Skip to content

Workspaces & tenancy

Gamut is multi-tenant. Each organisation operates in its own tenant, an isolated environment whose AI systems, assessments, evidence and users are kept separate from every other organisation. Inside a tenant, each assessment acts as a workspace that work and membership attach to.

Tenant isolation is a deliberate security property, enforced at the data layer rather than by application filtering alone: each tenant’s records live in their own normalised database schema. Your governance records, evidence and users are never visible to another organisation, and access is always scoped to the tenant you belong to. See Security & data handling.

Within a tenant, membership and roles can be scoped to an individual assessment. A user carries a tenant role for what they can do organisation-wide, and an additive workspace role, Lead Assessor, Contributor, Reviewer or Viewer, on the specific assessments they are added to. This is how you give someone broad read access but write access only where they actually work.

The Runtime Policy Approver role is also workspace-scoped. It reveals submitted Runtime Access Policies only for assigned workspaces and does not grant general editing authority.

Locking a workspace in View only mode preserves its governance record for inspection while blocking changes. Existing Runtime Access Policies can still be opened and reviewed, including their boundaries and history. Policy drafting, editing and lifecycle actions remain unavailable until the workspace is deliberately unlocked by an authorised user.

Some people work across more than one organisation or environment, for example advisers and auditors. Where that applies, a user can belong to multiple tenants and switch between them, always acting within the one currently selected and never carrying data across the boundary.

A tenant has a status that controls access. An active tenant operates normally; a suspended tenant is locked out entirely until reactivated. Provisioning, suspension and reactivation are audited account lifecycle actions.