SigmaEra for MSP & Portfolio
You run this for a dozen companies, not one.
Spanning organizations is normally where multi-tenant products quietly weaken isolation. SigmaEra does it the other way: parent tenants hold consented, derived artifacts about their children, and there is no privileged credential anywhere that reads across them.
You run this for a dozen companies, not one.
The arc an MSP, holdco, or portfolio operator walks with SigmaEra: how spanning organizations works here, and why it does not weaken the isolation your clients are buying.
- 1The structural problem
Every tool makes you choose
Either you get one login per client and no portfolio view, or you get a portfolio view built on a superuser account that can read everything — which is exactly the thing your clients would refuse if they understood it.
What you have to answer
- How does cross-organization visibility actually work here?
- Is there a privileged account that spans clients?
- What would a client’s security team say about it?
The layer that answers it
Per-person spanning reads
The parent view holds no credential that reads children. There is no service-side spanning read path: every cross-organization read resolves through the requesting person’s own membership and scope grants in each child, at read time.
What changes for you
You get portfolio visibility built so that the thing your clients fear is structurally absent rather than merely policy-forbidden.
- 2Onboarding a client
Consent that is real and revocable
A new client joins the portfolio. They will want to know exactly what you can see, and to be able to withdraw it later without a support ticket and a leap of faith.
What you have to answer
- What exactly does the parent hold about a child?
- How is consent granted, and by whom?
- What happens the moment it is revoked?
The layer that answers it
A consent state machine
Each parent-child link is a first-class, consented, auditable grant with defined revocation semantics that fail closed to stubs, and a purge cascade that reaches parent-held artifacts when a child is deleted.
What changes for you
You can offer a client a portfolio arrangement they can actually verify and exit, which is what makes it sellable to their security team.
- 3Portfolio review
Comparing engagements without pooling them
You want to know which engagements are drifting and which are quietly working. What you must not do is create a place where every client’s content sits together.
What you have to answer
- Where do portfolio artifacts physically live?
- Is any client content copied into a shared store?
- How is a rollup constructed?
The layer that answers it
One artifact-homing rule
Portfolio rollups and link edges are homed in the parent tenant’s own rows, referencing children by opaque identifier plus a bounded display snapshot, under a single homing rule everything follows rather than a special case per report.
What changes for you
You get comparative intelligence across the estate while each client’s corpus stays inside its own boundary.
- 4Scaling the practice
Twelve clients becomes forty
What worked as a manual arrangement for a handful of clients has to become an operating model — including the parts your own team should not be able to do.
What you have to answer
- Does the model hold as client count grows?
- What is audited about my own team’s access?
- Can I evidence this to a prospective client?
The layer that answers it
Audited by construction
Cross-tenant administrative actions require a reason string and are audited, link state changes are recorded, and the whole model is documented publicly in the platform security white paper for a client’s own reviewers to read.
What changes for you
The arrangement scales without becoming a trust exercise, and you can hand a prospective client the document rather than your assurance.
Control register
Every layer above is documented there in full, including the threat model and the control-status register.
Beneath the controls, the platform itself.
The five capabilities every SigmaEra deployment runs, read through the lens of this role.
Five stages · Protect → Emerge- 01
Protect
No service-side spanning read path exists. Every cross-organization read resolves through the requesting person’s own membership in each child, at read time.
- 02
Orchestrate
A consent state machine governs each parent-child link, with defined revocation semantics and a purge cascade that reaches parent-held artifacts.
- 03
Automate
Portfolio rollups are homed in the parent tenant under one artifact-homing rule that everything follows, rather than a special case per report.
- 04
Compound
Patterns become visible across the portfolio that no single company could see on its own — while each company’s content stays inside its own boundary.
- 05
Emerge
Comparative intelligence surfaces across the estate you operate: which engagements are drifting, and which are quietly working.
The Compound Effect
Intelligence that builds on itself.
- 100%
- of AI interactions governed — every call through one policy enforcement point, with a full audit trail. Source: Platform security white paper — Governance & AI policy
- 8
- must-follow platform standards, each with a named enforcement gate in CI — control coverage mapped to SOC 2, GDPR and HIPAA expectations. Source: Platform security white paper — Standards alignment
- 1
- company-specific model — your corporate knowledge compounds into a private intelligence layer that gets smarter every week. Source: Platform security white paper — Model processing & training
Stop leaking data. Start compounding intelligence.
See the Cross-Organization Model
- Runs air-gapped inside your own boundary
- Full audit trail on every interaction
- 100 agents, one control plane




