One tenant per client
Every client asks whether another client can see its data, what you did after an incident and what leaves with them when the contract ends. Each answer should come from how the platform is built, not from a promise in the contract.
Twenty clients should not mean twenty consoles.
Managed services lose margin to swivel-chair work: a separate console, login and report for each client, and licensing that was not built for many tenants.
Each new client should add work you can price, not another stack to run.
Separation you can show a client, not just promise.
ARRTECH gives each tenant its own users, data sources, policies, reports and alerts on one console.
Role-based rights limit each user to the sources they are granted, and the console records every login and search.
Onboard one client first. Move the rest when ready.
Start with one client on one console. Connections are tested before they are saved, so a new tenant starts from sources you know work.
The other clients move over when you are ready.
Tenants
How do we connect a new client’s directory, cloud accounts and odd log sources?
The credential vault stores each connection’s credentials and tests it before saving. The ARRTECH SIEM agent then collects over SSH, WMI, SQL, Kafka and Microsoft 365 without installing anything on those systems.
Who on your team can see our data?
Only the users you grant. Role-based rights limit each user to the log sources and features they are granted, and ARRTECH DLP also deploys multi-tenant for an MSSP. The console audit log records logins, searches and configuration changes.
What will the next client cost us to run?
ARRTECH SIEM needs no separate operating system or database license and scales by adding servers. Agents install and update from the console, centrally or on a schedule.
What will we receive from you each month?
Each tenant’s reports run on a schedule and arrive by email as PDF, DOC or XLSX. Dashboards can be shared, locked and exported as modules.
What leaves with us when the contract ends?
The record. ARRTECH SIEM exports any source with its signatures, certificate and a standalone verifier, so the client, its auditor or any third party can check it without your SIEM.
Who approved what was done for us?
ARRTECH DLP acts only on each tenant’s own policies. An ARRTECH SOAR Operator node emails a person up to five color-coded options and waits. Nothing below it runs until the reply arrives, and the history shows who chose which option and when.



