Multitenancy in watsonx Assistant for Z
This section describes the multitenancy pattern, the onboarding models it supports, and the benefits of using this approach.
Why multitenancy is required
Multitenancy in watsonx Assistant for Z is based on the multitenancy capabilities provided by IBM Software Hub and watsonx Orchestrate. For detailed information about multi-tenancy, see Multitenancy support in the IBM Software Hub documentation.
- Logical isolation
- Strong security boundaries
- Independent governance
- Managed Service Provider (MSP) Model
-
- Each tenant represents a different external customer.
- Ensures strict isolation and independent configuration per customer.
- Enterprise Model
-
- Each tenant represents an internal unit such as department or region.
- Enables internal governance and operational independence.
Multitenancy workflow
Implementing multitenancy involves three key stages, each with specific roles and responsibilities.
- Tenant onboarding - During onboarding, you establish the foundation for tenant isolation and
access control.As a CPD Administrator, you can:
- Create tenants by provisioning watsonx Orchestrate service instances
- Add users to each tenant
Add users only if necessary; otherwise, users will be authenticated through the configured SSO.
- Assign appropriate roles (User or Admin) to control access and permissions
For detailed instructions on creating tenants and adding users, see Create a tenant and add users to it.
- Platform setup - During platform setup, agents are deployed and associated with the appropriate
tenant environments.As an Operator, you can:
- Deploy agents to the platform
- Configure agent deployments using tenant-specific identifiers (tenant ID and namespace)
For detailed instructions on deploying agents, see Deploy agents.
- Runtime management - During runtime, tenants can use and manage the agents that are available to
them.As a tenant-level administrator, you can:
- View available tenants and deployed agent
- Subscribe or unsubscribe agents to tenants, based on your assigned role and permissions
For detailed instructions on subscribing to agents, see Subscribe to agents.
To learn more about the roles that can view and subscribe tenants, see Role-based access for tenant creation and agent subscription.
Role-based access for tenant creation and agent subscription
In the IBM WXA4Z Management Console, a user’s ability to view and subscribe to agents depends on their CPD role and watsonx Orchestrate (tenant) role.
| Cloud Pak for Data (CPD) role | watsonx Orchestrate instance (tenant) role | View tenants | Subscribe to agents |
|---|---|---|---|
| CPD User | User | ✓ | |
| CPD User | Admin | ✓ | ✓ |
| CPD Admin | User | ✓ | ✓ |
| CPD Admin | Admin | ✓ | ✓ |
Managing tenants
To manage tenants in the IBM watsonx Assistant for z management console, create tenants and add users, then subscribe agents to those tenants. You can unsubscribe agents when they are no longer needed.
Complete the following steps to manage your tenants: