Working with customer Workspaces
David Starr
This guide explains how customer Workspaces work, then covers creating them from the MSP partner portal, opening them to work in, and adopting existing customers or separating them from your management. It assumes your organization is already a Workbrew MSP partner. If not, start with the Workbrew MSP overview.
Open the portal from the Workspace picker at the top of the Workbrew Console sidebar by choosing Managed Services, or go to https://console.workbrew.com/partners/<partner-name>. The tasks here use the Customer Workspaces page in the portal sidebar.
About customer Workspaces
A customer Workspace is an instance of Workbrew that holds a single customer's Devices. Customers are always separated into their own Workspaces for security, management, and legal reasons. Each Workspace has its own Devices, Policies, members, and plan, and the customer is the owner of this Workspace. The Workspace owner cannot be removed from the Workspace by the MSP and the customer always retains their own environment in the event of separation from the MSP.
The partner is connected to the Workspace through relationships rather than ownership:
- A management relationship gives the partner's team access to the Workspace through the MSP portal.
- A billing relationship includes the Workspace in the partner's consolidated monthly bill.
A Workspace can have at most one management partner and one billing partner. Workspaces created by the MSP have both a management and billing partner relationship by default. If your MSP requires managing a customer that would like to procure (or has already procured) Workbrew themselves or through another organization, contact Workbrew support.
Your team's management access is granted through your management relationship; it's not necessary (or recommended) to create and manage individual MSP access accounts for your MSP inside of a customer Workspace. All MSP activities are logged and auditable through the management relationship.
When an MSP relationship ends with a customer, management and billing access end with it. The Workspace, enrolled Devices, and its data stay with the customer and the customer owner becomes the new admin (see Separate a customer).
The partner organization also has a Workspace of its own, the sandbox Workspace, pre-configured with a Workbrew Enterprise plan. Team members who join the partner automatically get read access to it, so the team can enroll test Devices and evaluate Workbrew functionality without disturbing a customer's fleet.
Your customer may sign in to the Workbrew Console, see their Dashboard and Devices, and work with packages and Policies like any other Workspace, within whatever roles they hold. By default the initial owner of a customer's Workspace is not an administrator of the Workspace. In addition, there are a few places where an MSP-managed Workspace differs from an unmanaged Workspace:
- There are no pricing, subscription, or renewal details as these are managed directly by the MSP partner.
- The customer cannot change their plan or add a payment method. All Workbrew subscription plan changes are handled through the MSP partner.
- The partner's billing rates are not visible.
- Customer support requests are routed through the partner support email instead of Workbrew's support. See Support for Workbrew MSP.
One additional difference is visible only to your MSP team members. When a partner team member views a customer Workspace, an amber Viewing customer workspace banner is pinned to the top of every page, with a Back link that returns to the MSP customer workspaces list. This way an engineer working across many similar Workspaces can quickly see that they are accessing a customer's environment.
Create a customer Workspace
Only MSP admins can create customer Workspaces from the portal.
- On the Customer Workspaces page, click New Workspace.
- Enter a Workspace Name. The name becomes part of the Workspace URL.
- Optionally set a Device Cap, the maximum number of Devices for the Workspace.
- Enter the Customer Owner Email. This person becomes the Workspace owner and receives a welcome email to Workbrew. They start with read-only access, even as the owner.
- Optionally set an Allowed Domain to restrict who can sign in to the Workspace by email domain, as an extra security step.
- Click Create Customer Workspace.
Every new Workspace starts on a free Workbrew plan. The MSP is automatically granted admin access to the new Workspace. The customer's Workspace gets both a management and a billing relationship with your organization, and appears on the Customer Workspaces page with its plan and Device count. To adopt a customer's existing Workspace instead, see Adopt an existing customer. To move a customer onto a paid plan, see Change a customer's plan.
Access a customer Workspace
The Customer Workspaces page lists only the Workspaces you can access. Partner admins always see every customer Workspace, while partner members see just the ones they have been granted (see Working with role-based access control (RBAC)).
Open a customer Workspace by clicking its name on the Customer Workspaces page. The Console switches to that customer's view, and you land on the Workspace's Dashboard with the role your team role and per-Workspace grants give you. You can manage Devices, Policies, Default Packages, and everything else your role allows, under the amber Viewing customer workspace banner described in About customer Workspaces. Every action you take in the customer's Workspace is audited, even though you are not a direct member of it. To return to the portal, click the Back link in the banner.
The Customer Workspaces page
Each row on the Customer Workspaces page also gives you each customer at a glance. It shows the Workspace's plan, its Device count, and fleet-health counts for open vulnerabilities, outdated packages, outdated agents (Devices running an outdated Workbrew Agent), and pending package requests (self-service requests awaiting review), each linking into the relevant page of that Workspace. A search box and health filters (for example, "Has vulnerabilities") narrow the list.
Row actions
Partner admins also see three actions on each Workspace row:
- Info shows the Workspace's owner, its relationship types with your organization, and when it was created.
- User Access manages per-Workspace grants for partner members. See Working with role-based access control (RBAC).
- Plan opens the customer's plan page and lets you change the plan. See Change a customer's plan.
Change a customer's plan
To see or change a customer's plan, partner admins can click the Plan action on a customer row on the Customer Workspaces page. The page shows the plans you offer, each with its billable rate, an estimated monthly amount at the customer's current Device count, and the capabilities the plan includes.
For a customer you bill, change the plan from the same page:
- Click the card of the plan to move to. The card highlights what the change adds or removes against the current plan, and a summary shows the monthly billing before and after, plus this month's prorated charge if you switch today.
- If the target is a paid plan and you have no card on file, add one first. Add a payment method opens the payment portal and returns you to the same preview to confirm.
- Click Confirm plan change. The change applies immediately, and the customer gets the new plan's features right away.
Mid-month changes are prorated. The month bills the old plan's rate for the days it applied and the new plan's rate for the rest, both at the month's high-water Device count, exactly as the preview showed. See MSP billing for how the change appears on the invoice.
Two cases behave differently on this page:
- Management-only customers are read-only. A customer you manage but do not bill (for example, one billed directly by Workbrew) shows only its current plan. Contact Workbrew to change it, so the plan always matches the customer's own subscription.
- Piloting customers show "Not billed during the pilot" on their current plan card. The plan can still be changed, but nothing is charged while the pilot runs.
Downgrading
Downgrading can remove features the customer has configured. When you select a lower plan, the preview lists every configured feature the new plan drops, security-relevant features first, and treats them in one of two ways:
- Features that pause. Policies, the cask allowlist, automatic upgrades, vulnerability patching, webhooks, and the GitHub and GitLab integrations stop applying when the plan no longer includes them. Their settings are kept, not deleted. The preview shows them as a warning, and you can confirm the downgrade. If the customer later returns to a plan that includes the feature, it resumes with its existing configuration.
- Features that must be removed first. Brew Configurations and Brew Commands would keep running on the customer's Devices after a downgrade while the pages to manage them become unavailable, so the preview lists each configured item with a link to remove it. The downgrade cannot be confirmed until they are removed.
Adopt an existing customer
A customer that already uses Workbrew keeps their existing Workspace. Instead of creating a new one, Workbrew adopts the existing Workspace into your organization (customer adoption).
- Agree the move with your customer. Workbrew requires written confirmation from the customer's Workspace owner, by email, before the Workspace is adopted.
- Email help@workbrew.com from your organization with the Workspace name, whether the relationship should be management, billing, or both, and the owner's written confirmation (forwarded or attached).
- Workbrew creates the relationships, and the Workspace appears on your Customer Workspaces page.
A customer Workspace can hold relationships with only one management partner and one billing partner. A Workspace that is managed by another management partner cannot be adopted. It is possible to adopt a customer that is billed by another partner (e.g. reseller) or billed to the customer directly.
Adoption changes nothing inside the Workspace. Its Devices, members, data, and plan stay as they are, and nothing is copied into the customer's member list. What changes comes from the relationships:
- A management relationship gives your team access to the Workspace through the portal, with the role each person gets (see Working with role-based access control (RBAC)). Your team sees the amber Viewing customer workspace banner inside it, and the customer's Contact page starts routing support to your support email. See Support for Workbrew MSP.
- A billing relationship rolls the Workspace into your consolidated monthly bill from the day the relationship starts, and removes the customer's own subscription pages, as described in About customer Workspaces. See MSP billing.
Separate a customer
To end the partnership for one customer, a customer or MSP may contact Workbrew support. Workbrew will remove the Workspace's relationship from the MSP. The customer keeps their Workspace configured with its Devices, data, Policies, and team intact. If applicable, the customer will need to add a method of payment to the plan as part of separation. If the separation would leave the Workspace without an admin, the Workspace owner is automatically promoted to an administrator. Separation removes the MSP team's access through Workbrew MSP and the customer's Workspace no longer will be listed in the Customer Workspaces list or MSP dashboard.
For details on how the end of a billing relationship shows up on your bill, see MSP billing.
Related docs
- Working with role-based access control (RBAC) - granting your team access to a Workspace and the role each person gets
- Working with the MSP dashboard - fleet health across every customer at once
- MSP billing - moving a customer onto a paid plan, how billed Workspaces roll up into your monthly invoice, and how a subscription ends
- Support for Workbrew MSP - the addresses adoption and separation requests go to, and how customer support routes
- Workbrew MSP overview - what Workbrew MSP is and the guides for its other areas
- Console login and SSO enforcement - Allowed Domain and how Workspace membership is controlled
- Decommission a Device or move it to another Workspace - moving customer Devices between Workspaces