# Working With Clients

> How consultancies and managed service providers run automations inside their clients' workspaces, and where the two paths differ.

**Build and operate automations across separate client workspaces from a single login.** Each client gets their own isolated workspace governed by delegation grants. Workflows, connected accounts and run histories stay completely separate.

[Video](https://www.youtube.com/watch?v=sY-58wmzQD8)

## Choose the path that fits your practice

Select your role during onboarding to configure your console and client consent screens:

  
    
      
      
      
    
    
      
    
    Consultant
    
      Projects delivered to clients, then handed over.
    
    
      Your console: Consultant Dashboard
    
  
  
    
      
      
      
      
    
    
      
    
    MSP
    
      Client automations you run and maintain on an ongoing basis.
    
    
      Your console: MSP Dashboard
    
  

**Both paths share the same core features**: delegation grants, recorded session access, cross-workspace pushes, and a unified management console.

What does differ is the shape of the work, and it shows up in three places in
this section:

|                          | Consultant                                                                                   | MSP                                                                          |
| ------------------------ | -------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- |
| **Bringing a client in** | Inviting them to create the workspace makes the handover cleaner: it is theirs from day one. | Creating it yourself suits a workspace you will be operating.                |
| **Grant duration**       | Set it to the length of the engagement, and leave management when you are done.              | The default two years fits an ongoing relationship.                          |
| **When it ends**         | You leave; the client keeps every workflow you built.                                        | It does not, usually. Reviews and scope changes take the place of an ending. |

  
    ### Managed Service Provider (MSP) Practice

    MSPs govern ongoing IT operations across dozens or hundreds of client tenants with strict SLA commitments and recurring revenue models:

    - **Your Stack:** PSA service boards (HaloPSA, ConnectWise, Autotask), RMM agents (NinjaOne, Datto RMM), Directory services (Microsoft 365, Entra ID, Google Workspace), EDR threat feeds (SentinelOne, Huntress, CrowdStrike), and CSP billing (Pax8).
    - **Core Problems Solved:** Eliminating technician toil on high-volume Tier-1 tickets, automating JML user provisioning and session revocation, catching unbilled SaaS license leakage, and enforcing compliance audits.
    - **Operational Workflow:** Build reusable patterns in your primary workspace, review each one-client preflight before pushing, then monitor execution activity from your **MSP Dashboard**.
    - **Key Resources:**
      - [Supported Integrations](/msp/msp-integrations)
      - [App Directory](/msp/integration-directory)
      - [Automation Blueprints](/msp/automation-blueprints)

  

  
    ### Automation Consultant & Solutions Agency

    Consultants and agencies deliver custom, milestone-driven integration projects and specialized business automations with clean client handovers:

    - **Your Stack:** CRM pipelines (HubSpot, Salesforce), Financial & ERP systems (QuickBooks, NetSuite, Stripe), Document & e-Signature tools (DocuSign, PandaDoc), and bespoke REST/GraphQL APIs.
    - **Common Uses:** Building custom data pipelines without sharing credentials, bringing clients into separate workspaces, and delivering client-owned workflow copies.
    - **Operational Workflow:** Invite your client to create their workspace, request a scoped delegation grant for the sprint duration (e.g. 30 or 90 days), deploy your solutions via cross-workspace push, and hand over complete ownership when the project is signed off.
    - **Key Resources:**
      - [Client Onboarding & Invitations](/msp/client-onboarding)
      - [Governance & Scoped Delegation](/msp/governance)
      - [Cross-Workspace Push & Preflight](/msp/cross-workspace-pushing)

  

Nothing above is enforced. They are the defaults that tend to fit, and each is
covered where it comes up.

Already signed up as an Individual / Team? The answer is not fixed — tell your
account team which path fits and they will move you across.

## Getting set up

Start on your own, and the last step is a short conversation with us. Everything
except the client layer is yours from the moment you sign up: your workspace,
your workflows, your connected accounts.

### Sign up and say what you are

Signing up names your workspace, then asks who you are on the **Choose your
role** screen: Individual / Team, **Consultant** or **MSP**. Choose the one that
describes your practice. The answer is recorded against your account and is what
we work from, so it is worth answering accurately rather than picking the middle
option. See [Account & Authentication](/getting-started/account-and-authentication).

### Build in your own workspace

Start by connecting your own accounts and building workflows in your workspace. Once the client layer is enabled, the push process copies a reviewed workflow into each client's workspace.

### We turn the client layer on with you

Multi-tenancy changes how billing, access and client consent work across your
account, so we switch it on together rather than leaving it behind a toggle.
Tell us roughly how many clients you manage and what you want to automate for
them, through [Support](https://forum.getglow.ai/) or your account team, and the
console appears on your workspace. From there the rest of this section applies.

Onboarding support, architecture reviews and the billing arrangement for your
practice come with it. Billing works per client workspace today, so bring how
you invoice your own clients and we will fit it to that.

---

## The rest of this section

The pages below follow the order the work actually happens in.

  - [1. How Multi-Tenancy Works](/msp/how-multi-tenancy-works): The model in one place: what each client's workspace holds, what a grant permits, and what crosses between them. Written so you can hand it to a client who asks.

- [2. Client Onboarding](/msp/client-onboarding): Three ways to bring a client in: create their workspace, invite them to create it, or request access to one they already have.

- [3. Governance & Impersonation](/msp/governance): Confirm what your access permits, how it is scoped, and how a client narrows or ends it before you work in their workspace.

- [4. Your First Client Workflow](/msp/first-client-workflow): Follow one client from approved access through deployment, testing, Live operation, monitoring, and handover.

- [5. Choose a Deployment Method](/msp/choosing-a-deployment-method): Compare a reviewed one-client Admin Push with a rollout from a selected saved version before following either procedure.

- [6. Your Console](/msp/dashboard-analytics): Every client in one view: execution health, cross-client activity, and where something is failing.

- [7. Supported Integrations](/msp/msp-integrations): Protocol matrix and architecture across PSA, IAM, RMM, Security, and Billing with OAuth and REST steps.

- [8. App Directory](/msp/integration-directory): Searchable catalogue of commonly used MSP platforms, with connection methods and setup links.

  - [9. Automation Blueprints](/msp/automation-blueprints): Example patterns for onboarding, offboarding, security triage, billing reconciliation, endpoint maintenance, and lifecycle reporting.

---

## What's Next?

👉 **[How Multi-Tenancy Works →](/msp/how-multi-tenancy-works)** — the model in one page, opening with a two-minute walkthrough. Then [Client Onboarding](/msp/client-onboarding), which is where the work starts.
