One canonical model, four native SQL dialects, and an isolation-and-governance layer designed for real enterprises — multi-tenant by design, deployable in your own infrastructure or a private managed hub.
Whether you run one organisation or a hundred, MDM Studio keeps every tenant's data — and every user's clearance — exactly where it should be.
Every model, source, rule, golden record and audit row is tenant-scoped and enforced at the data layer. Users can belong to several tenants and switch between them, with per-tenant branding throughout.
Sign in with directory credentials or a local password, chosen per user. Each tenant configures its own directory (direct bind or search-then-bind), with an encrypted service account and a built-in connection test.
Four classification levels cascade from domain to record. Per-user clearance grants decide who can see Confidential or Restricted data — restricted records are hidden entirely, so their very existence never leaks.
Where clearance masks values, access groups scope which records a person sees — by domain, tier, value hierarchy or column value — applied by every surface, so counts, scores and exports agree. Opt-in per domain, with a preview of what each grant reveals before you arm it.
Change requests with review and approval, model checkout, governance policies and a tamper-evident audit trail you can open event by event. Each request names the objects it touches — picked from your model, not typed — and each part of the record can be signed by the person who performed it.
A role-to-area-to-action permission matrix governs every page and operation, with four-eyes elevation for new administrators and an idle-session policy.
Connection and directory secrets are AES-256 encrypted at rest; all traffic is TLS-terminated. Secrets never leave the hub, and no data is sent to any third-party service.
We'll stand MDM Studio up against a sample of your sources and show isolation, matching and governance working end to end.