Back to case studies // zero-trust

Franchise Tenant Isolation

A luxury brand operating through independent franchise partners gave each franchisee a fully isolated identity tenant, so partner staff and client data never cross boundaries while the brand keeps central governance.

June 9, 2025 · Veripass
Franchise Tenant Isolation

This luxury brand expanded through independent franchise partners — separate legal entities that operate boutiques under the brand’s name in different regions. Each franchisee runs its own staff, manages its own clientele, and is contractually a distinct business. Yet they all touch shared brand systems: the product catalog, the clienteling platform, brand training. The brand needed each partner walled off from every other, while retaining central oversight of the standards they all run on.

The requirement was strict isolation between partners with central governance above them — a multi-tenant problem at its core.

The challenge

Franchise relationships make data boundaries a legal obligation, not just good practice. One franchisee’s client list, staff roster, and sales data must never be visible to another — they are competitors operating under a shared brand. At the same time, the brand cannot abdicate control: it sets who may access shared systems, enforces security standards, and must be able to audit every partner uniformly.

A single shared directory would have leaked partners into each other. Fully separate systems per franchisee would have made central governance impossible. The brand needed both isolation and a common control plane.

What Veripass deployed

Veripass modeled each franchise partner as its own tenant. Every tenant is a hard isolation boundary: a franchisee’s members, client data, policies, and audit history live entirely within it and never cross into another. Shared applications — catalog, clienteling, training — were registered once on the platform and then granted into the specific tenants entitled to them, so partners used the same brand systems without ever seeing each other’s data.

Each franchisee kept its own directory: partners on Microsoft Entra ID or Google Workspace federated over OIDC, while smaller partners used Veripass-local identities, all under the brand’s tenant. Above the tenants, the brand operated a governance layer setting baseline policy — required MFA, allowed applications, audit standards — that every partner inherited.

  • Per-franchisee multi-tenant isolation of members, data, and audit
  • OIDC federation to each partner’s Entra ID or Google Workspace
  • Shared brand applications granted per tenant, never globally exposed
  • Context-aware, policy-based access enforcing tenant boundaries
  • RBAC via claims, capabilities, roles, and access profiles per tenant
  • Adaptive, step-up MFA over email and phone TOTP as a brand baseline
  • API keys for tenant-scoped machine-to-machine integrations
  • Immutable per-tenant audit trail with brand-level oversight

Context-aware policy enforced the boundary on every request: a partner’s session could only resolve to its own tenant’s data, with no path to cross over. RBAC stayed local to each tenant, while the brand’s baseline — mandatory MFA and audit standards — applied everywhere. Each tenant carried its own immutable audit trail that the brand could review uniformly.

Outcome

Each franchise partner now operates in a sealed tenant: client lists, staff, and sales data are structurally invisible to every other partner, satisfying the contractual confidentiality the franchise model demands. The brand kept what it could not give up — central policy, uniform security standards, and consistent audit across all partners.

The brand scaled its franchise network without scaling its risk: new partners onboard as new isolated tenants under the same governed control plane, with isolation and oversight built into the model rather than bolted on per deal.

More deployments

IoT & Smart-Lock Integration

IoT & Smart-Lock Integration

A facilities operator brought thousands of smart locks and IoT controllers under one identity-governed access fabric, so every door event was attributable to a verified person or device.

Wealth Advisor Privileged Access

Wealth Advisor Privileged Access

A wealth-management firm locked down advisor access to client portfolios with context-aware policy and biometric step-up, ensuring privileged actions required proof of identity, not just a valid session.

Affiliated Hospital Federation

Affiliated Hospital Federation

A network of affiliated hospitals federated identity across independent facilities, so rotating clinicians worked at any site under one identity while each hospital kept its own directory and audit boundary.