Skip to content
All projects

Vantage Central

Multi-tenant SaaS platform Live

Twenty admin portals,
one control panel.

A multi-tenant control panel for organisations that look after Microsoft 365 for many companies at once. Users, licences, groups, mailboxes, devices and security posture for every tenant, reachable from one login - with joiner and leaver processes that run themselves rather than living in somebody’s head.

Built for Managed service providers and internal IT teams

A full interactive build on fictional tenants. Nothing you click touches a real Microsoft 365 account.

Vantage Central
Vantage Central - Multi-tenant SaaS platform

1,700+

Automated tests

12

Onboarding integrations

Counted from the codebase: the test cases that run on every change, and the third-party systems a new starter can actually be provisioned into. A thirteenth integration exists as a stub awaiting the vendor’s API docs and is not counted here.

What it was like before

Managing Microsoft 365 for one company is tedious. Managing it for twenty is chaos: twenty admin portals, twenty logins, and twenty places to check whether somebody still holds a licence they stopped using in March. Every new starter is a manual checklist, every leaver is a half-remembered set of steps, and nobody can prove afterwards what was done or when.

What we built

Vantage Central pulls every tenant into one dashboard, turns joining and leaving into a form the client fills in and the platform executes, and watches continuously for the things that cost money or create exposure. It is sold as a product: organisations, plans, seat limits, suspension and optional single sign-on are part of the platform rather than bolted on afterwards.

What it
actually does.

Multi-tenant command centre

Switch between the tenants you manage without re-authenticating anywhere. Full user directory, groups and distribution lists, mailbox operations, delegation and calendar permissions - plus a visual identity map showing how one person connects to their groups, devices and third-party accounts.

Joiners and leavers, on rails

Each client gets a branded public form, designed on a drag-and-drop canvas with its own questions, branching logic and follow-up actions. Requests land in an approval queue and every step runs live on screen. A leaver can be scheduled weeks ahead and processed unattended on the day.

Retry one step, not the whole run

When one step of twelve fails - a third-party API is down, a mailbox is still converting - it is fixed and re-run on its own instead of restarting the process. A leaver’s files are archived to SharePoint with live progress, so nothing is lost when the account closes.

Device inventory and health

Every managed device per tenant: who has it, whether it is compliant, whether the disk is encrypted, when it last checked in. Remote sync, restart, lock, locate, retire or wipe. A background scan raises alerts for non-compliant, unencrypted and stale machines before anyone reports them.

The questions an auditor asks

Every user’s registered sign-in methods across every tenant, with unprotected admins highlighted and an Excel export. Sign-in logs analysed for impossible travel, repeated failures, new countries and legacy protocols. Access policies rendered readable, strictly read-only. Every action logged against the person it happened to.

Licences nobody is using

Disabled accounts still holding paid seats, guests with licences, and seats billed through distribution that no longer match what the tenant actually consumes. Surfaced as a reclaimable-seat count per tenant rather than as a report somebody has to remember to run.

What it is
built with.

Chosen for how long it will stay supportable, not for what was interesting that year. Everything below is in production in this project today.

Platform

Node.jsTypeScriptExpress 5PostgreSQLRedisDocker

Interface

React 19ViteMUIServer-Sent EventsReact Flow

Integrations

Microsoft GraphIntuneEntra ID & Conditional AccessExchange Online PowerShellSharePoint & OneDrivePax8Heimdal Security

Security

OAuth 2.0 admin consentAES-256-GCM token storagePer-request CSPRole-based accessEntra ID single sign-on

Something like this,
for your business.

Vantage Central started as somebody describing a process that had stopped working. If that sounds familiar, that is all we need to start.

Discovery and written scope - free, and yours to keep