Hierarchical Identity Management for Multi-Tenant Application Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current applications face challenges in being easily configured for various use cases, such as single-tenant or multi-tenancy scenarios, without requiring rearchitecting or developing different versions, especially when hosted on-premises or in the cloud by SaaS or MSPs, leading to limited diverse offerings and increased development costs.
Innovation Solution
The implementation of a hierarchical identity management (IDM) model that leverages the IDM models of tenants, allowing the application to be configured for multiple use cases without rearchitecting, including hard and soft partitioning scenarios, enabling efficient management and access control across different tenants and providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If an application is configured for a specific usage scenario (single-tenant or multi-tenancy), then the application can be optimized for that scenario, but it requires rearchitecting or developing different versions for other scenarios
Solution Approach 1:
The application is designed with a universal configuration framework that enables it to function across multiple usage scenarios (single-tenant, multi-tenancy, SaaS, on-premises, MSP-managed) without requiring separate versions or rearchitecting. The system uses a hierarchical identity management model that can be configured through parameters to adapt to different deployment scenarios, making the application multi-functional and scenario-agnostic.
2Adaptability or versatility
If different versions of the application are developed for different usage scenarios, then each version can be optimized for its specific scenario, but development costs increase
Solution Approach 1:
The system enables different usage scenarios to be achieved by changing configuration parameters rather than developing different code versions. The hierarchical identity management model uses configurable parameters to adapt the application's behavior and structure to match different scenarios (single-tenant, multi-tenancy, SaaS, on-premises, MSP-managed), significantly reducing development resources while maintaining full adaptability.
3Adaptability or versatility
If the application supports multiple usage scenarios through a single configuration, then diverse offerings are enabled, but the configuration complexity increases
Solution Approach 1:
The configuration system is segmented into hierarchical layers (global configuration, tenant configuration, instance configuration) that can be independently managed. This segmentation allows complex multi-scenario support to be broken down into manageable configuration units, reducing overall configuration complexity while maintaining diverse scenario support through hierarchical composition.
Solution Approach 2:
A configuration intermediary layer is introduced that mediates between the application core and different usage scenario requirements. This intermediary handles the complexity of scenario-specific configurations by providing a standardized interface and translation layer, allowing the application to support diverse scenarios without exposing configuration complexity to users.
4Ease of operation
If separate management tools are used for each customer in MSP scenarios, then customer-specific requirements are met, but management efficiency decreases
Solution Approach 1:
The system merges multiple customer-specific management tools into a single unified application instance that can manage multiple tenants simultaneously. The hierarchical identity management model allows the MSP to access and manage different customer environments through one interface, combining the functionality of separate tools while maintaining customer-specific customization capabilities, thereby significantly improving management efficiency.
Data Source
AI summary
An application managed by a provider is configured to run according to a selected usage scenario of a group of usage scenarios. The group of usage scenarios include a hard-partitioned usage scenario in which instances of the application are hard partitioned in correspondence with tenants of the provider. The group of usage scenarios include a soft-partitioned usage scenario in which the instances of the application are soft partitioned in correspondence with the tenants of the provider. The configured application is executed.


