MSP / Partners

Manage security for multiple client organizations under one Sectora MSP account. Consolidated dashboards, per-client scoping, volume pricing.

What MSP mode is

MSP (Managed Service Provider) mode lets one Sectora account own multiple client organizations. Useful for:

  • Security consulting firms managing multiple clients
  • Internal security teams at large parent companies managing multiple subsidiaries
  • VARs / agencies reselling Sectora to their customers
  • Holdcos with portfolio companies

Architecture

Each client gets a fully separate organization — separate scans, separate findings, separate Shield sites, separate billing line items. MSP users have cross-org access via a workspace switcher in the top-left.

Roles in MSP mode

MSP Owner (manages all client orgs)
MSP Admin (manages assigned client orgs)
Client Member (scoped to one client)
Client Viewer (read-only scoped)

Consolidated dashboards

The MSP dashboard shows aggregate metrics across all client orgs:

  • Total active scans
  • Critical/High findings by client
  • SLA breach status per client
  • Trending threats affecting your portfolio
  • Cross-client comparisons (e.g. "Client X has 3× the open Highs of client Y")
  • Revenue + usage per client (for VARs reselling)

White-labeling (Enterprise MSP)

Replace Sectora branding with yours for end-customer-facing reports + alerts + dashboards. Custom logo, custom domain (your-firm.com instead of sectora.io), custom email-from address.

Billing models

  • Direct — clients are billed directly by Sectora; you have read-only access.
  • Aggregated — single invoice to the MSP; you bill clients yourself.
  • Per-client subscription — each client has their own Sectora plan; MSP manages but client owns billing.

Onboarding a new client

  1. MSP dashboard → Clients → + Add client
  2. Enter client name + primary contact email
  3. Send invitation — client confirms they want managed security from you
  4. Once accepted, you have admin access to their newly-created org
  5. Configure their domains, integrations, scan schedules
  6. Optionally: invite the client's team with Member or Viewer roles

Data isolation

Each client org is RLS-isolated — even with admin access, queries are scoped to one client at a time via the workspace switcher. There's no "query across all my clients' data" query in the API; cross-client views are aggregations through the MSP dashboard layer.

What's next