Setting Up Workspaces¶
Overview¶
Create a workspace, allocate cloud accounts to it, invite its users, and apply branding. Repeat one level down for each workspace that manages its own customers or teams.
Who can use this¶
You need:
MSP Root Adminto create workspaces directly under the root organization.MSP Managed Workspace Managerto create workspaces under a workspace you manage.workspace:modifyto edit workspace settings and branding.user:addto invite users into a workspace.
A workspace manager can act only inside their own subtree.
Before you begin¶
Confirm:
- The cloud accounts you will allocate are connected and visible in your own account pool.
- Whether the new workspace needs to manage workspaces of its own — this decides
ManagedorNormal. - The markup rate, if you are charging this workspace above raw cloud cost.
- The name and email of the workspace's first user.
Create a workspace¶
Two entry points open the same six-step wizard.
To create a workspace directly under the root organization:
- Open
Organization > Overview. - Select
Workspaces. - Select
New managed customer.
To create a workspace under a workspace you manage:
- Open
Workspace. - Select
Child workspaces. - Select
New workspace.
Then complete the wizard:
- Basics — enter
Nameand an optionalDescription. SelectWorkspace type:Managed (can own children)orNormal (leaf). - Ownership — select the
Parent workspace. Leave empty to attach directly under your root scope. - Account allocation — select the cloud accounts to allocate. See Allocate cloud accounts.
- Billing rule — enter
Markup %, or skip to leave the workspace pass-through at 0%. See Markup and billing rules. - Team & access — optionally enter a
Team nameand selectMember user IDsfrom active users. - Review — check the summary and select
Confirm & create.
If a step fails after the workspace is created, the wizard keeps your progress and shows Retry. Selecting Retry resumes from the failed stage instead of creating a duplicate workspace.
Allocate cloud accounts¶
A workspace sees no cost data until you allocate accounts to it. You can allocate during wizard step 3 or at any time afterwards.
- Open the workspace's
Account Allocationstab, or selectAllocate accountson a child workspace row. - Filter by
Provideror search inSearch accounts by name or ID. - Select
Addon each account to allocate, orSelect all shownto add every account matching the current filter. - Select
Save allocation.
The table shows each account's name, cloud ID, and type: Standalone account, Consolidated billing account, or Sub-account. Selecting a parent account automatically includes its sub-accounts, which display Included with parent.
Accounts already allocated to a sibling workspace are disabled and show Allocated to <workspace>. One account cannot serve two siblings at once.
To remove every allocated account, select Remove all and confirm. The workspace loses access to that cost data.
Note
You can only allocate accounts your own workspace already holds. The picker shows your own pool only. At the root, it shows the full connected inventory.
Invite users¶
Users are created directly into the workspace where they belong.
- Open the workspace's
Userstab. - Select
Add User. - Choose
Tenant UserorExternal User. - Enter
NameandEmail Address. - Select
Role. - Keep
Login using SSOselected underSelect Authentication Method:if the user signs in with SSO. - Select
Add.
A workspace manager can assign only MSP Customer Dashboard User inside their workspace. A root administrator sees the full role catalogue and can assign organization-level roles, including MSP Managed Workspace Manager for a workspace that needs to manage itself.
If the Users tab shows No workspace allocated., select a workspace first — a user always needs a workspace context.
Apply branding¶
Branding changes the name and logo the workspace's own users see in their dashboard header and workspace switcher.
- Open the workspace's
Brandingtab, or openOrganization > Overview > Workspaces, select the workspace, and chooseBranding. - Enter a
Brand nameof up to 60 characters. - Upload a
Logoin JPG, JPEG, PNG, or SVG format, up to 5 MB. - Select
Save branding.
Select Remove logo to clear an existing logo.
Build the next level down¶
A Managed workspace repeats this whole process for its own customers. Its manager signs in, opens Workspace, and creates child workspaces, allocating from the account pool the parent gave them and inviting their own users. Everything stays scoped to their subtree.
Expected result¶
The workspace appears in the workspace list with its owner, type, and status. Its users sign in and see a cost dashboard covering exactly the accounts allocated to it.
Notes and limitations¶
- Users are created against a specific workspace. There is no single action that moves a user between workspaces — remove the user from one workspace and add them to the other.
- Adding a user to a team requires that the user is already registered in that workspace.
- A
Normalworkspace cannot create children or allocate accounts.
Troubleshooting¶
If New workspace or New managed customer is missing, confirm your role includes workspace management permission for the target workspace.
If an account does not appear in the allocation picker, confirm it is allocated to your own workspace and not already allocated to a sibling.
If an invite fails with a permission error, confirm your role includes user:add.