Sendense Documentation

Staff Roles And Tenant Administration

Provider staff sign in to the SCA with scoped roles to run the fleet and manage tenants, and in the CSP edition to administer a tenant's own users.

Documents Home

Concept

Staff Roles And Tenant Administration

Provider staff sign in to the SCA with scoped roles to run the fleet and manage tenants, and in the CSP edition to administer a tenant's own users.

ReadyCurrentscarbacstafftenantsadministration

Overview

Provider staff sign in to the SCA with scoped roles to run the fleet and manage the tenants a provider serves. In the CSP edition, staff additionally administer the individual users within a tenant.

Staff identity is separate from tenant identity. A staff account and its role govern access to the SCA itself; it is not a tenant login. The provider's own team and a tenant's users are two distinct populations, and neither inherits the other's access.

Staff Roles

Every provider staff account carries one role, set when the account is created.

Administrators also manage the staff team, creating staff accounts, setting each account's role, and assigning staff to the tenants they cover. Staff roles and team management are available in both the MSP and CSP editions.

Administrator
A full SCA administrator. An administrator sees and acts across the entire fleet, including every tenant the provider manages, without tenant-by-tenant scoping.
Staff
A provider staff account scoped to the tenants assigned to it. A staff user sees and acts only within its assigned tenants, never across the whole fleet.

Tenant Administration

Staff create and manage tenants, the customer or end-tenant records a provider operates. Tenant management is available in both editions; what differs is what a tenant is bound to.

In the MSP edition, a tenant maps to an independently-run customer SHA. In the CSP edition, each tenant is bound to its own dedicated, single-tenant appliance the provider provisions for it, so one tenant's data never shares an appliance with another's.

Staff can suspend a tenant. Where a tenant signs in through the SCA front door, which is the CSP edition, suspension is re-checked on every request, so it takes effect immediately rather than only at the next sign-in.

Tenant Users

Tenant-user administration is a CSP-edition capability. In a CSP tenant, staff create and manage the tenant's own users, who then authenticate at the tenant front door: the SCA is the identity front door for the tenant and issues each user a session bound to that tenant.

Each tenant user carries a role the provider assigns: a viewer role for read-only visibility, or an operator role that additionally permits backups and restores. These are roles on the tenant's own appliance, not SCA staff roles. When a tenant user acts, the SCA presents that identity to the tenant's appliance, whose own RBAC authorizes the read, backup, or restore. The appliance stays the enforcement point.

Tenant users are scoped to their own tenant and can only ever reach their own appliance. They never see the fleet, another tenant, or the SCA staff surfaces.

Separate Realms

Staff accounts and tenant users live in two separate identity realms.

Two realms, never crossed

The staff realm and the tenant realm are separate. A staff credential never authenticates a tenant session, and a tenant credential never authenticates a staff session.

What It Is Not

A few distinctions keep these roles clear:

  • Staff roles govern access to the SCA itself. They are not appliance-side permissions, and they are not a substitute for the delegated-operation grants a customer's or tenant's appliance enforces.
  • The appliance remains the enforcement point for every per-tenant action. The SCA adds provider capabilities; it does not replace the SHA that runs each deployment's protection.
  • Both editions model tenants. Tenant-user administration and the dedicated per-tenant appliance are CSP-edition capabilities; the MSP edition instead works with independently-run customer SHAs and has no tenant front door.

Related Docs