MSP HUB Administration
Use one SSLNexus Enterprise control plane for the MSP's own infrastructure and the isolated certificate estates it operates for customers.
Operating Model
An MSP-enabled installation has two working contexts:
- MSP HUB is the MSP's own organisation. Use it for the MSP's internal certificates, deployment targets, policies and normal certificate operations.
- Client estate is a customer-specific working area. Its certificate operations are kept separate from other customers and from the MSP's own estate.
The estate selector in the dashboard shows the MSP HUB and the active customer estates available to the signed-in staff member.
Create A Client Estate
Start From MSP HUB
Sign in as an Organisation Administrator and make sure the current estate is MSP HUB.
Open MSP Clients
Select MSP clients and choose Add client estate.
Describe The Customer
Enter the customer name and, where useful, the account/contract reference and tags your service team uses to organise the portfolio.
Create The Estate
Select Create isolated estate. The new customer is then available in the MSP portfolio and estate selector.
Assign Engineers To Customers
Organisation Administrators can oversee the managed portfolio. Operational staff should be given only the customer access they require.
- From MSP clients, open the customer's Access controls.
- Select the enabled MSP staff who should be allowed to work with that customer.
- Save the assignment.
Use per-customer assignment for Operators, Network Operators and Read-only staff so customer visibility follows support responsibility.
Enter And Leave A Customer Estate
Use the dashboard estate selector, or choose Open estate from the MSP client portfolio. The dashboard clearly identifies the active customer context.
When customer work is complete, select MSP HUB to return to the MSP's own infrastructure and shared administration.
What You Operate Inside A Client Estate
Use the normal SSL Nexus workflow inside the selected customer: manage certificates, deployment targets, vendors, policies, reports and audit activity that belong to that estate.
Where maintenance/blackout windows are used, configure them with the customer whose change-control schedule they represent.
Controls That Stay In MSP HUB
Some settings affect the SSL Nexus appliance as a whole rather than one customer. Return to MSP HUB for product licensing, backups/restores and other shared platform administration. This prevents ordinary customer operations from changing appliance-wide configuration.
Suspend Or Reactivate A Customer
From MSP clients, an Organisation Administrator can suspend a customer estate when service is paused or a customer is being off-boarded.
Suspension preserves the customer's certificate records, targets, jobs, policies and audit history. Reactivate the estate when service resumes rather than recreating the customer from scratch.
Client-Estate Capacity
The MSP licence includes a managed client-estate allowance chosen for the size of the portfolio. When that allowance is reached, existing customers continue to operate but another client estate cannot be created until capacity is increased.
Check Settings → Product licence for the current licence state or contact your SSL Nexus account team when additional client capacity is required.
Backups And Disaster Recovery
Backups are managed from MSP HUB because they protect the SSL Nexus appliance and its managed estates together. Treat backup media as MSP-confidential and restrict restore operations to authorised Hub administrators.
If The MSP Add-On Is Removed
Removing the MSP entitlement does not delete the customer portfolio. Client estates and their retained data stay in place, while MSP customer operations remain unavailable until the add-on is restored.
If the organisation no longer requires MSP service delivery, this preservation model allows licensing changes without turning a commercial change into destructive data loss.
Recommended MSP Workflow
- Keep corporate/internal certificates in MSP HUB.
- Create one client estate per customer or separately governed managed environment.
- Use references and tags that map cleanly to contracts, service tiers or regions.
- Assign engineers only to the customer estates they support.
- Use customer-specific policies and maintenance windows to respect change-control requirements.
- Keep appliance-wide licensing, backups and shared administration in MSP HUB.
- Suspend off-boarded customers before archival or contract closeout instead of deleting operational history.

