Multitenancy in watsonx Assistant for Z

This section describes the multitenancy pattern, the onboarding models it supports, and the benefits of using this approach.

Note: For multitenancy, users need to use a custom user interface. This interface allows each tenant to configure its own Identity Provider (IDP) so that users authenticate within their organization. After authentication, the system routes users to the embedded chat interface, ensuring secure access and clear tenant isolation.

Why multitenancy is required

Multitenancy in watsonx Assistant for Z is based on the multitenancy capabilities provided by IBM Software Hub and watsonx Orchestrate. For detailed information about multi-tenancy, see Multitenancy support in the IBM Software Hub documentation.

Multitenancy enables multiple independent environments (tenants) to operate within a shared infrastructure while maintaining:
  • Logical isolation
  • Strong security boundaries
  • Independent governance
Onboarding models
To use these models, you need to create a watsonx Orchestrate tenant instance and add users.
Managed Service Provider (MSP) Model
  • Each tenant represents a different external customer.
  • Ensures strict isolation and independent configuration per customer.
Enterprise Model
  • Each tenant represents an internal unit such as department or region.
  • Enables internal governance and operational independence.

Multitenancy workflow

Implementing multitenancy involves three key stages, each with specific roles and responsibilities.

  • Tenant onboarding - During onboarding, you establish the foundation for tenant isolation and access control.
    As a CPD Administrator, you can:
    • Create tenants by provisioning watsonx Orchestrate service instances
    • Add users to each tenant

      Add users only if necessary; otherwise, users will be authenticated through the configured SSO.

    • Assign appropriate roles (User or Admin) to control access and permissions

    For detailed instructions on creating tenants and adding users, see Create a tenant and add users to it.

  • Platform setup - During platform setup, agents are deployed and associated with the appropriate tenant environments.
    As an Operator, you can:
    • Deploy agents to the platform
    • Configure agent deployments using tenant-specific identifiers (tenant ID and namespace)

    For detailed instructions on deploying agents, see Deploy agents.

  • Runtime management - During runtime, tenants can use and manage the agents that are available to them.
    As a tenant-level administrator, you can:
    • View available tenants and deployed agent
    • Subscribe or unsubscribe agents to tenants, based on your assigned role and permissions

    For detailed instructions on subscribing to agents, see Subscribe to agents.

To learn more about the roles that can view and subscribe tenants, see Role-based access for tenant creation and agent subscription.

Role-based access for tenant creation and agent subscription

In the IBM WXA4Z Management Console, a user’s ability to view and subscribe to agents depends on their CPD role and watsonx Orchestrate (tenant) role.

The following table shows the role-based access required to view tenants and subscribe to agents for a tenant.
Cloud Pak for Data (CPD) role watsonx Orchestrate instance (tenant) role View tenants Subscribe to agents
CPD User User  
CPD User Admin
CPD Admin User
CPD Admin Admin

Managing tenants

To manage tenants in the IBM watsonx Assistant for z management console, create tenants and add users, then subscribe agents to those tenants. You can unsubscribe agents when they are no longer needed.

Complete the following steps to manage your tenants: