Pillar guide

Employee monitoring for MSPs: what breaks at multi-tenant scale

Most monitoring products are built for one business watching itself. Run it across twelve clients and three things fail: account sprawl, cost that tracks client hiring, and access scoping built for one company.

Published · Updated

Monitoring tools assume one organization: one admin group, one billing relationship, one set of employees. An MSP's unit is a portfolio.

Problem one: one vendor account per client

A single-tenant tool's default path is one account per client: login, settings, invoice, support. Annoying at two clients, real cost at twelve:

  • Technicians juggle a dozen portal credentials
  • Configuration drifts: nothing forces two accounts to match
  • Offboarding means touching every account
  • You reconcile a dozen invoices, not one
  • Cross-client reporting is manual, no cross-account view

The fix: the client as a first-class object in one account, separated records, files, settings, one team login.

Problem two: cost that follows your clients' headcount

Per-monitored-user pricing raises your cost whenever a client hires. You did no extra work and cannot bill more without renegotiating. It also skews which clients get offered monitoring: below twenty employees the deployment effort exceeds the attach, so smaller clients get talked out of it.

Your real cost per client is the technicians who need a console and the rollout support. Neither moves much when a client grows from thirty to sixty. Billing keyed to console access matches that. See the arithmetic.

Problem three: access scoping built for one company

Single-tenant tools model roles as admin, manager, viewer in one organization. An MSP needs a different axis: this technician supports these four clients and not the other eight. Separate accounts enforce that only through who holds which credentials, which you cannot evidence to a client.

What you want is assignment: admins work account-wide, managers see only assigned clients, full or read-only.

What to check before you commit to a tool

  • Can one login move between clients without signing out?
  • Can a manager be scoped to some clients, read-only?
  • Does adding a client change what you pay?
  • Does it deploy silently through your RMM?
  • Is there an audit trail spanning all clients?
  • Can a local admin uninstall the agent to support it?

Limits

Multi-tenant design is not free of trade-offs. A product built for MSPs tends to be younger and shallower on reporting than one that has served enterprises for a decade. SnitchOS is Windows only and signs in through Microsoft Entra only, which rules out mixed fleets and clients not on Microsoft 365. The three problems above are structural. No amount of report depth fixes them.

Sign up

See the multi-tenant model on your own client

$100 per login a month, month to month. Or start with a 14-day pilot, no card.