an effort range.

  2. 02

    Model & token design

    Roles, permissions and tenants are modelled explicitly: what belongs in the token, what in policy, what in the domain. Decisions are captured as ADRs.

  3. 03

    Implementation & migration

    Keycloak setup or remediation, application integration, a self-service admin UI and incremental migration of existing users — no big-bang weekend.

  4. 04

    Operations & anchoring

    Runbook, monitoring, rotation and recovery paths, plus onboarding of your internal team. Afterwards you can continue without us.

Frequently asked

Why Keycloak?
Because identity and access are not something you should hand over. You keep control of users, roles and audit events instead of moving them into a third-party service whose pricing, data location and exit risk you do not steer. And because it can be customised deeply enough to model your real tenant structure, not just a standard variant of it.
Does it have to be Keycloak?
No. Keycloak is our default because it is open source, self-hostable and operable inside the EU. If your landscape fits Entra ID, Auth0 or Ory better, we say so during discovery.
We already run Keycloak, but it is a mess.
That is the most common case. We remediate existing realms, clients and role models step by step instead of rebuilding, with clear intermediate states.
How does migrating existing users work?
Incrementally: accounts are moved over in stages, password hashes migrated or renewed via a reset flow. Parallel operation is the norm, not a cut-off date.
What does it cost?
After discovery you get a fixed-price frame. Discovery itself is kept small and is credited when you continue.

Often combined with

Background in the article Multi-tenancy with Keycloak: what belongs in the token.