SoxAIDocs
Guides

Multi-Tenant Setup

Deploy SoxAI for multiple organizations with complete data isolation

Multi-Tenant Setup

SoxAI is built for multi-tenant deployments from the ground up. Each tenant has fully isolated data, users, teams, quotas, and billing.

Tenant Architecture

Each tenant in SoxAI is a separate organizational unit with:

  • Independent user base
  • Separate API tokens
  • Isolated usage logs and billing
  • Custom quota policies
  • Optional custom domain and branding

Data isolation is enforced at two levels:

  1. Application layer — all queries include tenant_id filtering
  2. Database layer — PostgreSQL Row-Level Security policies as a safety net

Creating a Tenant

System administrators can create tenants in the Console under Admin → Tenants → Create Tenant:

FieldDescription
SlugURL identifier, e.g. acme → acme.soxai.io
NameDisplay name shown in the console
PlanSubscription tier (affects feature availability)
Max UsersMaximum number of user accounts
Max TeamsMaximum number of teams

Tenant-Specific Gateway Access

Each tenant accesses the gateway using their own API tokens. Tokens are scoped to the tenant — a token from Tenant A cannot access Tenant B's resources.

The gateway URL is shared across tenants:

https://api.soxai.io/v1

Tenant isolation is determined by the API token, not the URL.

Custom Domains

For white-label deployments, each tenant can have a custom domain:

api.acme.com → api.soxai.io
console.acme.com → console.soxai.io (with Acme branding)

Configure custom domains under Admin → Tenants → [Tenant] → Custom Domain.

See White-Label Deployment for full setup instructions.

Per-Tenant Quota Defaults

Administrators can set default quota policies that apply to all users in a tenant who do not have a more specific group or user policy.

Navigate to Admin → Tenants → [Tenant] → Quota Settings to configure:

  • Default hourly token limits
  • Default daily spending limit
  • Allowed models for all users in this tenant

Tenant-Level Billing

Each tenant has an independent balance. Tenant administrators top up their tenant's balance from the Console. When a user in the tenant makes API requests, the cost is deducted from the tenant balance.

Tenant administrators can view billing details under Billing → Overview within their tenant context.

Programmatic Tenant Management

System administrators can manage tenants via the Admin API:

# Create a tenant
curl https://api.soxai.io/api/admin/tenants \
  -H "Authorization: Bearer $ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "slug": "acme",
    "name": "Acme Corp",
    "plan": "pro",
    "max_users": 500
  }'