← All signals
6 min read

Why I put every customer in their own resource group

AzureArchitectureMulti-tenant

When you host sites for other people, the boring questions matter most: whose bill is this, what happens when someone leaves, and can one customer's mistake touch another's resources. A resource group per customer answers all three without much ceremony.

Cost: tag the group once and every resource under it rolls up cleanly. Isolation: RBAC and policy apply at the group boundary, so blast radius stays contained. Teardown: cancellation is one delete, not a scavenger hunt.

Where it stops being worth it: shared infrastructure. Your platform's own database, queue, and secrets don't belong in a per-customer group — they live in a platform group with a tighter access story. The line I draw: customer-owned resources get their own group; anything shared stays central.


Got a signal worth building around? Start a conversation →