Introducing Multi-Tenancy in OpenAEV: One Platform, Many Tenants
TL;DR
- OpenAEV now supports Multi-Tenancy: one deployment, multiple fully isolated tenants, centralized control.
- Built for enterprises and MSSPs running validation across business units, subsidiaries, or client environments that can’t share data.
- Each tenant gets its own configuration, scenarios, and results – no data crosses tenant boundaries, simplifying compliance in regulated industries.
- Central teams can deploy scenarios across all tenants simultaneously and reporting can be scoped per environment.
Scaling OpenAEV and the XTM Platform
Running security validation across multiple teams, clients, or business units just got a lot simpler.
OpenAEV is Filigran’s adversary emulation and validation platform, part of the open-source XTM Platform alongside OpenCTI. It gives security teams the tools to run Breach and Attack Simulations, Tabletop Exercises, and intelligence-driven scenarios to validate real coverage against realistic threats and tactics, techniques, and procedures (TTPs).
Until now, doing so across multiple environments meant managing multiple instances. Multi-Tenancy changes that: one deployment, fully isolated tenant organizations, centralized control.
With Multi-Tenancy, OpenAEV’s full set of capabilities can now be deployed at enterprise and managed service scale.
Why Multi-Tenancy?
Because SecOps don’t work in silos.
As OpenAEV adoption grew across large enterprises and managed security providers, a structural gap became clear: organizations running validation programs across multiple business units, subsidiaries, or client environments needed a way to do that from a single deployment while keeping each environment cleanly separated.
Multi-Tenancy addresses this directly. A single OpenAEV instance can now host multiple isolated tenant organizations, each with its own configuration, its own scenarios, its own chatbox, and its own results. A platform administrator manages the overall deployment and retains centralized visibility, while tenant administrators operate independently within their own scope. No data crosses tenant boundaries by design.

For organizations in regulated industries, this also means strict data segregation is enforced at the platform level, which simplifies compliance rather than adding to it.
A Scenario in Practice
Picture this:
A managed security provider is supporting a financial services client and a healthcare client simultaneously. Both operate in heavily regulated environments and both have asked for validation against the same threat actor group that has been active across sectors in recent months.
The MSSP’s central team identifies the relevant TTPs from the Threat Arsenal, packages them into a scenario, and deploys it to both client tenants from the same OpenAEV instance. Each client’s agents run the simulation against their own infrastructure.
Now here’s the catch: The financial services client’s EDR catches the lateral movement technique; the healthcare client’s does not.
So the MSSP generates separate validation reports for each, scoped entirely to their respective environments, and brings the healthcare client a concrete remediation recommendation backed by evidence from their own infrastructure.
None of that data touched the other tenant. The MSSP’s team ran the whole operation from one platform, with one set of credentials, and one administrative interface.

What This Unlocks for Different Teams
For large enterprises, Multi-Tenancy means a global security team can now run a consolidated validation program while giving each regional team or business unit its own operational space. The CISO gets a unified view of coverage across the organization. Each local team works within its own environment without interference.
For MSSPs, it means being able to onboard and manage client validation environments from a single platform deployment, with each client fully isolated and independently configurable. Scenarios from the Threat Arsenal can be deployed across clients simultaneously when a new threat emerges, and reporting stays cleanly scoped per client.
For internal red or purple teams supporting multiple product lines or geographies, it means running parallel programs without cross-contamination, with results that are independently reportable and comparable.
What’s Next
Multi-Tenancy is part of a broader set of enterprise capabilities coming to OpenAEV.
If you want to see what else is on the horizon, the XTM Platform public roadmap is available at hub.filigran.io. It’s updated regularly and reflects the community feedback that has always shaped how Filigran builds.
As aways, feel free to ask any questions about it on our Slack community channel !
Read more
Explore related topics and insights