Tenant isolation
Your organisation. Your files. Never mixed.
Each organisation is its own workspace. People records, consent, money and files never leak to another team. Shared platform. Separated data. Country and partner partitions can be designed in. The organisation keeps the files — not the consultant’s laptop.

How it is built
Org-scoped by design
Organisation A never sees Organisation B. That is the product, not a policy slide.
Roles inside the tenant
Admin, Staff, Viewer — invited by email, inside your organisation only. Viewer is the donor-oversight seat.
Exit without lock-in
Residual capacity stays with the organisation after close-out. A new firm onboards onto your historical layer.
Your close-out should not be a project
The old way versus IMP
The usual tenancy
- A consultant holds the master workbook.
- A federation’s country offices share a drive they should not.
- When the contract ends, the structure is gone.
- IT is asked to ‘trust the vendor’s tenancy’ with no way to see it.
The IMP tenant
- Every customer organisation is a separate tenant at setup.
- Country or partner isolation can be designed into the workspace model (Country A cannot see Country B).
- Team roles — Admin, Staff, Viewer — inside your organisation only.
- The structure and files remain yours. No consultant lock-in.
What is actually in the product
Live workspace capability — not a roadmap dressed as a feature list. The ceiling is published on the same page as the capability.
In the workspace today
- Organisation tenant at setup — multi-tenant isolation
- Org-scoped people, consent, programmes, files and claims
- Team invites: Admin / Staff / Viewer
- Country / office partition patterns on multi-country engagements
- HQ roll-up discipline for authorised exports (multi-country configuration)
- Hosting options in scope design: shared cloud, regional, or sovereign-isolated
Honest ceiling
- Not a national government registry or ID system
- Not a cross-organisation data marketplace
- Sovereign isolated infrastructure is an engagement option — not the default shared cloud
Built to handle the messy reality
Tenant
Your organisation gets its own workspace. People, consent, money and files never leak.
People
Records and consent stay inside that tenant. Partners who need isolation get their own boundary.
Access
Admin runs the workspace. Staff write. Viewer is for donor oversight — a free-of-write seat, not a shared login.
Exit
The structure and files remain yours. Residual capacity is a checklist, not a hope.
What isolation looks like in practice
Organisation A never sees Organisation B. Country A need not see Country B. That is configuration plus product, not a memo.
- 01
Tenant
Your organisation gets its own workspace at setup.
- 02
People
Records and consent stay inside that tenant.
- 03
Access
Admin, Staff, Viewer — inside your organisation only.
- 04
Exit
The structure and files remain yours.
From fire drills to a live record
IT / data protection
From
Hoping the vendor’s tenancy is real
To
Org-scoped by design
Federation secretariat
From
One messy shared sheet
To
Shared platform, isolated members
Country office
From
Dependent on HQ’s consultant
To
Local residual capacity
Questions buyers actually ask
- Is this a national government registry?
- No. IMP is a multi-tenant workspace for programme organisations. It is not a national ID system or offline HMIS.
- Who owns the data?
- The organisation. Residual capacity is the point: when people leave, the files stay. A new implementer onboards onto the organisation’s layer — not theirs.
- Can Member Associations be isolated from each other?
- Yes. A tenant per Member Association or implementing unit is the federation pattern. Name countries, partners and isolation on the invoice request.
Explore more of IMP
The work stays when people leave
Don’t wait for the laptop to be on a plane. Brief the cycle the way you would brief a successor.
Already have the note? Tell us about this cycle — we price from that.