Delegate PowerScale administration without giving up control.
NASLORD Multi-Tenant Manager gives each tenant a self-service portal confined to its access zone — SMB shares, NFS exports, quotas and snapshots — while your team keeps the governance, the roles and the audit log.
The storage team has become the ticket desk for everything
Every new share, every quota change, every snapshot policy goes through a ticket. Central administrators become the bottleneck; client teams wait days for five-minute operations.
The native alternative — granting OneFS administration rights to those teams — exposes the entire cluster. Most organizations therefore choose the bottleneck, for lack of anything better.
What each tenant can manage on its own
-
SMB sharesCreation, modification, permissions and deletion, within its own zone only.
-
NFS exportsPaths, allowed clients and mount options, in full autonomy.
-
QuotasAdvisory, soft or hard quotas per directory and per user.
-
Snapshot policiesSchedules, retention and restores at the level of its own directories.
-
Consumption and chargebackEach tenant sees its own usage and its own costs.
Native OneFS and NASLORD: complementary, not competing
OneFS provides multi-tenant isolation at the platform level — access zones, networks, authentication. NASLORD adds the delegated-administration layer that client teams use every day.
| Capability | Native OneFS | With NASLORD |
|---|---|---|
| Access zones, networks and per-tenant authentication | Yes — the platform foundation | Used as-is |
| Self-service web portal for tenants | — | Yes |
| Confined delegation without OneFS administration rights | Broad rights required | Per-zone roles, no cluster access |
| Multi-cluster management in a single console | One console per cluster | All clusters, all OneFS versions |
| Audit log of tenant actions | Generic system logs | Audit per zone, per user and per action |
| Per-tenant chargeback and budgets | — | With the Chargeback & Showback module |
What a tenant administrator sees
| Path | Type | Limit | Used | % | Status | Last modified |
|---|---|---|---|---|---|---|
| /ifs/research/genomics | Hard | 80 TiB | 61.4 TiB | 77% | On track | team-genomics · 2026-07-28 |
| /ifs/research/imaging | Hard | 60 TiB | 52.8 TiB | 88% | Warning | team-imaging · 2026-08-01 |
| /ifs/research/archives | Soft | 40 TiB | 38.9 TiB | 97% | Critical threshold | team-archives · 2026-08-02 |
| /ifs/research/lab3 | Advisory | 25 TiB | 9.1 TiB | 36% | On track | team-lab3 · 2026-06-14 |
| /ifs/research/exchange | Hard | 10 TiB | 2.4 TiB | 24% | On track | team-collab · 2026-05-30 |
A delegation model designed to be verifiable
Access-zone confinement
Privileges are granted per access zone and per role. A tenant administrator can neither see nor touch another zone’s resources — the separation is structural, not conventional.
Enterprise authentication
LDAP and Active Directory integration, local accounts where needed, and two-factor authentication (TOTP). NASLORD privileges are managed independently of OneFS roles.
Complete audit log
Every creation, modification and deletion is recorded: who, what, when, in which zone. Browsable per cluster and per zone, exportable for your audits.
All your clusters, one console
A single NASLORD appliance manages multiple PowerScale clusters — whatever their size or OneFS version. Tenants that span several clusters are managed in one place, and reports consolidate the entire estate.
- Unlimited clusters per appliance
- Heterogeneous OneFS versions supported simultaneously
- Filesystem browsing and per-directory charts per cluster
- Consolidated chargeback with the Chargeback & Showback module
| Cluster | OneFS | Access zones | Tenants | Capacity | Status |
|---|---|---|---|---|---|
| ISI-PROD-01 | 9.7 | 12 | 9 | 1.2 PiB | Connected |
| ISI-PROD-02 | 9.5 | 8 | 6 | 840 TiB | Connected |
| ISI-DR-01 | 9.7 | 12 | 9 | 1.2 PiB | Connected |
| ISI-LAB-01 | 9.4 | 3 | 2 | 96 TiB | Read-only |
See NASLORD using your own Dell environment.
Connect a test cluster, delegate an access zone, and count the tickets that disappear — for 90 days, at no cost.