One team per client, isolated end to end.

You hold privileged access to dozens of organisations that have never met each other. The blast radius of one compromised engineer account is the thing your clients are actually asking about when they send you a security questionnaire.

How the model fits

An organisation holds many teams. Run one team per client: their contacts, their secrets, their playbooks, their audit trail, all separated. Engineers are added to the clients they serve rather than to everything, and removing someone from one client does not disturb another.

Because quorum is per secret, you can require that opening a client’s domain admin credentials needs two of your engineers — or one of yours and one of theirs, which is a genuinely different sales conversation.

Evidence per client, not per MSP

Evidence packs export per team, so each client gets a document about their own environment — the credentials held on their behalf, who could reach them, who actually did and why, and when the procedure was last rehearsed. A pack covering your whole book of business would be useless to any one client and a disclosure problem for the rest.

The RMM question

The uncomfortable scenario for an MSP is not a client outage — it is your own remote management platform being compromised and used against every client at once. The response to that is a plan that assumes your primary tooling is hostile: out-of-band contacts for every client, credentials your RMM never had, and a call tree that does not route through the compromised system. That plan is worth writing before you need it, and worth rehearsing after you do.

Start free