MSP customer workspaces
On this page
The MSP plan turns aethercert into something you operate for other people. Each of your customers gets a fully isolated workspace; you manage all of them from one login and one invoice, and you decide independently what to charge each of them.
This page covers how it works in the product. The commercial side is on the pricing page and the MSP solutions page.
What isolation means here
Every customer is a separate organization, with its own domains, agents, certificates, authorities, members and event log. It is not a shared tenant filtered by a customer ID.
The practical consequence: there is nothing for one customer to see about another, because there is no query that spans them. Managing ten customers means ten isolated organizations, and you switch between them from the sidebar.
Your own MSP organization is separate again. It has its own certificates and agents if you want them, and it is where slots, billing and the customer list live.
Slots and licences
A slot is a licence you own. It has a tier, its own annual subscription and its own renewal date, and it sits in your pool until you assign it to a customer.
| Included | 5 Standard-tier slots with the MSP plan. |
| Buying more | From the customers page, on demand from the dashboard at a discounted MSP rate. |
| Assigning | Assign a slot to a customer and that workspace immediately runs at that tier. |
| Reassigning | Unassign it from one customer and give it to another. The slot keeps its own renewal date. |
| Auto-renew | Controlled per slot. Turn it off and the slot lapses at its renewal date rather than billing again. |
The tier decides the plan limits inside that customer's workspace - certificate and agent counts, check-in cadence, event log retention - exactly as if they had bought that plan directly.
Buy the slot, then assign it
The two steps are deliberately separate. A slot bought in advance sits unassigned and ready, so signing a customer on a Friday afternoon does not wait on a payment flow.
Onboarding a customer
From MSP > Customers, create the customer workspace. You provide:
| Section | What goes in it |
|---|---|
| Customer details | Name - which appears on invoices and becomes the Stripe company name - a contact person, an email address, and the language for their notifications. |
| Billing and invoicing | Where invoices are sent (defaults to your own organization's address), phone, country, address, and a tax or VAT number. |
| Licence | The workspace tier, taken from an unassigned slot. |
The workspace is created immediately and you can start working in it - add domains, enroll agents, issue certificates - before the customer ever signs in, or without them ever signing in at all.
Giving the customer access
Two models, and both are supported:
- You operate it entirely. The customer never gets a login. You manage their certificates from your own account by switching workspaces.
- The customer sees their own workspace. Invite them into their organization at whichever role fits - viewer for read-only visibility, member for day-to-day work, admin if they should configure deploy targets themselves.
Roles work the same inside a customer workspace as anywhere else, so "read-only visibility for the customer, full control for us" is just a viewer invitation.
Billing and support responsibility
| Who is responsible | |
|---|---|
| Paying aethercert | You. One invoice covers your plan and every slot. |
| Charging the customer | You, at whatever price you set. aethercert has no relationship with your customer. |
| First-line support for the customer | You. That is what the customer is paying you for. |
| Support for you | aethercert. As an MSP you are a direct customer, with a direct line. |
A customer workspace's own in-app support screen points its users at you, not at aethercert, using the contact details on your MSP organization. Keep those current - they are what your customers see.
Ending a customer relationship
Unassign the slot. The workspace drops to Free-plan limits rather than being deleted, so nothing is destroyed and nothing is retracted - certificates already deployed keep working, and the data is still there if the customer comes back.
Then either reassign the slot to a different customer, or turn its auto-renew off and let it lapse at its renewal date.
Deleting a customer workspace outright is a separate, deliberate action. Note that an account deletion is blocked if it would strand an MSP customer workspace, so a workspace cannot disappear as a side effect of someone closing their personal account.