Run a whole book of customers, priced per tenant
How CrossTenant compares with GAT Labs' GAT+ for an MSP whose job is every customer at once: fleet-first pages, writes you can evidence, and no warehouse of customer content in the middle. What each product covers is set out below.
Prefer email? Get in touch and we run onboarding with you.
Why MSPs pick CrossTenant
The whole book is the default view
One scope picker moves every page between all customers, a tenant group, and a single customer. Every row carries the tenant it came from, and a write always routes back to the owning tenant behind a confirmation. The single-customer view is a zoom level, not the unit of work, so "how are all of my customers, worst first" is one screen rather than a morning of logins. The cross-tenant page shows the model in detail.
GAT Labs markets multi-tenancy too, with one dashboard across client domains and delegated auditors, so this is a difference of emphasis rather than a capability they lack: their centre of gravity is depth inside one domain, ours is altitude across many.
Priced per customer, not per seat
CrossTenant is priced per tenant, set per engagement during early access, with a free tier for managing your own Workspace tenant while you evaluate. Your cost tracks the number of customers you manage, not the number of people they hire, so a customer growing from twenty staff to sixty does not quietly eat the margin on that account. See pricing.
GAT Labs prices per user. As published at 2026-08-28, their tiers ran in euros at roughly €16 to €48 per user per year, with a per-domain annual minimum their pricing page states between €500 and €800. Those figures are theirs to state and they move: check their own pricing page on the day you decide. We will not compute a saving for you, because the two products are not feature-equivalent.
Every write shows you what it will do first
Bulk actions and configuration applies run a dry-run preview before anything changes, execute per tenant, and land in the audit log with a per-row result. Golden-config applies carry a change cap and read-before-write revert records. The offboarding run is a guided flow of up to thirteen ordered leaver steps with live per-step previews: the server re-sorts the steps into a safe order, mail steps before suspension, demands a typed confirmation of the leaver's address, and refuses your own break-glass admin. Deliberately not one click. See it in offboarding a leaver.
A second approver, included and optional
Elevated writes can be parked for a second person instead of executing: bulk actions, golden-config applies, critical single-row writes, and the whole offboarding run. The requester and the approver must be different people, the approver must already hold read access to every tenant and area the request touches, review happens against a fresh preview with a deterministic drift check so a stale request cannot be waved through, requests expire rather than queue forever, and an unreadable policy store fails closed instead of quietly ungating. The gate ships off: switching it on is your choice, per class of write. Details on the approvals page.
GAT Labs has approval controls too, sold as a separate product in their suite: GAT Unlock, which governs access to customer content. CrossTenant's gate is a different job, the writes your own team makes, and it is part of the console you already have.
Your customers' content stays in Google
There is no customer-content database. Every console view is a live fetch from Google's APIs, rendered and discarded. What the server does keep, the privacy policy names in full: authorisation tokens, operator configuration, audit metadata, delivered report PDFs, and an encrypted aggregates snapshot whose field vocabulary structurally cannot express person data. When a customer asks what your tooling holds about them, the answer is short and checkable.
GAT's model differs by design rather than by accident: deep Gmail and Drive content inspection is the feature. If content forensics is on your requirements list, that is a reason to choose them. If a third party holding searchable reach into customer content is the thing you would have to explain away, that is a reason to choose us.
No service-account key files to steal
Domain-wide delegation is a separate, customer-approved grant. Where CrossTenant uses it, it signs its delegation assertions through Google's IAM Credentials API rather than a downloaded service-account key file: keyless by default, with production refusing the legacy key path unless it is explicitly enabled. Each operation asks for the narrowest scopes it needs, and a tenant's delegated scopes can be narrowed further.
What you are granting is legible before you grant it. The pre-consent trust screen is generated from the live scope manifest: every scope the consent will request, tagged read or write, with plain-language copy, enforced by a test that fails the build when a scope has no description. A newly onboarded tenant starts in read-only mode, and the server blocks writes to it.
An audit trail you can hand to a client
Every write lands in a per-tenant trail of HMAC-SHA256 hash-chained entries, with a signed trail-ownership manifest so entries cannot be appended into the wrong customer's trail, and an on-demand verify that recomputes the chain. It fails closed: a trail that stops verifying blocks further production writes rather than carrying on silently.
We call that tamper-evident and deliberately not tamper-proof. Truncation of the most recent entries is not detectable, and shipping the chain off-box is future work rather than a shipped control. Our trust and security page says the same thing in writing.
Scores that admit what they could not check
A failed read renders as "not assessed" and is excluded from the security health score rather than inflating it. Controls aligned to CIS Google Workspace Foundations guidance degrade to "not checkable" where Google's APIs do not expose the setting, instead of inventing a verdict. An unreadable rule store pauses delivery rather than reading as all-clear. It is a smaller number on some tenants than a friendlier tool would show you, and it is the number you can defend in front of the customer. See security posture, and reports and alerts for the white-label PDFs that carry the evidence out.
Seats for your customers' own IT
Invite a customer's IT person into a scoped view of their own tenant: per-area access set to none, read, or full across eleven areas, MSP-internal surfaces absent rather than visible and denied, the tenant roster filtered so they never see your other customers, and your branding passed through so it presents as your portal. It is the same console scoped down, not a second product to learn or license. See the customer portal, or co-managed IT for how it works in practice.
Honest small print for the claims above: CrossTenant is in early access and holds no third-party certification. Assessments are aligned to CIS Google Workspace Foundations guidance, not certified by it, and a passing score is not a Cyber Essentials certificate. The approval gate is optional and ships off. Offboarding is a guided flow, not one click. The audit chain is tamper-evident, not tamper-proof.
What GAT Labs covers that we do not
GAT Labs ships a suite rather than a single console, so where a capability belongs to the wider platform rather than to GAT+ itself, we attribute it to GAT Labs. As at 2026-08-29 their site markets seven products: GAT+, GAT Shield, Shield+, GAT Flow, GAT Unlock, FlowHR and Email Signature Manager. Here is what those cover, why CrossTenant draws the line where it does, and what it does instead.
- Content search and investigation. Searching inside Gmail messages and Drive files. This one is a deliberate choice rather than a missing feature: CrossTenant reads settings and metadata only, so there is no index of your customers' content to search, and no copy of it to leak. That is what lets you tell a customer that nobody at CrossTenant can read their mail. If content investigation is a requirement, you want a product built for it.
- DLP and phishing remediation. Content-level detection needs content inspection, so the same choice applies. What CrossTenant does instead is govern the settings an attacker actually abuses: external auto-forwarding, unexpected delegates, stale send-as addresses and legacy protocol access, audited across every mailbox in every tenant. See auditing mailbox exposure.
- Browser-level controls. GAT Shield applies real-time Chrome DLP and Shield+ adds continuous identity verification. Enforcing inside the browser is endpoint tooling's job rather than a Workspace console's, so CrossTenant reads the managed Chrome browser and device fleet and acts through Workspace, rather than sitting in the browser itself. See device lifecycle.
- Scheduled and HR-driven lifecycle. GAT Flow builds reusable joiner, mover and leaver workflows, and FlowHR drives them from an HR source. CrossTenant now has both ends of the lifecycle, each a guided flow with live previews, a per-step record and the same confirmation as any other write. What GAT Flow adds is the automation around them: starting a joiner on a future date, and triggering it from an HR system rather than from an operator. CrossTenant currently keeps an operator in the loop for account creation and does not connect to an HR system. See offboarding a leaver.
- Email signature management. They sell a dedicated product for organisation-wide signatures. CrossTenant pushes a signature across a tenant as one of its fleet-wide mail actions, behind the same preview and confirmation as any other write, but without a dedicated template and branding product around it.
GAT+, GAT Labs, GAT Shield, Shield+, GAT Flow, GAT Unlock, FlowHR, Email Signature Manager and Graphs are marks of their respective owner, used here nominatively and for comparison only. CrossTenant is not affiliated with GAT Labs, and nothing on this page has been reviewed or endorsed by them. Every GAT Labs fact here was checked against GAT Labs' own published materials on 2026-08-28, and against third-party review sites on 2026-08-21; where a figure carries its own date, that is the date it was checked. Their products and prices move faster than our copy does. If anything here is out of date or wrong, tell us through the contact page and we will correct it.
Choosing between them
GAT+ is the better fit when the job reaches inside content: searching messages and files, DLP and phishing clean-up, or real-time controls in the browser. It also suits you if per-user licensing matches how you bill, and if you need joiners to start on a schedule or from an HR system rather than when an operator runs them.
CrossTenant is the better fit when the job is governing a book of customers: every tenant on one screen with per-tenant attribution, writes behind previews and confirmations with an optional second approver included, a tamper-evident per-tenant audit trail you can hand to a client, live reads rather than a content warehouse, and scoped seats for your customers' own IT, priced per tenant rather than per seat. The fastest way to judge it is a walkthrough against a tenant you choose.
CrossTenant vs GAT+
Governance across every customer you manage
Per-tenant pricing, writes you can preview and evidence, and no copy of your customers' content in the middle. There is a free tier for your own Workspace tenant while you evaluate.