How MSP and ODiiN relate

The two consoles share data, but their permission boundaries are separate.

To enter a customer environment you use a temporary session issued after the customer approves.

About 5 minConceptPartly not final

Two layers

ODiiN is the operating environment, one per customer. MSP is the management layer that looks down on all of them.

Management layerMSPOne partner
Operating layerODiiNCustomer A
Operating layerODiiNCustomer B
Operating layerODiiNCustomer C

Data flows bottom-up

The numbers on MSP screens are not produced by MSP.

Each customer's ODiiN environment collects from the cloud, and MSP only sums those results per partner.

What MSP showsSourceRefreshed
Cost per customerCost collection in each ODiiNAggregated daily
Resource countAsset inventory in each ODiiNEvery collection cycle
Service statusCloud provider status feedReal time
Audit recordsActivity in both MSP and ODiiNImmediately
Customers look empty before linking

Even after a customer is registered, cost and resources show 0 until the cloud account is linked. That is not an error — the source simply doesn't exist yet.

How you enter a customer environment

An MSP account does not open a customer's ODiiN directly.

The order is: entry request → customer approval → temporary account and session → access via that session.

  1. 1Entry request
    Clicking [Go to ODiiN] on the customer detail page creates an entry request.
  2. 2Customer approval
    The customer side approves. Without approval no session is issued.
  3. 3Temporary session issued
    Once approved, a temporary account and session scoped to that customer environment are created.
  4. 4Session-based access
    Only that session can view or act, and every action is written to the audit record.
Still being confirmed

The approval request method, session lifetime and re-approval cycle will be reflected here once finalized.

Permission boundary

  • However high your MSP role, you cannot enter an environment without the customer's approval.
  • Customers outside your permission set do not even appear in the list.
  • Work done through a session is recorded together with who did what in which customer.

Frequently asked questions

MSP is for partner staff only.

Customer contacts cannot enter this console; they use the ODiiN environment assigned to them.

What happens when a session expires?
Viewing and actions stop immediately and you must start again from the entry request. Unsaved work is lost, so split long tasks up front.
What if the customer declines?
No session is issued and you cannot enter the environment. The aggregate data visible in MSP stays as it is.
If an MSP account is deleted, are its sessions cut too?
Yes. When an account is suspended or deleted, sessions issued to it are invalidated as well.
Was this page helpful?