For MSPs

Multi-tenant break-glass, one MSP, many clients.

Per-client tenant isolation at the crypto layer, delegated admin, cross-tenant incident coordination, and per-client compliance evidence. From onboarding a new client to handing one back, the same tool covers it.

14
Capabilities across the client lifecycle
5
Lifecycle stages — onboard to offboard
2+1
Independent compute clouds (Fly.io planned)
Client tenants per MSP organisation

The problem

Managed service providers juggle credentials, contacts, and emergency procedures for dozens of clients. Shared spreadsheets and generic password vaults do not provide the isolation, audit trails, or crisis coordination your clients expect — and they certainly do not survive a major outage. You also need the same tool to produce meaningfully different compliance evidence for each client's regulatory regime.

Through the client lifecycle

Each card pairs the operational moment with the capability Glassbreak offers for it. Grouped by lifecycle stage so an MSP can see end-to-end coverage.

Onboarding a new client3 capabilities

Per-client organisation + team

What MSPs need

Each new client needs a clean compartment — their own secrets, contacts, playbooks, audit log — with zero leakage from other clients on the same Glassbreak account.

Glassbreak supplies

A new organisation per client. Each org has its own root membership, role table, and encryption-key scope. Cross-org access is impossible at the data layer, not just at the application layer.

Role templates per client size

What MSPs need

Enterprise clients want explicit admin / approver / requester separation. Small clients want one role. You should not have to rebuild role definitions for each client.

Glassbreak supplies

Pre-built role templates: solo-operator, small-team, enterprise-with-quorum. Spin up a new tenant from a template in minutes and customise from there.

Client SSO bridge (Premium)

What MSPs need

Larger clients want to authenticate through their own IdP (Okta, Entra ID, Google Workspace). They also want offboarded users to be cut off automatically.

Glassbreak supplies

SAML / OIDC bridge on the Premium tier. Per-client IdP configuration; deprovisioning at the IdP propagates to Glassbreak through standard SCIM hooks.

Day-to-day operation3 capabilities

Delegated admin per client

What MSPs need

Some clients want to manage their own team rosters; others want you to. You need to grant fine-grained admin to a client without exposing other clients.

Glassbreak supplies

Per-tenant role grants. A delegated client admin can manage members, roles, and policies within their own org and nothing else. The audit log shows who did what, when, in whose tenant.

Cross-tenant vendor catalogue

What MSPs need

Many of your clients share the same upstream vendors (cloud providers, payment processors, regulators). Each client maintaining its own contact list duplicates work and drifts out of sync.

Glassbreak supplies

A shared "vendor pool" inside your MSP organisation, with per-client opt-in references. Update once, propagate to all subscribed clients. End-to-end encrypted.

Per-client secret quorum

What MSPs need

Each client has different break-glass policies. One requires 2-of-5 for prod-admin secrets; another requires 3-of-7; another wants 1-of-1 for low-risk credentials.

Glassbreak supplies

T-of-N is per-secret, not per-tenant. The DB CHECK constraint allows (T=1, N=1) personal or (T≥2, N≥T) team modes; each client configures its own thresholds.

Incident at a client3 capabilities

Cross-tenant incident dashboard

What MSPs need

When two clients have incidents at the same time, you need a single view that shows status across both without giving either client visibility into the other.

Glassbreak supplies

MSP-level dashboard with read-only visibility into incident status per tenant. Client secrets and chat remain encrypted — your MSP role sees timing + severity + assignment, not content.

Per-client war room

What MSPs need

During a client incident you need a coordinated channel with the client and any vendors involved — without that channel persisting visibly to other clients on your tenant.

Glassbreak supplies

Per-client conversation with end-to-end encryption. The MSP team and the client team can be added; vendor contacts can be temporarily invited. Transcript stays scoped to that client.

Simultaneous escalation across clients

What MSPs need

Wide-blast events (cloud regional outage, supply-chain compromise) affect many clients at once. You need to page out to multiple client teams in parallel without manual fan-out.

Glassbreak supplies

Multi-tenant escalation templates. Trigger once at the MSP level; per-client escalation chains fire in parallel; each client sees only its own page log.

Client compliance evidence3 capabilities

Per-client audit trail

What MSPs need

Each client wants a clean SOC 2 / ISO 27001 / DORA / FCA audit pack — and not a mixed log that reveals other tenants exist.

Glassbreak supplies

Audit log is partitioned per tenant. Export only that tenant's rows; other tenants do not appear in either the data or the metadata. Acceptable for a regulator audit.

Regulatory mapping per client jurisdiction

What MSPs need

A UK client wants FCA OR evidence. An Australian client wants APRA CPS 230. A US healthcare client wants HIPAA. Same MSP, different obligations.

Glassbreak supplies

The Executives page maps Glassbreak controls to ~30 frameworks. The per-client audit trail is the evidence. Hand the relevant subset to each client's auditor.

BAA / DPA per client (Premium)

What MSPs need

US healthcare clients want a Business Associate Agreement; EU clients want a signed Data Processing Agreement under SCCs.

Glassbreak supplies

BAA + DPA + SCCs + UK IDTA + Swiss FADP addenda available on Premium. Sign one per client; legal terms reflect the per-tenant data separation.

Client offboarding2 capabilities

Clean client export

What MSPs need

When a client leaves, they want their data — secrets they have access to, contacts, audit trail — in a portable format. Not as a confusing blob.

Glassbreak supplies

Per-tenant export: encrypted secret payloads + the corresponding public keys, contact records, audit log JSON, playbook documents. Re-importable into another Glassbreak tenant or just stored as cold archive.

Revocation that actually revokes

What MSPs need

Standard SaaS offboarding marks a user as "deleted" but the server still holds the data. For break-glass tooling that is unacceptable — the leaving client should be cryptographically separated.

Glassbreak supplies

Per-tenant root keys are deleted on offboarding. Past audit log entries remain (for compliance), but no further decryption of that tenant's content is possible by anyone, including a Glassbreak operator with full DB access.

Why MSPs ship with Glassbreak

Tenant isolation that holds up, cross-tenant operability when it matters, and per-client compliance that does not require running five different tools.

Tenant isolation at the crypto layer

Per-organisation key scopes mean cross-tenant data access is impossible at the encryption layer, not just the access-control layer. A compromised MSP admin role does not equal compromised client data.

Run alongside your existing PSA / RMM

Glassbreak is purpose-built for the break-glass case — not a replacement for ConnectWise / Datto / N-able. It sits on the resilience layer of your stack and never depends on the day-to-day tools.

Multi-cloud means client SLA pressure is real

AWS + Scaleway (Fly.io planned) independent verticals mean a single-cloud outage at your provider does not cascade into a multi-client SLA breach.

Per-client compliance, one tool

Whether your clients are under DORA, FCA OR, APRA CPS 230, HIPAA, MAS TRM, NYDFS, OSFI B-13, or any of the 30+ frameworks mapped, the same Glassbreak tenant produces the right evidence subset.

White-glove migration

Bring an existing book of clients across by importing per-tenant. Premium tier includes guided migration sessions for MSPs onboarding more than 10 clients.

Pricing that scales with you

Free for one client / five members. Standard tier scales linearly with active client members. Premium gives unlimited tenants and the BAA / DPA package.

Start with one client, scale to your book

Free tier covers one team + five members — pick one client to load, run a tabletop, validate the audit export, and grow from there.

Glassbreak is a break-glass platform, not a PSA or RMM. Run it alongside the tools you already use to manage clients; reach for it when those tools are part of the outage or when the client's regulator wants evidence the day-to-day tools cannot produce.

Stay Updated

Get product updates and security insights. No spam, unsubscribe anytime.

We respect your privacy. See our privacy policy.