MSP customer workspaces

The MSP plan turns aethercert into something you operate for other people. Each of your customers gets a fully isolated workspace; you manage all of them from one login and one invoice, and you decide independently what to charge each of them.

This page covers how it works in the product. The commercial side is on the pricing page and the MSP solutions page.

What isolation means here

Every customer is a separate organization, with its own domains, agents, certificates, authorities, members and event log. It is not a shared tenant filtered by a customer ID.

The practical consequence: there is nothing for one customer to see about another, because there is no query that spans them. Managing ten customers means ten isolated organizations, and you switch between them from the sidebar.

Your own MSP organization is separate again. It has its own certificates and agents if you want them, and it is where slots, billing and the customer list live.

MSP › Customers - your whole book of business in one list.

Slots and licences

A slot is a licence you own. It has a tier, its own annual subscription and its own renewal date, and it sits in your pool until you assign it to a customer.

Included5 Standard-tier slots with the MSP plan.
Buying moreFrom the customers page, on demand from the dashboard at a discounted MSP rate.
AssigningAssign a slot to a customer and that workspace immediately runs at that tier.
ReassigningUnassign it from one customer and give it to another. The slot keeps its own renewal date.
Auto-renewControlled per slot. Turn it off and the slot lapses at its renewal date rather than billing again.

The tier decides the plan limits inside that customer's workspace - certificate and agent counts, check-in cadence, event log retention - exactly as if they had bought that plan directly.

Buy the slot, then assign it

The two steps are deliberately separate. A slot bought in advance sits unassigned and ready, so signing a customer on a Friday afternoon does not wait on a payment flow.

Onboarding a customer

From MSP > Customers, create the customer workspace. You provide:

SectionWhat goes in it
Customer detailsName - which appears on invoices and becomes the Stripe company name - a contact person, an email address, and the language for their notifications.
Billing and invoicingWhere invoices are sent (defaults to your own organization's address), phone, country, address, and a tax or VAT number.
LicenceThe workspace tier, taken from an unassigned slot.

The workspace is created immediately and you can start working in it - add domains, enroll agents, issue certificates - before the customer ever signs in, or without them ever signing in at all.

Giving the customer access

Two models, and both are supported:

  • You operate it entirely. The customer never gets a login. You manage their certificates from your own account by switching workspaces.
  • The customer sees their own workspace. Invite them into their organization at whichever role fits - viewer for read-only visibility, member for day-to-day work, admin if they should configure deploy targets themselves.

Roles work the same inside a customer workspace as anywhere else, so "read-only visibility for the customer, full control for us" is just a viewer invitation.

Billing and support responsibility

Who is responsible
Paying aethercertYou. One invoice covers your plan and every slot.
Charging the customerYou, at whatever price you set. aethercert has no relationship with your customer.
First-line support for the customerYou. That is what the customer is paying you for.
Support for youaethercert. As an MSP you are a direct customer, with a direct line.

A customer workspace's own in-app support screen points its users at you, not at aethercert, using the contact details on your MSP organization. Keep those current - they are what your customers see.

Ending a customer relationship

Unassign the slot. The workspace drops to Free-plan limits rather than being deleted, so nothing is destroyed and nothing is retracted - certificates already deployed keep working, and the data is still there if the customer comes back.

Then either reassign the slot to a different customer, or turn its auto-renew off and let it lapse at its renewal date.

Deleting a customer workspace outright is a separate, deliberate action. Note that an account deletion is blocked if it would strand an MSP customer workspace, so a workspace cannot disappear as a side effect of someone closing their personal account.