Frequently asked questions
The questions MSPs actually ask before connecting a customer tenant, answered plainly: what is stored, what access is requested, and what is honestly not built yet.
Questions and answers
What does CrossTenant store?
Every screen is a live fetch from Google's APIs, rendered and discarded: there is no database of your customers' Workspace content, and the console reads settings and metadata, never the contents of messages or files. What it does keep is small and operational: per-tenant authorisation tokens, your own configuration (roles, schedules, alert rules, approvals), tamper-evident audit metadata about the writes your team performs, and encrypted derived health metrics, the one disclosed exception, pruned automatically. The full inventory, including retention, is in the privacy policy.
What access does it request?
Onboarding ends in a pre-consent trust screen listing every OAuth scope the next consent will request, each tagged read or write, with plain language on what the operator could do with it: nothing is granted until your customer's super admin approves in Google's own consent window. Domain-wide delegation is a separate, customer-approved grant made in the customer's own Admin console, never part of that OAuth consent. See security posture for what the reads power, and the security statement for the formal write-up.
Can a customer start read-only?
Yes, and it is the default at onboarding: mutations against a read-only tenant are refused server-side, by the API itself, not by hiding buttons. A read-only consent plan requests read-only OAuth scopes at consent, and the server-side refusal also covers operations that ride the separate domain-wide delegation grant described above. Moving a tenant to write access later is a deliberate configuration change by you, the MSP, not a toggle your customer can flip: the enforcement model is described under cross-tenant management.
How do I get started?
Book a demo and we run onboarding with you. New MSPs start with guided onboarding rather than self-service signup, and the first consent happens together against a tenant you choose. There is a free tier for managing your own Workspace tenant while you evaluate. Start at how onboarding works, or write to toby@crosstenant.com directly.
What does it cost?
Pricing is per customer tenant, not per seat, across two tiers: Core and Complete. We quote for the size of your book rather than publishing a rate card. The tier breakdown is under pricing.
How does CrossTenant compare with GAT+?
GAT Labs' GAT+ is the established Google Workspace suite, and it goes deeper inside content than we do: message and file search, DLP, and browser-level controls. CrossTenant is built for the MSP shape instead, with every customer tenant on one screen, pricing per tenant rather than per user, and writes behind previews with an included second-approver gate. The side by side, including what GAT Labs covers that we do not, is on CrossTenant vs GAT+.
Does the AI see my customers' data?
The assistant is optional and ships switched off: nothing reaches a model until you enable it for your own deployment. When it is on, mailbox and file contents are redacted before any model call, so only sanitised configuration and posture context is ever sent. The assistant can propose an action but never perform one: an operator confirms every execution through the existing gated path. The guardrails are detailed on the AI assistant page.
Is there an SLA?
No: there is no contractual uptime commitment, and we do not pretend otherwise. What exists instead are first-response targets by severity, honest targets rather than contractual service levels, on the support page. CrossTenant is built and supported by a small team in the United Kingdom, and you should weigh that honestly alongside everything else.
Is CrossTenant certified?
No: we hold no ISO 27001 certification, no SOC 2 report, and no Cyber Essentials certificate. The posture scoring inside the product is assessment evidence about your customers' tenants: CrossTenant is not a certification body, and a passing score is not a Cyber Essentials certificate. Our own security posture, including what is deliberately not yet built, is written up on the trust & security page.
Who is behind CrossTenant?
CrossTenant Ltd, a company registered in England & Wales (company no. 17349672), operating from the United Kingdom. The background is on the about page, and every address that reaches a person is on the contact page.
If the answer you need is not here, ask: the contact page lists an address for every kind of question, and security questionnaires are welcome; the trust & security page covers how they are handled.
Questions
The fastest answer is a walkthrough
Book a demo and test the answers against your own tenant first: guided consent, read-only by default, and a person on the other end.