Skip to main content
Version: 2026.09

Agent Multi-Tenancy

An agent belongs to one tenant: the tenant an administrator was signed in to when they generated its key (or, where the Identity Service is off, its Agent API Token). The agent processes only jobs and accesses only data belonging to that tenant, which keeps tenants isolated from each other.

Setup​

These steps describe installations with tenant management. If the Admin Panel's Users page has an Invited tab, your installation does not use tenant management; read On installations without tenant management before you start.

Prerequisites​

  • More than one tenant on your Istari platform. With tenant management, a Platform Administrator creates tenants in the Platform Admin Console.
  • For each tenant, someone who can generate agent keys in it: a Tenant Administrator of that tenant, or a Platform Administrator.
  • Agents installed on your target machines.

Configuration Steps​

Installations with the Identity Service off

If the Identity Service is off, the agent signs in with an Agent API Token instead of a key. The Agents page then offers Generate Token instead of Generate Key, because Agent API Tokens can be created only where the Identity Service is off.

  1. Identify Target Tenant: Determine which tenant the agent should belong to.
  2. Sign In to That Tenant: Sign in to the target tenant as a Tenant Administrator or Platform Administrator.
  3. Generate Key: Create an agent key, as described in Generate an agent key.
  4. Configure Agent: Copy the downloaded key file onto the agent host. Set its path as istari_digital_agent_identity_service_secret_file in the agent's istari_digital_config.yaml file, and set istari_digital_agent_identity_service_enabled to true. Then start the agent, or restart it if it is already running.
  5. Verify Assignment: If you can see more than one tenant, first pick the target tenant in the Organization filter. Then confirm the agent appears on the All Agents tab.

On installations without tenant management​

Tenants are Zitadel organizations, set up as in Set Up and Manage Multi-Tenancy with Zitadel Dashboard. The steps above change in two places:

  • When you sign in to the tenant, sign in as an organization administrator of the target organization.
  • When you verify the assignment, select the tenant in the Organization filter to see its agents.

Troubleshooting​

Agent isn't picking up jobs​

  • Problem: Agents across tenants have the same module installed, but they are different versions.
    • Solution: If agents across tenants have the same module installed, the modules must all match the latest version published to the Istari Platform. Update agents so they all have the same version of a particular module.