# Witina AI — For managed service providers > One console for a whole book of client networks. A portfolio dashboard ordered > worst-first by a rule you can read, per-customer lifecycle and runbooks, and each > client's device credentials encrypted on a gateway inside *their* network — not yours > and not Witina's. Source: https://witinaai.com/ai/msp.md Part of the Witina AI machine-readable corpus — index: https://witinaai.com/llms.txt Last updated: 2026-09-30 Human version: https://witinaai.com/msp ## The problem it addresses An MSP is the network team for a dozen networks it did not design. RMM covers the endpoints; PSA covers the tickets. The switches, APs and firewalls across dozens of sites are covered by a folder of bookmarks, several vendor cloud dashboards, and whoever remembers that site. Three specific failures follow: - **Nobody notices drift.** A VLAN added by hand two years ago, firmware nobody is tracking, a spanning-tree root that moved. It is not a ticket until it is an outage — at a site nobody has opened since install. - **The client calls first.** Per-vendor dashboards each know about their own gear at one site. None can say which of your clients is in trouble right now, so the escalation path starts with your phone ringing. - **Every network is bespoke.** Standardising on one vendor's cloud is not an option when you do not control the purchase order. ## The portfolio dashboard Turn on MSP mode and **Customers** becomes a top-level section — daily workflow, not an admin screen. It opens on the whole book: how many clients need attention, how many devices you carry and how many are unreachable, gateways online out of gateways deployed, and every open incident across every client, worst severity first. ### Worst-first is a rule, not a vibe Customers sort by: **health → worst open incident severity → incident count → share of fleet unreachable → name.** Severity outranks count deliberately — one critical is a worse morning than three low ones, and sorting by count would bury it. The final key makes the ordering total, so a refresh can never reshuffle the board under your cursor. ### "Needs attention" always says why A client is flagged by **named rules**, and the verdict is the worst rule that fired — a later check never quietly downgrades an earlier critical. Every flag carries its reason onto the card, so triage does not begin by opening the customer to find out what is wrong. Rules include: - **No gateways configured** — the client has sites but nothing that can poll them. - **Devices unreachable** — as a share of the fleet; warning, then critical. - **Gateways offline** — a gateway that was phoning home has stopped. Some is a warning; all is critical, because nothing is reaching that client at all. - **Gateway never checked in** — shipped, never plugged in. - **Devices found, none under management** — discovery worked, onboarding stalled. - **Failing collectors** — the device answers but something polled keeps erroring. Monitored badly, which is easier to miss than not monitored at all. - **Nothing provisioned** — an active customer with no sites, gateways or devices at all. Lifecycle is an input, so a half-installed prospect is not flagged like a live client. ## The customer record Each customer gets a page: their sites, their gateways and when each last checked in, their open incidents, their runbook, and every rolled-up number read from the same source the dashboard uses — so the board and the page cannot tell you two different stories. - **Lifecycle**: prospect → onboarding → active → suspended → offboarded. Rename the states or drop the ones you do not use; the editor only offers what your organization actually has. - **Tier and account manager**: bronze/silver/gold out of the box, or whatever you sell. Filter the whole board by tier or lifecycle. - **A runbook, not a CRM**: free-form notes per customer — who to call, the maintenance window, the odd thing about their core switch, links out to the ticket, wiki and contract. It deliberately points at your systems of record instead of duplicating them, because a stale copy of your PSA is worse than no copy. - **Quick actions**: jump into the client's context, issue a provisioning token for a new site, invite their admin, suspend. Anything you cannot do right now is disabled with the reason rather than offered and then failed. ## Onboarding One form, not a runbook of nine steps you can half-finish. Typing the client's name creates the customer, their first site, their access boundary and their admin team, and mints the provisioning token — **in a single transaction**, so you never end up with half a client. Then you deploy a gateway at their site. ## Isolation - **Per-client gateways**, so each client's device credentials stay encrypted on a gateway inside their own network. - **Overlapping IP ranges** are supported — two clients on the same RFC1918 space do not collide. - Every record is scoped by the Organization / Division / Region hierarchy, and access is checked per request against the scope you are acting in. ## AI access, scoped per client The MCP server pins an agent to **one context**. For an MSP that means you can connect an AI assistant scoped to a single client, and it cannot see any other client's network. Its permissions are also capped to yours and it cannot execute changes. See https://witinaai.com/ai/mcp.md ## Commercial One organization, one login, one bill, however many clients you carry. No credit card to start. The MSP plan is **$899/month** ($8,990/year) and includes 400 monitored devices, 100 client networks, 120 gateways and 100 team members. Past that: $0.51/month per device (up to 4,000) and $2.99/month per extra client network. It is self-serve. See https://witinaai.com/ai/pricing.md ## Related - Capabilities: https://witinaai.com/ai/capabilities.md - Architecture: https://witinaai.com/ai/architecture.md - Contact: https://witinaai.com/contact