All guides

Your brand, your limits, your hours

The settings that apply to every client instance on an environment: the name and colours they see, your own domain, what happens when one outgrows its plan, and when updates are allowed to run.

Verified on August 14, 2026

On a multi-tenant environment, most of what you configure is not per client — it is for all of them at once. Those settings live in Environment settings, folded at the bottom of the Instances tab so they stay out of the way of the client list you actually visit for.

The quota policy panel: three choices - do nothing, tell me, or suspend the client automatically after a grace period - each with the consequence spelled out beneath it.
One of the six panels folded into Environment settings, and the only one that decides what happens to a paying customer.

Four of them are worth understanding before you sell anything.

Your own domain

By default a client's address sits under the platform's domain. Your domain replaces that: point a wildcard at us and every client of this environment gets an address under your name instead.

This is the difference between a client who knows they are on RollBackk and one who only ever sees you. It is set once per environment, and it changes the address new clients receive; existing clients keep what they were given until you move them.

The brand your clients see

Branding sets the name, the colours and the logo your clients meet inside their own Odoo. Only a multi-tenant environment has one — a solo environment has no client to show it to.

Two things about it are worth knowing.

Changing it applies immediately, to everyone. Saving a new brand pushes it into every live client of the environment and tells you how many were rebranded. There is no separate publish step, because an integrator who has just rebranded has told us their clients are seeing the wrong name right now.

One client can differ. A per-client override layers on top, for the customer who wants their own colours. Clearing that override falls back to the environment's brand — not to no brand at all, which would leave that one client staring at a blank white product.

What happens when a client outgrows their plan

Quota policy decides the consequence, and it is one of three. The choice is yours because the right answer depends on what you sell:

SettingWhat the platform does
Do nothingRecords it. Nobody is told, nothing changes.
Notify meTells you. Your client is never touched.
Suspend after a grace periodTells you, then takes the client offline if they are still over when the grace period ends.

Suspension here is the same reversible thing as suspending by hand: it stops the client's address and touches none of their data. And the platform resumes them by itself as soon as they are back within their plan — a limit that punishes forever is a support ticket, not a policy.

There is also a warning threshold, so you hear about a client approaching their limit rather than crossing it.

Per-client prices

Client billing is where a price per client instance is set, and where you see what this environment is currently worth per month across all of them. A template can also carry its own price, which is what the self-service guide covers; this panel is the environment-wide figure.

When updates are allowed to run

The default update window sets the hours during which client upgrades may run on this environment. The upgrade wave described in the client instances guide respects it: a client with a window is only migrated inside it.

Set it to the quiet hours of the businesses you serve, not yours. A retailer and an accountant do not have the same quiet hours, and a client with their own window overrides this default.

Who can change what

These panels are gated separately, and the split follows the risk: environments.domains for your domain, environments.config for the brand, tenant.view to see the quota policy and tenant.manage to change it. A collaborator can be trusted with the client list without being able to rebrand every customer you have.