Skip to content
worth noting Tools and apps

ZS Associates deployed a secure multi-tenant machine learning platform on Amazon SageMaker

only one source so far

ZS Associates built a secure multi-tenant platform for ad-hoc analytics on Amazon SageMaker Studio in a regulated healthcare environment. It operates 200+ SageMaker domains; the source gives conflicting user counts (both 1 000+ and 500+ per day).

ZS Associates, which operates in the regulated healthcare sector, described on AWS Machine Learning Blog how it built a security-hardened environment for ad-hoc analytics based on Amazon SageMaker Studio. The goal was to give data scientists and analysts quick access to machine learning tools while meeting compliance requirements. According to the source, the platform runs without direct internet access by default (internet-free mode), with VPC endpoints handling communication with AWS services. JFrog Artifactory handles software package management with real-time package checks intended to prevent unauthorized or modified code from entering the environment.

The architecture is multi-tenant—each tenant has its own SageMaker domain with an isolated EFS volume, separate IAM roles and configurable network settings. Access permissions are managed by a three-tier structure of IAM roles (Domain Execution Roles, Studio User Roles, Space Execution Roles), which applies the principle of least privilege. Encryption using AWS KMS is enabled by default for EFS, S3, ECR and CodeCommit. Additional security is provided by CrowdStrike (threat detection at the operating system level), Splunk (log aggregation) and CloudTrail (auditing of all API calls).

According to the company, the platform is the main tool for ad-hoc analytics for most of its application teams. However, the source gives conflicting figures for the scale of deployment: the introduction mentions 1 000+ daily active users across 200+ SageMaker domains, while a later section mentions 500+ daily active users across the same number of domains. According to internal cost tracking by ZS, monthly spending on SageMaker exceeds 50 000 dollars; by using SageMaker Savings Plans, the company saves approximately 10 000 dollars per month, according to its own figures. Costs are allocated to individual teams and projects through resource tagging and AWS Cost Explorer.

The platform also includes automated lifecycle configurations—because SageMaker has no native backup functionality, ZS developed its own solution for regularly synchronizing user data and scripts to S3, supplemented by AWS Backup with resource tagging. Access to more powerful instances requires separate approval from the analytics team, and idle resources are automatically shut down to limit unnecessary costs. The rest of the article was not available.

What changed

Why it matters

The case demonstrates a concrete architecture proven in practice for companies in regulated industries that want to give large numbers of users access to machine learning tools while retaining control over security, auditability and costs. The combination of isolated domains, layered IAM roles and tag-based chargeback can serve as a reference pattern for similar deployments in other organizations with similar compliance requirements.

Two audiences, two different impacts

What this means

01

For individuals

For ML and cloud engineers in regulated industries, the case described offers a concrete architecture pattern—three-tier IAM roles, operation without direct internet access using VPC endpoints, and real-time package scanning—as a reference when designing a similar secure environment.

What to do Study the described architecture of IAM roles, network isolation and package scanning as a reference for designing your own self-service ML environment.
More practical updates →
02

For a business

ZS Associates demonstrates that a security-hardened multi-tenant machine learning platform can be operated at scale while tracking costs by team and project through resource tagging; according to internal tracking by the company, monthly spending on SageMaker exceeds 50 000 dollars, and Savings Plans save approximately 10 000 dollars per month.

Risks and compliance
What to decide Consider a similar architecture pattern (multi-tenant SageMaker domains, three-tier IAM roles, tag-based chargeback, Savings Plans) when designing your own secure self-service ML environment in a regulated setting.
More business impacts →
Amazon SageMaker cloud infrastructure compliance Machine Learning Operations Multi-tenant architecture security

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected How ZS democratized secure ad-hoc analytics with Amazon SageMaker