CrossTenant
Home / Use cases / Co-managed IT

Co-managed IT

Some customers bring an IT lead of their own: someone who wants real visibility and a measure of hands-on control. Give them exactly that, in a seat you shape and can withdraw, without giving away the master view.

Prefer email? Get in touch and we run onboarding with you.

How it works

Agree the split, then set it

Co-management starts as a conversation: who handles users and devices day to day, who owns security, where the line sits. Whatever you agree becomes the seat's policy. Invite the customer's IT lead into a scoped seat of the same console, with each area set to the level you both settled on, and the same live pages your engineers work from.

scoped seat same console live data

Per-area access levels

Each area of their tenant is independently none, read, or full for the seat. Levels are enforced server-side on every request, not by hiding buttons in the interface: if the seat's level does not allow a write, the server refuses it, whatever the client sends.

none / read / full server-enforced

Their logo on the shell

The seat presents under the customer's own name and logo on their tenant. Co-management goes better when the customer's team feels at home in the tool, rather than borrowing someone else's.

branded shell per-tenant

Single-tenant visibility

A customer seat sees its own organisation and nothing else. The tenant roster is filtered in the API before a response leaves the server, and no cross-tenant scope exists for a customer seat to request: the rest of your book is simply out of reach.

api-filtered one tenant

No borrowed master view

Tenant onboarding, schedules, the cross-tenant book and console administration are MSP surfaces, and for a customer seat they are absent rather than greyed out. There is no admin menu to probe: the server gates those surfaces to your own operators, whatever a client requests.

msp-only server-gated

One shared audit trail

Every action a seat takes lands in the same per-tenant, hash-chained, tamper-evident audit trail as your own engineers' work. Co-managed does not mean unaccountable; whichever team made the change, the trail records it.

hash-chained tamper-evident

Suspension and sign-out

When the engagement changes, or a laptop goes missing, act at once: suspend the seat, or sign it out of every session it holds. A suspended seat is refused at the next sign-in, and both controls are yours to use at any time.

suspend sign out everywhere

A customer seat is the same console scoped down, not a separate product with behaviour of its own to learn and trust. Customer seats continue to be shaped with MSP feedback: if co-managed IT is how you and your customers work, your experience will help set the defaults.

Co-managed IT

Give their IT lead a proper seat

Real visibility and bounded, revocable control for the customer's own team: co-managed in the open, on one console, with one record of what happened.