Run every client, campus and brand from one tenant.
A corporate academy delivers training to 15 client companies from one platform. A K-12 publisher runs 114 schools. Each organisation keeps its own people, programmes, roles, logo and domain — and the group above still sees the whole tree.
Two hierarchies, and the difference matters
Lurno gives an institution two separate trees. A sub-organisation is a full child organisation — its own members, programmes, roles, branding, terminology and domain — and they nest, so a publisher holds a hundred schools and a school holds its campuses. A branch is an operational tree inside one organisation, for campuses, departments and regions, where a role granted at a branch cascades down every branch beneath it. Resell to fifteen client companies and each client is a sub-organisation. Split a university into faculties whose deans run their own staff, and those are branches. Groups are the third primitive: the cohort, class or team a learner sits in.
- Sub-organisation
- A full child organisation inside a parent tenant, with its own members, programmes, roles, branding, terminology and custom domain. Sub-organisations nest; the plan sets how many one tree may hold.
Permission scope runs platform, organisation, sub-organisation, programme, cohort, course and group, with branch alongside group. A grant at a wider scope flows down: a manager given a role at the North branch holds it at every campus under North.
One exception is deliberate, and it is why this works for resellers. Roster permissions — editing a member, seeing personal data, reading an audit log — do not cascade from a parent into a child. You can appoint the administrator of a client's organisation without holding standing power over that client's learners. Isolation is enforced in the database: separation built into the platform itself decide what a request may read.
Sub-organisation, branch or group
All three exist at once. The question is which one a given division of your institution belongs in.
| Capability | Sub-organisation | Branch | Group |
|---|---|---|---|
| What it is | A separate organisation inside your tenant | A unit inside one organisation | A cohort, class or team |
| Nests | Yes, as deep as your structure needs | Yes, up to ten levels | Yes, groups hold groups |
| Own branding, logo and domain | Yes | No | No |
| Own directory of people | Yes | Shares the organisation's directory | Shares the organisation's directory |
| What a role granted here does | Applies inside that organisation; roster permissions do not cascade in from the parent | Cascades down every branch beneath it | That group only |
| Counts against the plan's organisation limit | Yes | No | No |
| Typical use | A client company, a school in a network, a country subsidiary | A campus, a department, a region | Year 9 Biology, the January intake, a sales team |
Your product, your domain, your words
Brand each organisation, or brand once at the top
An organisation starts from one of three theme templates and a default mode of light, dark or system. Seventeen fields are then yours: fourteen colour tokens, the display font, the body font and the corner radius. Add a light logo and a dark one, a favicon, a title and a slogan.
- Four login-page background slots: left and right panes, each with a light and a dark image, resolved from the hostname before anyone signs in.
- Branding inherits by cluster. A sub-organisation with no theme of its own takes the parent's entire theme; the logo pair inherits as a unit; title, slogan and favicon fall back field by field. A school keeps the publisher's palette and flies its own crest.
A domain per organisation, at any depth of the tree
Point learn.yourbrand.com at Lurno and the whole experience answers there — login page, courses, invitation emails. Hostnames are provisioned through Cloudflare, TLS issues automatically, and every organisation in the tree can hold its own. The login page resolves logo, title, slogan, theme and background from the hostname alone, before anyone authenticates.
Sign learners in from your own product, silently
A learner who already has an account with you should not meet a second login. Your backend posts a short-lived signed assertion for a learner it has authenticated. Lurno verifies it, resolves or creates the learner, and returns a single-use code. Redirect the browser to it and the learner is in their course.
- The assertion travels server to server and never touches the browser; the code is single-use and expires in two minutes. Signatures are checked against a vaulted key, with a replay guard that refuses a code presented twice.
- It provisions learners only — a partner key cannot mint an administrator. One signing key covers the partner's whole tree; a per-organisation account code routes each learner to the right one.
Three steps to a live domain
Self-serve from the organisation's own settings. No ticket, no engineer of ours.
- 01
Enter the hostname
Type the domain you want. It is saved at that moment, so you can close the wizard, go and find whoever owns DNS, and come back to it later.
- 02
Publish the DNS records
Lurno shows the exact records for your registrar: a routing record and the domain-control record the certificate needs, or one TXT record if you host the domain yourself.
- 03
Set it primary
Certificates issue asynchronously, so the wizard shows live status until it reads active. Flag the domain primary and every invitation link for that organisation is built on it.
What else changes when the tenant is genuinely yours
Your vocabulary, per language
Rename the platform's words — teacher, student, parent, guardian, class, group, curriculum, school — in singular and plural, separately in each of the four product languages. Clear a value and the default returns.
Audience groups inside one organisation
Segment the experience without splitting the tenant: a playful profile for children, a plainer one for corporate staff. Each carries a theme override, assigned by hand or by rule on email domain or role.
SAML and OIDC single sign-on
On the roadmapCommitted, not built. Partner sign-on covers handing your own authenticated learners over today; if directory-backed login gates your rollout, say so on the call and we will be straight about where it sits.
Where this connects
Before you draw the org chart
Bring us your org chart.
Fifteen client companies, a hundred schools, four campuses, a franchise network. We will model it on the call and show you the permission grants that fall out.