The verdict in three sentences
For a software vendor growing from 5 to 100 customers, a shared database with row-level security remains the best balance of cost, simplicity and speed up to several hundred tenants. Schema-per-tenant or database-per-tenant only make sense for strong contractual requirements (healthcare, defense, banking) or customers that represent more than 10% of revenue. Budget EUR 20,000 to 60,000 (about USD 22,000 to 65,000) to rebuild a single-tenant application into true multi-tenancy, and EUR 3,000 to 10,000 for the SAML SSO that enterprise accounts require.
The three isolation models compared
Your isolation model drives infrastructure cost, your ability to sign enterprise accounts and the speed of your releases. At 5 customers, everything works. At 100 customers, every database migration, every backup and every incident multiplies depending on the model you picked.
| Criterion | Shared DB + RLS | Schema per tenant | Database per tenant |
|---|---|---|---|
| Monthly infra cost (100 tenants) | EUR 200 to 600 | EUR 500 to 1,200 | EUR 1,500 to 3,000 |
| Data isolation | Logical (RLS policies) | Strong logical | Physical |
| Running a migration | Single execution | 100 executions | 100 executions + orchestration |
| Onboarding a tenant | A few seconds | 1 to 5 minutes | 5 to 30 minutes |
| Restoring a single tenant | Complex (filtered export) | Simple | Very simple |
| Arguments for a CISO | Fair | Good | Excellent |
| Practical ceiling | Several thousand tenants | 300 to 1,000 schemas | Limited by ops budget |
With PostgreSQL, row-level security enforces a tenant_id filter inside the engine: even a badly written query cannot read another customer's data. This is the default foundation we recommend, with a hybrid model for the 2 or 3 customers whose contract demands a dedicated database.
What moving to multi-tenancy really costs
Most vendors started with one instance per customer, often deployed by hand. That model holds up to 10 or 15 customers, then operations time explodes. The rebuild touches the data model, authentication, billing and internal tooling.
| Workstream | Effort (days) | Indicative 2026 budget |
|---|---|---|
| Audit and target architecture | 3 to 6 | EUR 2,500 to 5,000 |
Adding tenant_id and RLS policies | 10 to 25 | EUR 7,000 to 18,000 |
| Migrating existing customer data | 5 to 15 | EUR 3,500 to 11,000 |
| Roles and invitations per organization | 5 to 10 | EUR 3,500 to 7,500 |
| SAML / OIDC SSO (Azure AD, Okta, Google) | 4 to 12 | EUR 3,000 to 10,000 |
| Internal admin console | 4 to 10 | EUR 3,000 to 7,500 |
| Automated isolation tests and audit | 3 to 6 | EUR 2,000 to 4,500 |
Realistic total: EUR 20,000 to 60,000, depending on codebase size and the quality of existing tests. These estimates use an average day rate of EUR 650 to 750 (in Toronto, senior contractors bill CAD 900 to 1,200 per day, so expect roughly 30% more), an order of magnitude for 2026.
SSO, quotas and billing: the details that block deals
Enterprise accounts (manufacturers, banks, public bodies) almost always require SAML SSO, SCIM provisioning and exportable audit logs. Without them, the tender stops at the security questionnaire. Three points to build into the rebuild:
- Per-tenant quotas: cap requests and storage so one heavy customer cannot degrade service for the other 99 (the noisy neighbor problem).
- Plans and features: per-organization feature flags avoid maintaining customer-specific code branches.
- Data residency: Canadian customers in the public and health sectors often require hosting in Canada (AWS ca-central-1, Azure Canada Central), and European ones sovereign hosting, with a 10 to 30% premium.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Julien, CTO of an industrial maintenance software vendor, runs 14 separate instances. Each update costs him 2 days of deployment, about 24 days a year, and infrastructure runs EUR 2,100 per month. After a EUR 42,000 rebuild to a shared database with RLS and SAML SSO, the hosting bill drops to EUR 650 per month and deployment becomes a single 30-minute operation.
Annual savings: (2,100 - 650) × 12 = EUR 17,400 in infrastructure, plus 22 engineering days freed (about EUR 15,000). Payback comes in about 16 months, not counting the two enterprise accounts signed thanks to SSO, each worth EUR 18,000 a year.
FAQ
Is row-level security enough for a demanding customer?
For 80 to 90% of B2B customers, yes, provided you document the policies and prove isolation with automated tests. For the remaining 10%, a dedicated database billed EUR 300 to 800 more per month settles the issue.
How long does a multi-tenant rebuild take?
Count 2 to 4 months for an application of 50,000 to 150,000 lines of code. Customers are migrated in waves of 5 to 10 to limit risk.
Should we move to microservices at the same time?
No, in 9 cases out of 10. A modular multi-tenant monolith easily handles several thousand tenants and costs 30 to 50% less to operate.
What budget for SAML SSO alone?
EUR 3,000 to 10,000 in development, or a managed service (WorkOS, Auth0) from USD 125 per connection per month. Beyond 10 SSO connections, an in-house integration pays off.
How do we reassure a CISO during the audit?
Provide an architecture diagram, the list of RLS policies, a penetration test report (EUR 5,000 to 12,000) and your audit logs. That package often shortens the sales cycle by 4 to 8 weeks.
Let's scope your project. We price your move to multi-tenancy (audit, RLS, SSO, migration) with a target budget of EUR 20,000 to 60,000 and a 2 to 4 month plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.