
// Escape the Subscription
Security Baselines Applied Across Every Tenant From One Place
An organization securing many separate cloud tenants
The story in briefKeeping dozens of separate cloud tenants on the same security standard usually means a per-tenant subscription tool, or a technician clicking through the same settings by hand. We built an owned platform that applies a versioned baseline everywhere, shows exactly what will change before it changes, watches for drift afterwards, and produces the evidence an auditor asks for.
The situation
The organization was responsible for security and compliance across a large number of separate cloud tenants. Each one needed the same protective settings, the same policy objects, and the same ability to answer a simple question: is this environment actually configured the way we say it is?
Why the usual options fell short
There were two conventional paths and neither held up. Configuring each tenant by hand does not scale, and it guarantees the environments drift apart over time. The alternative is a management subscription priced per tenant, which grows into a permanent bill that rises with the business and still leaves the underlying evidence in someone else’s product.
What we built
An owned platform that applies versioned security and compliance baselines across every tenant from a single place. An operator selects the tenants and the baseline, previews exactly what will change, and applies it. Tenant-specific values are substituted automatically, every step reports its own success or failure instead of half-applying quietly, and changes can be rolled back. Afterwards the platform monitors for drift and produces evidence mapped to the relevant framework.
The part they didn’t expect
That the evidence would become as valuable as the enforcement. Being able to show what was applied, when, and to which environment turned an anxious scramble before an audit into a report generated from the system itself.
The payoff
- One versioned baseline applied consistently across every tenant.
- Changes previewed before they run, with rollback available.
- Drift surfaced automatically instead of discovered during an audit.
- Audit-ready evidence produced by the platform rather than assembled by hand.
- An owned system in place of a per-tenant subscription.
// is this you?
If this sounds like a problem you recognize — even if you never pictured building your own answer to it — that is usually the sign. Describe your version and a senior engineer will tell you plainly whether it is the kind of thing we build.
Start a project// common questions
Questions about this kind of build
What problem does this actually solve?
Consistency at scale. When each tenant is configured by hand, they drift apart, and nobody can prove what state any of them is in. A baseline applied from one place keeps them the same, and the platform records what was applied so the answer is evidence rather than memory.
Is it safe to apply changes across many tenants at once?
That was the central design concern. Every run is previewed before it executes, tenant-specific values are substituted automatically, and each step reports success or failure rather than partially applying in silence. Changes can be rolled back.
What happens after the baseline is applied?
The platform keeps watching. Settings that drift away from the standard are surfaced, so a tenant that quietly falls out of line is caught rather than discovered during an audit.
Could this work for our environment?
If you run multiple separate tenants or environments that all have to meet the same standard, the pattern transfers. The specifics of which controls matter are worked out per engagement.
// next step
Have a system in mind?
Describe what you are trying to build or fix. A senior engineer reviews every inquiry and responds directly, with a technical read on the problem.