{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"redocly_category":"Guides","type":"markdown"},"seo":{"title":"Understand environments, regions, and tenants","description":"Everything about Mosaic Journeys, SDKs, and APIs","siteUrl":"https://developer.transmitsecurity.com/"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"understand-environments-regions-and-tenants","__idx":0},"children":["Understand environments, regions, and tenants"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Mosaic runs your integration within a few clear boundaries: an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["environment"]}," (production or sandbox), a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["region"]}," where your data is stored, and one or more ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["tenants"]}," that hold your configuration and identities. This guide explains each one and how to plan them, so you can set up your integration correctly from the start. For a quick primer on how these pieces fit together, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/deployment/how_mosaic_is_organized"},"children":["How Mosaic is organized"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"environments-and-regions","__idx":1},"children":["Environments and regions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Mosaic is delivered through two environment types, each serving a distinct role in your development lifecycle."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Production"]}," is for live, customer-facing traffic, and enforces your identity, verification, and fraud prevention policies. Production is available in several regions, so you can store your data where your business location, data residency, and compliance requirements dictate:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["United States (US)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["European Union (EU)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Canada (CA)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Australia (AU)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Japan (JP)"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sandbox"]}," is for development and early-stage testing only. It's hosted in the US, supports all Mosaic APIs and SDKs, and must never be used for live traffic."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Your choice of environment and region determines the base URL for API calls and the Admin Portal you log in to:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"table"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Environment"},"children":["Environment"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Region"},"children":["Region"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Base URL"},"children":["Base URL"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Sandbox"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["US"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.sbx.transmitsecurity.io"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["US"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.transmitsecurity.io"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["EU"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.eu.transmitsecurity.io"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["CA"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.ca.transmitsecurity.io"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["AU"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.au.transmitsecurity.io"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["JP"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.gasne1-ts01.transmitsecurity.io"]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Examples in Mosaic documentation are typically based on the US production base URL (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api.transmitsecurity.io"]},"). Check the correct base URL for your region and adjust code snippets as needed. For the full base URL structure, see the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/openapi/api_ref_intro"},"children":["API reference"]},". For all portal URLs and how to switch tenants, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/platform/access_admin_portal"},"children":["Access to Admin Portal"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"plan-your-tenants","__idx":2},"children":["Plan your tenants"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Unless your commercial agreement with Transmit Security specifies otherwise, you're entitled to:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Two production tenants"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["One sandbox tenant"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The recommended way to use them:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["One ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["production tenant"]}," carries live, customer-facing traffic and final validation only."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The second ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["production tenant"]},", paired with the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["sandbox tenant"]},", covers pre-production work—development, UAT, QA, and configuration validation."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Keep live and pre-production work in separate tenants—mixing them in one tenant increases operational risk."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"A note on naming"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The term ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["sandbox"]}," is often used for two different things: Mosaic's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sandbox environment"]},", Transmit Security's US-hosted pre-release environment, and your team's own development and testing setup."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To avoid confusion, refer to your second production tenant used for development and testing as a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["pre-production tenant"]},". It runs in a production environment, separately from Mosaic's Sandbox."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"keep-your-tenant-count-down","__idx":3},"children":["Keep your tenant count down"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Additional tenants add real cost and operational complexity, and usage is tracked and enforced per production tenant—not aggregated across tenants. Before adding a tenant, model your needs with the tools designed for it:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Model organizational complexity with apps and organizations."]}," Give each business unit, subsidiary, market, or channel its own app inside a single tenant, with its own isolated user pool and journeys—without the cost of a separate tenant. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user/apps_and_clients"},"children":["How apps and clients work"]},". For B2B products, model the external business entities that access an app as ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user/b2b/b2b_main-concepts"},"children":["organizations"]},", each with its own members and roles."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manage team access with RBAC."]}," Use ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/platform/manage_admin_users"},"children":["role-based access control"]}," to control who can view or edit configuration in a tenant."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Centralize identity and fraud signals"]}," in one tenant per region. Splitting them reduces detection accuracy and adds integration and operational overhead."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add tenants beyond the default only for a genuine regulatory, data-residency, or release-process reason—and treat it as an architecture decision made with your account team, not a workaround for a process problem. If a team's development volume genuinely can't be managed within the default model, a second production tenant used purely as a pre-production gate is the supported way to add isolation."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"pre-production-usage-limits","__idx":4},"children":["Pre-production usage limits"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Usage is tracked and enforced against your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["production"]}," tenant, which is the single source for commercial reporting, billing, and renewals. Pre-production tenants are for validation and testing, not sustained workloads. Unless explicitly agreed otherwise, pre-production usage is limited to:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"table"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Metric"},"children":["Metric"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Pre-production limit"},"children":["Pre-production limit"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Monthly Active Users (MAUs)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Up to 100 per month"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Detection & Response requests"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Up to 10,000 per year"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Identity Verifications"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Up to 100 per year"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Journey invocations"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Up to 10,000 per year"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sustained usage beyond these limits may require commercial alignment and may result in additional charges. If you anticipate higher pre-production usage, engage your Technical Account Manager or Account Executive proactively."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"model-your-organization-with-apps-and-organizations","__idx":5},"children":["Model your organization with apps and organizations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Within a tenant, an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["app"]}," holds the configuration for one integration—branding, authentication settings, and more—and requires at least one ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["client"]},". Each client represents a specific implementation with its own credentials and settings."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As a best practice, use one client per integration. For example, use a web client for your browser app, a native client for your Android app, and a separate native client for your iOS app. Clients of the same app share user sign-ups, so a user who registers on the web app doesn't need to register again in the mobile app."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use apps to draw clean boundaries for subsidiaries, lines of business, markets, and channels, each with its own isolated user pool—all within a single tenant. To get started, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user/create_new_application"},"children":["Create applications"]}," and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user/apps_and_clients"},"children":["How apps and clients work"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you're building a B2B product, add a second layer of hierarchy with ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["organizations"]},". An organization represents an external business entity—a customer company, partner, branch, or supplier—that accesses your app, and it holds its own members and roles. Organizations can also be nested as parent and child organizations, so one business entity can manage a set of sub-organizations within a scope you control. This lets you model complex customer structures inside a single tenant, without a separate tenant per customer. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user/b2b/b2b_main-concepts"},"children":["B2B Identity main concepts"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"control-team-access-with-rbac","__idx":6},"children":["Control team access with RBAC"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Manage who on your team can view or edit configuration using ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/platform/manage_admin_users"},"children":["role-based access control"]},". Mosaic provides three default roles—",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Global admin"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Global reader"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Support"]},"—plus custom roles you build from a permission tree, following the principle of least privilege."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Two things to plan around:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["RBAC controls Admin Portal permissions"]},"—broadly, what a person can view versus edit. It's not a tool for restricting specific users to specific journeys or connections; that's an organizational-boundary question, and apps are the right mechanism."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Roles are scoped per tenant and aren't synced across tenants."]}," A \"Reviewer\" role in your pre-production tenant and a \"Reviewer\" role in production are two separately defined things that happen to share a name."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Define a consistent role pattern—for example, an Engineer role scoped to pre-production, a Reviewer role with read access to production and edit access to pre-production, and a Release Owner role with edit access to production—document it once, and recreate it deliberately in every tenant, since the platform won't keep them in sync for you."]}]},"headings":[{"value":"Understand environments, regions, and tenants","id":"understand-environments-regions-and-tenants","depth":1},{"value":"Environments and regions","id":"environments-and-regions","depth":2},{"value":"Plan your tenants","id":"plan-your-tenants","depth":2},{"value":"Keep your tenant count down","id":"keep-your-tenant-count-down","depth":3},{"value":"Pre-production usage limits","id":"pre-production-usage-limits","depth":3},{"value":"Model your organization with apps and organizations","id":"model-your-organization-with-apps-and-organizations","depth":2},{"value":"Control team access with RBAC","id":"control-team-access-with-rbac","depth":2}],"frontmatter":{"markdown":{"toc":{"depth":2}},"seo":{"title":"Understand environments, regions, and tenants"}},"lastModified":"2026-10-02T10:16:41.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/deployment/understand_environments_regions_tenants","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}