Skip to content
Kutrion

solutions --msps

Manage and audit access across every client you look after.

Run access for organizations you do not own, from your own. You invite a client once they have their own Kutrion organization, you work in theirs only after they accept, and everything you do there is written into that client's own audit log.

Managed access to client organizations is included from the Team plan up. Per-seat billing when you're ready.

What changes

Answer the client's auditor

When a client's auditor, insurer or security questionnaire asks who touched what, the answer is a record rather than a reconstruction — every brokered session attributable to a person and to that client, on a tamper-evident trail.

Separation you can show

Each client relationship is its own scope, carrying the role they agreed to and an expiry if you set one. There is no shared admin account and no credential passed round the team, and revoking a relationship ends the access it carried.

One console for every client

See every organization you manage in one list — its status, the ceiling role it agreed to, how many brokered sessions you have opened, how many are open right now, and when you last entered.

Assistance that stays self-hosted by default

AI runs against a self-hosted model by default — there is no cloud instance default, and you can point it at an endpoint on your own network. Cloud assistance takes a per-organisation opt-in that is off until an admin turns it on, and every cloud call is audited.

What you can do

  • One operator identity across every client organization
  • Consent first — nothing is granted until the client accepts
  • Per-client separation, so neither side reads the other's data through the relationship
  • Read-only view-as, or act-as at the role they agreed to behind a fresh step-up
  • Every managed client in one list, with sessions and last access
  • AI assistance defaults to a self-hosted model, never a cloud default

faq --list

For MSPs — questions

How do I add a client organization?

You invite them by the email address of someone in their organization, and they need to already have their own Kutrion organization — the invitation links two organizations, it does not create one for them. The invite appears for their owners and admins to accept, nothing is granted until one of them does, and either side can revoke at any time. If an address cannot be invited, Kutrion gives the same answer whichever reason applies, so a refusal does not tell you whether the address has an account.

What can I actually do inside a client's organization?

Two modes. View-as is read-only. Act-as is a write session and needs a fresh passkey or app-MFA step-up plus a role the client agreed to — a read-only relationship cannot be turned into a write session. Both are recorded in the client's own audit log, attributed to the operator who opened the session, and both stop when the relationship expires or is revoked.

Can we see each other's data?

Not by the relationship existing. Each organization's records stay in its own tenant scope; the only thing that crosses is a session you deliberately open, at the role the client agreed to, and the record of it. There is no route the other way — a client cannot enter your organization through the relationship.

Are my own technicians' actions audited too?

Every session an operator opens is recorded in the client's own audit log, attributed to the individual who opened it, so the client can see exactly who entered and when. On your own side you get a per-client summary — sessions opened, how many are open now, when you last entered — and you can expand any client to the sessions behind it: which of your operators opened each one, when it started, whether it was read-only or a write session, and whether it is still open. That view is built from the access grants your own console holds, not from a copy of the client's log, and a session that did not record its scope is shown as unknown rather than assumed read-only.

Is there an MSP plan?

No. Managed access to client organizations is included on Team and Enterprise; there is no separate MSP tier or price.

Manage and audit access across every client you look after.

Managed access to client organizations is included from the Team plan up. Per-seat billing when you're ready.