How MSP and ODiiN relate
The two consoles share data, but their permission boundaries are separate.
To enter a customer environment you use a temporary session issued after the customer approves.
Two layers
ODiiN is the operating environment, one per customer. MSP is the management layer that looks down on all of them.
Data flows bottom-up
The numbers on MSP screens are not produced by MSP.
Each customer's ODiiN environment collects from the cloud, and MSP only sums those results per partner.
| What MSP shows | Source | Refreshed |
|---|---|---|
| Cost per customer | Cost collection in each ODiiN | Aggregated daily |
| Resource count | Asset inventory in each ODiiN | Every collection cycle |
| Service status | Cloud provider status feed | Real time |
| Audit records | Activity in both MSP and ODiiN | Immediately |
Even after a customer is registered, cost and resources show 0 until the cloud account is linked. That is not an error — the source simply doesn't exist yet.
How you enter a customer environment
An MSP account does not open a customer's ODiiN directly.
The order is: entry request → customer approval → temporary account and session → access via that session.
- 1Entry requestClicking [Go to ODiiN] on the customer detail page creates an entry request.
- 2Customer approvalThe customer side approves. Without approval no session is issued.
- 3Temporary session issuedOnce approved, a temporary account and session scoped to that customer environment are created.
- 4Session-based accessOnly that session can view or act, and every action is written to the audit record.
The approval request method, session lifetime and re-approval cycle will be reflected here once finalized.
Permission boundary
- However high your MSP role, you cannot enter an environment without the customer's approval.
- Customers outside your permission set do not even appear in the list.
- Work done through a session is recorded together with who did what in which customer.
Frequently asked questions
MSP is for partner staff only.
Customer contacts cannot enter this console; they use the ODiiN environment assigned to them.