Skip to content

Agencies & managed service providers

If your organization runs infrastructure on behalf of other companies - as an agency, an MSP, or an internal platform team managing several business units - Sencai has a dedicated model for that: one organization can be linked to another as its managing organization, with scoped, audited access instead of sharing logins or credentials across accounts. This page covers how that relationship works and what the agency-specific tools under Agency in the sidebar (/gravity/agency/*) and Operations (/gravity/operations) do today.

A cross-tenant relationship links two organizations:

  • The managing organization (sometimes called the operator or parent organization) - your agency’s own account.
  • The customer organization (the child) - the account you manage on their behalf.

Each relationship also carries:

  • A scope - the specific capabilities your organization is granted in the customer’s account (for example, read access to cloud resources, incident visibility and management, audit-log access, billing visibility, or fleet management). Access is scoped to what the relationship explicitly grants, not a blanket admin login.
  • A status - a relationship starts out pending and has to be moved to active before any cross-tenant access takes effect. A relationship can later be suspended or revoked.

Both organizations must already exist in Sencai - the relationship links two accounts together, it doesn’t create the customer’s account for you.

Cross-tenant visibility - what you can see, and what stays isolated

Section titled “Cross-tenant visibility - what you can see, and what stays isolated”

Being a member of the managing organization does not automatically give you visibility into every managed customer’s data. Two things have to both be true:

  1. Your organization has an active relationship with that customer organization.
  2. You take the explicit action of switching into that customer’s context - from Operations (/gravity/operations), each managed organization in the table has a Switch action that moves your active session into their organization.

Once switched, what you can see and do is bounded by the relationship’s own scope - a relationship granting read-only cloud visibility doesn’t let you manage that customer’s fleet agents or billing, even though you’re “in” their account. Organizations you don’t have an active relationship with remain completely isolated, exactly as if you were any other Sencai customer - there’s no ambient cross-tenant visibility beyond what’s explicitly granted.

Audit implications of acting on a customer’s behalf

Section titled “Audit implications of acting on a customer’s behalf”

Every time you switch your active session into a managed customer’s context, that switch is itself written to the audit trail - not just the actions you go on to take inside their account. Combined with the relationship’s own record (which organization granted access to which, what scope, when), this means a customer’s own audit log and admin team can always see when and by whom their organization was accessed on an agency basis, in addition to what was actually changed. See Audit log for how the audit trail itself works.

Agency → Onboard Customer (/gravity/agency/onboard) is a guided form for adding a new managed customer - customer details, a billing model (customer pays directly, your agency pays on their behalf, or internal/no billing), and the capabilities your agency should have in their account.

Bulk operations across managed organizations

Section titled “Bulk operations across managed organizations”

Agency → Bulk Operations (/gravity/agency/bulk-operations) lets an Owner or Admin of the managing organization apply one action across several managed customers at once, instead of repeating it per account.

  1. Create an operation - give it a name, choose a type (tag apply, patch management, security group update, or policy apply), and optionally scope it by tags or provider.
  2. Dry run it first - this counts the real resources across every managed organization the operation would touch, and separately lists any managed organization that’s skipped because your relationship with them doesn’t grant the capability that operation type needs.
  3. Review the dry-run results, then Execute.

Agency → Effort Tracking (/gravity/agency/effort) tracks how much of your team’s time goes into each managed customer, by billing period (month).

  • Generate Report creates or updates an entry per managed organization for the selected period, combining actions your team actually took in that customer’s account (counted automatically from the audit trail) with any manual time you log.
  • Log Time adds manual minutes to an entry - for work that doesn’t show up as a recorded action (calls, planning, and so on).
  • Mark Sent flags an entry as reported to the customer, so you can track what’s already been communicated.
  • Export CSV downloads the current period’s entries.

Using this tool requires Owner or Admin role in your managing organization.

Two related but different views:

  • Agency → Agency Billing (/gravity/agency/billing) - monthly billing summaries, one per operator (your organization), broken down by managed customer: which billing model applies to each, how many resources they have, and an estimated MRR figure per customer based on their actual subscription plan. Generate a summary for a period, review the per-customer breakdown, and finalize it once it’s ready.
  • Agency → Billing Rollup (/gravity/operations/billing) - a live 30-day cost rollup across all your managed organizations (compute, network, storage, and total), useful as a quick cross-customer cost check without generating a formal summary.

Generating and finalizing agency billing summaries requires Owner or Admin role in your managing organization. Neither of these figures is itself an invoice - they’re for your own reporting and reconciliation.

The Operations dashboard (/gravity/operations) also has a search box that looks across every managed organization at once - cloud resources, audit-log entries, and cost records - rather than switching into each customer one at a time to look something up. Results are scoped to organizations you have an active relationship with, the same way switching context is.

Two screens in the app have similar names, and neither gives you cross-customer health data today.

  • Customer Health Scores (under Settings) is a Sencai-internal, platform-wide dashboard for our own platform and customer-success team. It isn’t available to agency operators or customer organizations, whatever your role.
  • Health Overview (under Support; the page itself is titled “Customer Health Overview”) is scoped to the single organization you’re currently in and is visible to you, but it shows a “not implemented” notice instead of data. See Service levels.

If you want visibility into how a managed customer is doing, the audit trail, cost rollup, and support ticket history for that organization (reachable once you’ve switched into their context) are the tools available to you today.