CrossTenant
Governed Google Workspace operations for MSPs

Every Google Workspace customer.
One governed console.

Live security posture, lifecycle, devices, mail controls, approvals, and client-ready evidence across your whole book, without warehousing Workspace content. Built for operations, not account switching.

Prefer email? Get in touch and we run onboarding with you.

Works with Google Workspace

One console across the Google surface you already run

Directory, OUs
& devices
Mail
governance
Drive &
shared drives
Calendars &
resources
Gemini policy
oversight

The operating model

The whole customer book.
With control built in.

CrossTenant brings Google Workspace posture, users, devices, mail controls, approvals, and client-ready evidence into one cross-tenant workflow. CIPP showed why MSPs value whole-book operations on Microsoft 365; CrossTenant applies that operating model to Google Workspace, with Google-specific controls and data boundaries.

CIPP is an independent CyberDrain project for Microsoft 365, named here only as the model MSPs already know. CrossTenant is a separate product, built natively for Google Workspace.

Why now

Admin tooling grew one tab at a time.
CrossTenant was designed whole.

A console per domain, a script to bridge two of them, a spreadsheet to remember the rest. Every layer made sense when it was added, and the pile never became a system. Cross-tenant management is where this tooling is heading; CrossTenant simply starts there.

A browser tab per customer
One scope picker: all tenants, a group, or one
Scripts, CSVs and tribal knowledge
Live, structured cross-tenant pages
Spot checks when there's time
Whole-book security posture, benchmarked worst-first

AI, governed

AI that reads the whole fleet.
And never acts alone.

The assistant sees what you see (posture, drift, alerts, across every customer) and turns it into answers, summaries, and drafted fixes. Every proposal passes the same permission checks as a human action, dry-runs first, and executes only when you confirm.

  • Proposer, not actor. The assistant drafts; only an operator can run.
  • Redacted by design. Mailbox and file contents are stripped before anything reaches the model.
  • Your kill-switch. Off until you enable it, tightened per action or per engineer, never loosened downstream.

How AI governance works

Co-managed IT

Your customers get a portal too

Give a customer's IT lead a login of their own: scoped to their tenant only, read-only or hands-on per area, under their branding. They get a console that feels like theirs; you keep the master view and the audit trail.

How customer seats work

Trust

Secure by architecture

The controls your security team already expects (least privilege, isolation, auditability), applied to every customer tenant.

No customer data at rest

Every page is a live Google API read, rendered and discarded. No database, no cache of customer content.

Per-tenant isolation

Credentials, tokens, and audit logs are isolated per customer. One tenant's authorisation never reaches another's data.

Least-privilege scopes

Read-only customers receive only read-only OAuth scopes at Google consent. Domain-wide delegation is separately customer-approved and its current grant may include write-capable scopes. The console requests scopes per operation and refuses mutations for read-only customers.

Tamper-evident audit

Every write sits behind explicit confirmation and lands in a hash-chained, per-tenant audit log.

Read the security architecture  ·  Privacy policy

Priced for MSPs: per tenant, not per seat

Per-user pricing is built for a single organisation; you run a fleet. CrossTenant is priced per customer tenant you manage, in two tiers.

Core

Fast onboarding · no extra Google review

  • Cross-tenant directory & user lifecycle
  • Device & ChromeOS management
  • Security posture & customer health
  • Reports, schedules & alerts
  • Customer portal seats & role-based access

Pricing is quoted per managed customer tenant. Get in touch for a quote. There's a free tier for managing your own Workspace tenant while you evaluate.

Get started

Once you're in, your first tenant is live in minutes

We onboard you directly and run the first guided consent with you, against a tenant you choose. No agents to deploy, nothing to install in your customers' tenants.

01

Connect a customer

A guided consent flow shows exactly which permissions are requested and why, in plain language. Read-only mode if that's all a customer wants.

02

See the whole book

Health grades, posture, and alerts across every customer from the first screen: worst-first, so the tenant that needs you today finds you.

03

Fix from one place

Bulk actions run with dry-run previews and explicit confirmations, and land in a tamper-evident per-customer audit log.

Guided onboarding · free tier for your own Workspace tenant · toby@crosstenant.com