Browse
On this page

The client record at a glance

Every region of a client's Overview tab, the tab strip that reaches the rest of the record, and six of its deeper screens: Portal Access, Billing, Edit > Settings, Alerts, Integrations, and Time.

You need View access to Clients to see this record; edit access to change anything from the Edit button

  1. Header and actions

    The client's name and primary domain, with two badges under them: Pod names the pod currently dispatching this client's tickets, and the second badge reads No Plan until a plan is assigned on Billing. Edit opens this client's own settings, including status, client board, identity provider, Co-Managed IT, Default Ticket Assignee, and Owning Pod. The refresh icon reloads the page's live data, and the question-mark icon opens this client's own help.

  2. Tab strip

    Every other area of this client's record. On this instance it lists Documentation, Billing, Meetings, Users, Devices, Tickets, Projects, Time, Integrations, Notifications, Onboarding, Tags, RMM, and Alerts. A tab only shows when the module or connection it needs is turned on for this instance, and only when your own account has rights to it, so a client with Security (CyberSentry) or Licenses enabled would show more tabs than this one does.

  3. Stat tiles

    Four running counts: Open Tickets, Open Projects, Devices, and Users. Each tile is a shortcut into that tab's own list, already narrowed to what's open or active.

  4. Service Performance

    Three service metrics for the date range picked from the Last 30 Days control: SLA Response, the share of this client's tickets that met their response target, Avg First Response, and Tickets Opened.

  5. Health briefing

    A narrative health summary Elise writes on demand from this client's nightly snapshots, CSAT, and SLA history, meant for a quick read before a QBR. Click Generate with Elise to produce one.

  6. Open Tickets card

    A short preview of this client's open tickets with their priority and status. View all opens the full Tickets tab.

  7. Company Information

    Company name, domain, office phone, and street address, editable from Edit > Company Information in the header.

  8. Primary Contact

    The name and email typed into the Primary Contact search field on Edit > Company Information. Whoever is named there is this client's portal owner, and carries the Owner and Full Access badges on Portal Access automatically once their Contact record exists. This card reads Not set until that field is filled in, even when a person already carries a Primary badge on the Contacts tab - that badge is a label on the record only, renamed "Owner (Designated) Contact" in newer builds, and it grants no access by itself.

  9. Billing Information

    The billing email and billing address invoices use, set from the same Edit > Company Information form. It is a separate fact from any person marked Billing on the Contacts tab.

  10. Integrations card

    A one-line summary of this client's external connections. It reads No integrations configured until at least one of Microsoft 365, Google Workspace, External RMM, External PSA, or External EDR is linked; full status and the Connect, Sync Now, and Disconnect controls live on the Integrations tab.

  11. Included services and scope

    A collapsed panel that lists which optional service capabilities apply to this client right now: CyberSentry security monitoring, security awareness training, scheduled meetings and agendas, client health scoring, profitability reporting, onboarding tracking, known-issues sync, and Elise client actions. Each line reads In scope or Not in scope, and shows Default rule (no plan or board configured yet) until a plan or client board rule sets it.

Users > Portal Access

  1. Contacts and Portal Access sub-tabs

    Two different lists under Users. Contacts are manual records for billing, tickets, and meeting attendees; nobody on that list can sign in on the strength of being listed there, including a contact whose Type reads Primary (newer builds: "Owner (Designated) Contact") - that value is a label only. Portal Access is the one door that actually grants a sign-in role, and is the only one of the two shown expanded here.

  2. Portal Users panel

    Every person who can sign in to this client's portal, with a running count and Add User. On-screen text explains the default: users with elevated roles get additional portal access, and all synced users get basic read access on their own. The one exception to Add User is the client's portal owner - whoever is named under Edit > Primary Contact - who appears here automatically with the Owner and Full Access badges the moment their Contact record exists.

  3. Role per person

    Dana Whitfield, above, carries no role dropdown at all - she is this client's Owner, named under Edit > Primary Contact, and keeps every right automatically the moment her Contact record exists. Priya Shah's access is chosen from a dropdown offering Primary Contact, IT Admin, or Billing, set to Billing here, a portal role that is a separate fact from the Billing badge she can also carry on the Contacts tab. Owner is not one of the dropdown's own choices - it belongs only to whoever is named under Edit > Primary Contact, a different field from the Primary Contact role offered here.

Billing sub-tabs and Plans

  1. Billing sub-tabs

    Plans, Invoices, Quotes, Ticket Charges, Discounts, Exemptions, and Tax, reached from this client's own left-hand Billing menu.

  2. Outstanding, Paid, and Quotes

    Three running totals for this client: the unpaid invoice balance, the amount paid to date, and the open quote count. All three read $0.00 or 0 here because Bluebird Dental has no plan yet, matching the No Plan badge under its name.

  3. Core, License, Add-On, and Managed SaaS

    The four categories a client's plan is built from, each with its own Add button. Every section reads none assigned here; once items are added, this same All view lists them together, and the Core, License, Add-On, and Managed SaaS tabs above filter to one category at a time.

Edit > Settings

  1. Status, Client Board, and Identity Provider

    Status shows this client's lifecycle stage, Onboarding here. Client Board is the ticket board driving this client's service-desk workflow, set to Managed. Identity Provider ties the client's portal sign-in to a connected SSO source, or None for portal-native accounts.

  2. Portal Access and Co-Managed IT

    Portal Access turns this client's whole portal on or off; it is on here. Co-Managed IT is off, meaning this client's own IT staff do not get the elevated visibility that mode grants.

  3. Default Ticket Assignee

    Locks every new ticket for this client to one person ahead of every other assignment mechanism, skipping the pod dispatch waterfall entirely. Left on None (use board notification rules) here, so Owning Pod decides instead.

  4. Owning Pod

    The pod whose dispatch waterfall runs this client's tickets whenever no Default Ticket Assignee is set. Set to Help Desk here, matching the Pod badge on the Overview header.

  5. AI Budget Override

    An optional per-client ceiling on AI spend, in cents, overriding the tenant-wide monthly cap for this client's AI calls only. Left blank here, so this client uses the tenant-wide cap.

Alerts desk

  1. Severity column

    Critical, Warning, and Info in one shared vocabulary across every domain this desk lists. A device alert's own severity carries straight through. A CyberSentry alert's high severity reads as Critical here, and its low and informational levels both read as Info. An expiration's severity comes from how close it is: expired or due within 7 days is Critical, due within 30 days is Warning, and anything further out is Info. Severity is the only colour the page uses, so a red row always means the same thing no matter which domain raised it.

  2. Bulk selection and Acknowledge

    Tick the header checkbox to select every open alert on the page, or tick individual rows, then use this bar's Acknowledge to acknowledge all of them at once. Acknowledge means "I have seen this and I am on it" - it is not a resolution. An acknowledged row leaves this default Open view (the desk opens on Open, because that is the work), but the alert itself stays live and still belongs to its own page, which is where it actually gets closed. Acknowledging here writes the identical record the alert's own page would write, with your name on it, so the audit log reads the same either way.

  3. A row's own Acknowledge and Open

    Acknowledge is the one action this desk performs, on purpose, so scanning the list stays one decision per row - there is no snooze anywhere, and acknowledging is the only way a row leaves the working view. Resolving asks for a written reason against the alert's own history, and a device alert's mute is a noise control that lives on that device, so both stay on the page that owns them: use Open, at the end of the row, to get there. If Acknowledge is refused on a row, it usually means somebody else already acted on it, or your account does not carry edit rights for that kind of alert.

Integrations tab

  1. The five sync cards

    Microsoft 365, Google Workspace, External RMM, External PSA, and External EDR, each showing that connection's real health, not just whether something is linked. Linked (green) means genuinely available. Not Linked (grey), shown on all five here, means nothing has been connected yet. Needs attention (amber) means linked but degraded - permissions need updating, a credential expired, the connection errored, or consent was revoked. The Microsoft card carries one more state, Ignored (grey): excluded from Microsoft Graph sync and CyberSentry monitoring, with a Re-enable control that shows only while the client is ignored and you can edit the client. Right after a client admin grants Microsoft consent, its status briefly reads Finalizing Microsoft access (amber, not red) for up to about an hour while Azure finishes propagating the grant, then resolves on its own.

Time tab, drill-down permission (admin-tier account)

  1. Open full day view

    Drills into that technician's own full day (the My Time page filtered to them) - viewing another tech's day. This link only shows to a viewer whose own account carries admin-tier access on the Time area itself, a stricter bar than the tier that gets you onto this Time tab at all. It is shown here because this account carries that admin tier.

Time tab, drill-down permission (edit-tier account)

  1. No Open full day view here

    This account can see the same tech breakdown and ticket line - it holds ordinary access to this client's Time tab - but its own permission group's tier on the Time area is Edit, not Admin, so the Open full day view link never renders. Seeing the breakdown without the drill-down link is exactly what that gap means: view or edit access to this client's time, but not admin access to the Time area itself.

Why it works this way

Users splits into two lists that look alike but do different things. Contacts (Users > Contacts) are records only, for billing, tickets, and meeting attendee lists, and never sign in - not even a contact whose Type reads Primary, a label newer builds rename "Owner (Designated) Contact" without changing what it grants, which is nothing. Portal Access (Users > Portal Access) is the one door that actually grants a sign-in role, Primary Contact, IT Admin, or Billing, to a contact or to anyone else at the client's domain. The one person who reaches Portal Access without an invite is whoever is named under Edit > Primary Contact on the client record: that person is the client's portal owner, arriving with the Owner and Full Access badges and keeping every right.

Which tech and which pod handle this client's tickets are not on the Overview tab at all. Edit > Settings carries Default Ticket Assignee, which locks every new ticket to one person ahead of the pod's own dispatch waterfall, and Owning Pod, which runs that waterfall whenever no assignee is set.

The Primary Contact and Billing Information cards read their own fields from Edit > Company Information, not from whichever Contacts-tab entry carries a Primary or Billing badge. A client can have a Contacts-tab Primary contact on file and still show Not set on the Overview card until that separate field is filled in.

Included services and scope shows Default rule instead of guessing an answer, so nobody reads a false In scope or Not in scope claim before a plan or a client board rule has actually decided it for this client.

Questions this page answers

What does the client Overview tab show?

The Overview tab shows the client's core info: company name, domain, status, tier, primary contact, billing email, and employee count. It also shows linked integration IDs (PSA, RMM, docs, QB) - only for the integrations your tenant has configured - and quick-access buttons for editing the client or viewing as the client (impersonation).

What is the Microsoft banner at the top of Overview?

It surfaces when this client's Microsoft 365 connection needs attention - re-consent, a permissions update, or a credential problem - with a link to fix it. It stays hidden when the connection is healthy, and it's only shown to viewers who can actually act on it (the Integrations-management permission); a viewer without that permission won't see a dead-end banner. For the full connection status and manual sync controls, go to the Integrations (Sync) tab.

What can I do from a card - Connect, Sync Now, Disconnect?

"Sync Now" / "Sync All Sources" trigger a manual sync and only appear when the connection is reachable enough to retry (there's a per-client cooldown to avoid hammering the vendor API). "Connect" starts the per-client consent/link flow for a not-yet-linked or revoked connection. The amber "Fix Connection" link also opens that flow when permissions need updating or re-consent is required. A credential problem (expired secret, app error) is different - it's an MSP-side issue, not this client's - so that button opens the MSP's Microsoft integration page instead of re-running this client's consent. "Disconnect" removes the stored connection and appears whenever there's one to remove, even mid-error. All of these actions require edit permission on this client; re-consenting or fixing an MSP-side credential additionally requires the Integrations-management permission - techs without it see the card but not the action.

What does the Time tab on a client show?

Time logged against this client's tickets, grouped by tech, for the week or month you pick (step with the previous/next arrows). The headline total counts worked minutes only; a "+ {n}h presence" rider next to it is passive time (idle, breaks, ambient browsing) that landed on this client and is shown separately, never folded into the worked total. Expand a tech to see the "· {n}h present" chip alongside their worked hours (present time only shows when some of their browsing was attributed to this client's tickets) and a per-ticket breakdown you can click through to the ticket. This tab doesn't show billable dollar amounts - that lives on Billing.

How do I manage who can sign in from a client?

Open the client, go to Users, then Portal Access. The Portal Users card lists everyone who can sign in. Each row has a picker with three roles: Primary Contact, IT Admin and Billing. Your own client groups sit in the same picker under those. A new person starts on Billing. What a person can see comes from their role or group. There is no per person grid here. The client owner has no picker at all. They carry an Owner badge and a Full Access badge and always keep everything. To take access away, use Remove. That person drops back to plain user access.

What can each client portal role do?

There are four. User works their own tickets and can read docs, their own vault and training. Billing adds invoices, devices, licenses, meetings and the payment card page. IT Admin runs the place day to day. It can read invoices but not pay them, and it can edit people rather than fully manage them. Primary Contact is the same again, plus full control of people and client settings. The client owner sits above all four. They keep full access and carry an Owner badge.

What is the Projects tab for?

This tab lists the project tickets for one client. A project is a ticket with sub-tickets under it. Use one for a job that takes several steps. Plain tickets stay on the Tickets tab. Click a row to open the project.

How do I start a project for this client?

Click "New Project" above the list. That opens the New Project page. Pick the contact and the board there, name the project, then click "Create Project". The new project shows up back in this list.

Why is this list empty?

It means no project ticket here matches your filters. The list then reads "No project tickets for this client." The Status filter starts on Active, so closed work is hidden. Switch it to All to see every project. The search box looks only at this client's projects.

What is the Documentation tab for?

It holds what we know about one client's setup. You read one section at a time. The menu under Documentation picks the section. It ships with Knowledge Base, Password Vault, Procedures, Domains, Network, Expirations, Assets and Imports. Your team can add or hide sections, so your list may differ.

What is the Onboarding tab?

It is a plain internal procedure checklist for bringing this client online. You start a checklist from a template, then tick off each step as your team completes it. It is internal-only - nobody at the client sees or touches it - and steps are checked off manually (there is no auto-completion from integrations).

What is the Alerts Desk?

One place to look at every open alert we raise, across every client and every monitored domain. It does not replace the pages where alerts live: device alerts still belong to the device, CyberSentry alerts to Triage, expirations to the client's documentation. The desk is a reading surface over all of them, so a tech has one list to scan instead of four pages to remember.

What does the Time frame filter measure?

When the alert was raised, not when it expires or when it was last seen. It defaults to All time on purpose: a six month old critical that nobody fixed is exactly the row this page exists to surface, and a rolling window would hide it. The presets are the same ones the report builder uses, so "Last 30 days" means the same thing in both places.

What do Open, Acknowledged and Closed mean here?

Open means nobody has picked it up. Acknowledged means somebody has, and it is still live. Closed means it is over, however it ended: a device alert that resolved, a security alert that was resolved or expired, or an expiration that has passed and been acknowledged. The desk opens on Open because that is the work; switch the Status filter to Acknowledged, Closed or All to see the rest.

What does the client page show?

The client page opens on Overview. At the top are counts. They cover open tickets, open projects, devices and users. Under them are three cards. They hold Company Information, Primary Contact and Billing Information. The tabs beside the page cover the rest. There are a lot of them. Your notes are on Documentation. The money is on Billing. Next come Meetings, then Users, then Devices. After those are Security, Tickets, Projects, Licenses and Time. At the end are Integrations, Notifications, Onboarding, Tags, RMM and Alerts. You will not see them all. A tab shows up only when the module or the link it needs is on. Each one also obeys your own rights. Portal roles live under Users, on the Portal Access tab.

How do I handle a client's billing?

Open the client and go to the Billing tab. It has a row of its own tabs: Plans, Invoices, Quotes, Ticket Charges, Discounts, Exemptions and Tax. The Plans tab has an Add button named after each plan type. New Invoice and New Quote start those. Invoice columns sort. Use the headers Invoice #, Amount, Status, Invoice Date, Due Date or Source. There is no card on file here. Letting a client save a card is a separate opt in. It is set up under Client card capture, on the integrations side.

What is on a client's Devices tab?

Three things, in the order you need them. At the top are the installer doors. That is where you get the install key and download the agent for this client. In the middle is this client's slice of the one device roster. It is the same table you see under RMM, then Devices, with the same Roster and Unapproved tabs, already narrowed to this client. It holds every machine the portal knows about for them, ours and the ones another system told us about. At the bottom is Tool coverage, folded shut. Open it to see which machines are missing an RMM, antivirus or remote access tool. There is no second device list on this tab.

What is Co-Managed IT?

Co-Managed IT lets a client's own IT people work tickets beside you. When it is on, their IT Admin and Primary Contact users can claim an unassigned ticket and log time on it, inside their own company. Billing users never get this. It is off until you turn it on, one client at a time. Use Edit at the top of the client page, then find the Co-Managed IT switch in the Settings part of that form. The switch shows only when the MSP module is on. There is no client Settings tab.

Do people added here get a portal login?

Contacts are the people on file for this client. Most never get a login. The client's portal owner is the person you name with "Edit" on the client, under "Primary Contact". That person carries the "Owner" and "Full Access" badges on "Portal Access" and keeps every right. The "Type" picker on this tab is only a label on the record. That includes "Owner (Designated) Contact". It grants nothing. Anyone else gets a login only when you invite them on "Portal Access".

How is severity decided?

Each domain keeps its own rules and the desk shows them in one vocabulary. Critical, Warning and Info map from the device alert severity, from the CyberSentry alert severity (high reads as critical, low and informational both read as info), and for an expiration from how close it is: expired or within 7 days is critical, within 30 days is a warning, anything further out is info. Severity is the only colour on the page, so a red row always means the same thing.

How do I acknowledge alerts, and what does it do?

Acknowledge means "I have seen this and I am on it". Tick the boxes on the rows you want (the box in the header takes every open alert on the page), then use Acknowledge in the bar above the table; a single row also has its own Acknowledge next to Open. Acknowledged rows leave the default view, because the desk opens on Open. It is not a resolution: the alert stays live and still belongs to its own page, which is where it gets closed. Acknowledging writes the same record the alert's own page writes, with your name on it, so it reads identically in the audit log either way.

Why is there no mute or resolve here?

Acknowledge is the one thing the desk does, so that scanning the list stays one decision per row. There is no snooze anywhere: acknowledging is how a row leaves the working view. Resolving asks for a written reason and the alert's history to write it against, and a device alert's mute is a noise control for that device, so both stay on the page that owns them: use Open at the end of the row. If Acknowledge is refused on a row, it usually means somebody else already acted on it, or your account does not have edit rights for that kind of alert.

What do the badges on the Integrations tab mean?

Each of the five cards (Microsoft 365, Google Workspace, RMM, PSA, and External EDR) shows the connection's real health, not just whether it's linked. "Linked" (green) - genuinely available. "Needs attention" (amber) - linked but degraded: permissions need updating, a credential expired, the connection errored, or consent was revoked. "Not Linked" (grey) - nothing connected yet. The Microsoft card has one more state on top of those three, "Ignored" (grey): excluded from Microsoft Graph sync and CyberSentry monitoring. Click "Re-enable" on that card to resume - it shows only while the client is ignored and you can edit the client. Right after a client admin grants Microsoft consent, its status line reads "Finalizing Microsoft access" (amber, not red) for up to about an hour while Azure finishes propagating the grant - that resolves on its own.

Why don't I see "Open full day view" under a tech?

That link drills into another technician's full day (the My Time page under Time, filtered to them) and is only shown to viewers with admin-tier access on Time - the same tier that page itself requires. If you can see the tech breakdown but not the drill-down link, you have view access to this client's time but not admin access to the Time area.

Was this helpful?

Last validated 2026-09-24