Each client company is a distinct tenant on its own subdomain with row-level security, so client data is never mixed and every workspace stands alone.
02
Onboard client endpoints
Deploy the RMM agent to ingest inventory, patch state and discovery data, enrol devices in MDM across Windows, macOS, Linux and Android, and manage updates in rings with patch management.
03
Control how your team enters a client tenant
MSP staff use the support-access approval workflow: access is requested, approved by the client owner, time-boxed and fully audited — no standing access into client data.
04
Deliver security per client
Scope a separate VAPT engagement to each client’s allowed_hosts, run scans, and hand back a per-client HTML or PDF report.
05
Operate and report by tenant
Run an SLA-aware helpdesk, server and website monitoring, and per-tenant reports and activity logs so each client sees only their own operations.
Example
A worked example
Say an MSP serves 30 client companies from one console. Each client is its own tenant on its own subdomain, so a technician inside Client A’s workspace cannot see Client B at all. The RMM agent reports 14 machines at one client missing a critical patch, and the update rolls out in rings that evening. When an engineer needs deeper access, the client owner approves a time-boxed support session and every action lands in the audit log. Each quarter the MSP scopes a separate VAPT engagement per client and hands each one its own PDF report.
FAQ
Frequently asked questions
How do MSPs isolate client data on Infronest?
Every client is a separate tenant on its own subdomain with row-level security in the database, and cross-tenant isolation is verified by automated tests on each release, so there is no path for one client’s data to reach another.
How does our team get into a client workspace?
Through the support-access approval workflow. There is no standing back door: a technician requests access, the client owner approves it, the session is time-boxed, and every action is written to the immutable audit log.
Can clients log into their own workspace directly?
Yes. Each client tenant has its own subdomain login, and per-tenant reports and activity logs mean a client sees exactly their own operations — useful for QBRs where you want the client looking at the same numbers you are.
Can we run VAPT separately for each client?
Yes. Engagements are scoped to a defined allowed_hosts list per client, scans run independently, and each client gets their own HTML/PDF report — nothing is shared across tenants.
Can we enable different modules per client?
Module access is set per workspace, and owner overrides let you grant modules beyond a plan for a specific client, so each tenant’s footprint is configured independently.
Is there an agent for patching and monitoring client fleets?
The RMM agent ingests inventory, patch and discovery data, patch management deploys updates in rings, and MDM manages enrolled Windows, macOS, Linux and Android devices (no iOS/iPadOS device management today) — one lightweight agent footprint per endpoint.
Is Infronest a certified MSSP that carries our clients’ certifications?
No. Infronest is a multi-tenant platform, not a certified MSSP, and it does not hold PCI, SOC or ISO certificates on your clients’ behalf. It gives you "ISO 27001 aligned — certification in progress" aligned controls and exportable evidence so you can support each client’s own compliance posture.
Tenant-per-client isolation, approval-gated support sessions and per-client VAPT reports let you scale managed services without ever mixing two customers’ data.