An example shows it best. A SaaS vendor gets a new customer. In one run, a tenant pipeline creates a database on the managed database instance, a bucket pair with its own key in Object Storage, a subdomain with record and certificate via DNS & certificates, and rolls out the application for the customer.
The credentials never pass through emails or tickets: the database password and bucket key go via the template straight into the service’s environment, and if you wish as unreadable secrets in Scaleway Secret Manager. Who created what is recorded in the audit log.
In operations, Clusterward knows the same relationships. If the customer’s site goes down, an uptime check reports it, and the link leads to the logs of all instances under Logs & monitoring. If the customer needs an earlier state, the database is restored from a backup alongside the running one, as described under Backups & recovery.
If the customer cancels, everything runs in reverse: database dump and bucket archive first, then the application, domain, buckets and database are removed – exactly the ones created for that customer, and no others. This knowledge of how things relate is the difference between a control plane and a collection of scripts.