Control Tower
Five Microsoft tenants, 200+ locations, and no unified view of cost, identity, compliance, or lifecycle evidence. Leadership couldn't answer basic governance qu…
Not a wall of logos. A few systems told in depth, then the open-source ecosystem they grew into. Each one: the problem, the architecture and why, how agents were supervised and evaluated, and what I'd do differently.
Five Microsoft tenants, 200+ locations, and no unified view of cost, identity, compliance, or lifecycle evidence. Leadership couldn't answer basic governance qu…
Support knowledge scattered across POS configs, SharePoint, and 100K+ helpdesk tickets. Answers had to respect brand and role boundaries. Staff in one brand sho…
Nobody could answer 'what do we run and what does it cost' across 41 repos, 11 subscriptions, ~196 Azure resources, plus reseller-billed licensing.
Lifecycle automation. Onboarding, offboarding, leave-of-absence. Across five tenants, without storing a single credential anywhere.
Email overwhelm. Running cloud AI over a personal inbox is a privacy non-starter. I wanted the same production discipline off the clock.
Multi-tenant Microsoft identity governance is hard. MSPs manage dozens of client tenants. PE firms acquire companies with their own Entra ID estates. Multi-bran…
Smaller trails. Open-source tools and personal builds that carry the same discipline.
Cross-platform desktop app for franchise communication. Tauri + React + Vite. Unifies fragmented tooling for multi-unit operators.
Modernizing identity from passwords to FIDO2/passkeys across enterprise environments. Security engineering meets user experience.
The governance work above, generalized and opened up: seven repositories for multi-tenant Microsoft Entra ID governance. Built for MSPs, PE firms, and multi-brand portfolios that need identity lifecycle, infrastructure automation, domain security, and compliance — without vendor lock-in.
Three pillars — Mind (governance), Body (people), Spirit (security) — across seven repos that share a common design system, zero-secret auth, and GitHub Pages deployment.
Every repository is self-contained, MIT-licensed, and deployable to GitHub Pages in under a minute. Open any live site to explore it.
Mother ship — the complete governance framework
The root repository. User lifecycle automation, OIDC zero-secret auth, Entra Graph client, Terraform tenant modules, and pre-commit security hooks. Everything needed to govern a multi-brand Microsoft estate.
Deploy dashboards, not infrastructure
Azure Static Web Apps + Entra ID + SharePoint deployment templates. Seven reference architecture docs, six React design system components, and a step-by-step scaffolding playbook. Production-grade dashboards in ten minutes.
Groups that govern. Access that scales.
Automated group lifecycle engine for Microsoft Entra ID. Smart group creation, persona-based RBAC, dynamic membership rules, and audit logging across multiple tenants.
Provision tenants. Not config drift.
Terraform modules for tenant provisioning and OIDC setup. Flat module composition with object variables. One module, any tenant. Independent state isolation and cost tagging per brand.
Your domains. Your reputation. Your shield.
DNS management + DMARC monitoring + domain security scoring. Tracks SPF, DKIM, DMARC, SSL health, and domain expiry across a multi-brand portfolio. Feeds into PE reporting and compliance dashboards.
Spend smarter. Audit cleaner.
Finance compliance + federated credential management. Receipt ingestion, policy enforcement, budget alerts, and compliance snapshots. Multi-tenant cost allocation with full audit trails.
Documents found. Teams notified.
SharePoint document indexing + Teams notification bridge. Crawls sites, indexes documents, surfaces search results, and pushes alerts to Teams channels. Permission-aware and brand-scoped.
From tenant provisioning to user offboarding, the ecosystem covers the full identity lifecycle across a multi-brand portfolio.
Manage multiple client tenants from a single control plane. Onboard new clients with Terraform modules, not manual clicks. Govern identity, cost, and compliance without building from scratch.
Portfolio companies each get their own tenant, but you maintain oversight. Dashboards show cost, security posture, and identity health across the entire portfolio.
Each brand operates independently but shares governance standards. Staff move between brands with automatic access provisioning. Offboarding is immediate and auditable.
Every repo uses OIDC federated credentials. No client secrets, no API keys in repos, no credential rotation nightmares. GitHub Actions authenticates directly to Azure.
MIT license. Fork what you need, ignore what you don't. No vendor lock-in. No per-seat pricing. The codebase is yours to adapt, extend, and commercialize.
Every system was built with AI agent supervision — automated testing, judge gates, and security auditing. The same discipline that scales to Walmart's 4,000+ users.
Designed as independent polyrepos. Pick the tool that solves your immediate problem — the shared design system and auth patterns make integration natural.
Every system above — the flagship case studies and the open-source TenantFleet ecosystem — was built with Code Puppy, the open-source AI code agent created by Michael Pfaffenberger and John Choi. Adopted internally at Walmart, where they received the President's Innovation Award from Walmart President & CEO John Furner. 4,000+ store employees now use Code Puppy daily. I use it at Head to Toe Brands to run a five-brand, 200+ location franchise portfolio with a lean team — building applications, automations, and operational efficiencies that would otherwise require a much larger organization.
Reframing how teams move from idea to ship.
Northwest Arkansas singletrack as creative fuel.
The grove that grounds everything else.
Hey there! Tyler is currently looking for his next opportunity. Ask me about his background, skills, projects, or how to reach him directly.
hello@tylergranlund.com — for roles, questions, or just to say hi