← Back to Workspace Journal

July 17, 2026 · 3 min read

Domain-locked workspaces: the simplest tenancy model that works

Anchoring an organisation to its email domain keeps the wrong people out without an IT project.

Multi-tenant access control usually arrives as a project: an identity provider, a directory sync, a ticket in somebody's queue, and a six-week wait.

Domain locking gets most of the benefit on day one. The first person to sign up from a corporate email domain becomes the administrator for that organisation. Everyone who signs up afterwards from the same domain arrives pending, and the administrator approves or rejects them.

Free email providers cannot anchor an organisation. Without that rule, anyone with a mailbox could claim a tenant, and the model collapses.

The approval queue is the part people underestimate. It gives you a single, dated list of who asked for access and who granted it, which is the same shape of evidence an access review expects.

Domain locking is not a replacement for SSO. It is what carries you until SSO is worth the project, and it fails closed while you wait.

Keep reading