Every customer tenant.
One console.
The Google Workspace management console built for MSPs — your whole book of customers in one live view, with per-customer drill-down. Not a tab per Admin console. Not a domain switcher.
Works with Google Workspace
One console across the Google surface you already run
& devices Mail
governance Drive &
shared drives Calendars &
resources Gemini policy
oversight
The shortest way to say it
Know CIPP? This is the Google side.
CIPP gave MSPs one console for their whole book of Microsoft 365 tenants. Nothing equivalent existed for Google Workspace — the native tools are single-domain, and the closest products switch you between customer domains one at a time. CrossTenant is cross-tenant from the ground up.
CIPP is an independent CyberDrain project for Microsoft 365 — named here only as the model MSPs already know. CrossTenant is a separate product, built natively for Google Workspace.
Why now
Admin tooling grew one tab at a time.
CrossTenant was designed whole.
A console per domain, a script to bridge two of them, a spreadsheet to remember the rest — every layer made sense when it was added, and the pile never became a system. Cross-tenant management is where this tooling is heading; CrossTenant simply starts there.
- A browser tab per customer
- →One scope picker — all tenants, a group, or one
- Scripts, CSVs and tribal knowledge
- →Live, structured cross-tenant pages
- Spot checks when there's time
- →Whole-book security posture, benchmarked worst-first
The whole fleet, at every altitude
All tenants, a tenant group, or a single customer — the console follows you at every altitude.
Cross-tenant everything
Users, groups, devices, licences, policies — every page aggregates across customers, and writes route safely to the owning tenant.
ExploreSecurity posture
CIS Benchmark, Cyber Essentials, email authentication, policy drift — scored across the whole book, worst-first.
ExploreMail governance
Forwarding, delegates, send-as, IMAP/POP — audited across every mailbox, with fleet-wide remediation.
ExploreDevice lifecycle
ChromeOS, mobile, workstations and managed browsers — inventory and security actions behind confirmation flows.
ExploreAI assistant
Fleet-wide answers, executive summaries, and drafted fixes — governed, dry-run first, human-confirmed.
ExploreCustomer portal
Scoped, branded seats for customers with their own IT — you keep the master view and the audit trail.
ExploreReports & alerts
Branded PDF reports, scheduled delivery, and operator-defined alert rules across the fleet.
ExploreOne-click offboarding
Suspend, transfer Drive and Calendar, strip delegates — one audited sequence, not a checklist of tabs.
ExploreAI, governed
AI that reads the whole fleet.
And never acts alone.
The assistant sees what you see — posture, drift, alerts, across every customer — and turns it into answers, summaries, and drafted fixes. Every proposal passes the same permission checks as a human action, dry-runs first, and executes only when you confirm.
- ✓Proposer, not actor. The assistant drafts; only an operator can run.
- ✓Redacted by design. Mailbox and file contents are stripped before anything reaches the model.
- ✓Your kill-switch. Off until you enable it — tightened per action or per engineer, never loosened downstream.
Co-managed IT
Your customers get a portal too
Give a customer's IT lead a login of their own — scoped to their tenant only, read-only or hands-on per area, under their branding. They get a console that feels like theirs; you keep the master view and the audit trail.
Trust
Secure by architecture
The controls your security team already expects — least privilege, isolation, auditability — applied to every customer tenant.
✓No customer data at rest
Every page is a live Google API read, rendered and discarded. No database, no cache of customer content.
✓Per-tenant isolation
Credentials, tokens, and audit logs are isolated per customer — one tenant's authorisation never reaches another's data.
✓Least-privilege scopes
Read-only customers get read-only tokens; privileged operations request only the scopes they need, per operation.
✓Tamper-evident audit
Every write sits behind explicit confirmation and lands in a hash-chained, per-tenant audit log.
Priced for MSPs — per tenant, not per seat
Per-user pricing is built for a single organisation; you run a fleet. CrossTenant is priced per customer tenant you manage, in two tiers.
Core
Fast onboarding · no extra Google review
- ✓ Cross-tenant directory & user lifecycle
- ✓ Device & ChromeOS management
- ✓ Security posture & customer health
- ✓ Reports, schedules & alerts
- ✓ Customer portal seats & role-based access
Complete
Deep mail & Drive governance
- ✓ Gmail forwarding, delegates & send-as remediation
- ✓ Disable external auto-forwarding fleet-wide
- ✓ Drive storage & shared-drive administration
- ✓ File ownership transfer on offboarding
- ✓ Vault & Drive-label compliance reads
CrossTenant is in early access, so pricing is set per engagement — get in touch for a quote. There's a free tier for managing your own Workspace tenant while you evaluate.
Get started
Your first tenant live in minutes
No agents to deploy, nothing to install in your customers' tenants — CrossTenant talks to the same Google APIs the Admin console does.
Connect a customer
A guided consent flow shows exactly which permissions are requested and why, in plain language. Read-only mode if that's all a customer wants.
See the whole book
Health grades, posture, and alerts across every customer from the first screen — worst-first, so the tenant that needs you today finds you.
Fix from one place
Bulk actions run with dry-run previews and explicit confirmations, and land in a tamper-evident per-customer audit log.
Early access with direct input on the roadmap · free tier for your own Workspace tenant · [email protected]