MSP administrators evaluating shared lifecycle workflows
Set up MSP workspace access for operators and reviewers
Choose workspace roles, invite colleagues safely and plan offboarding without confusing screen masking, account access and Azure permissions.
Published by Arctic Parade LTD · Updated 2026-09-17 · Sources and editorial process
Choose a workspace for a trusted team
An Arctic Parade workspace separates one subscribing organisation from another. Within a workspace, every active member can see every managed customer. If a reviewer must not see another client’s records, the current workspace roles do not supply that customer-specific restriction. Establish the access boundary before importing customer information.
Grant the role needed for the work
Administrators manage membership, connections, billing, export and deletion. Operators import inventory and manage actions. Viewers read queues and reports. Use viewer access for someone checking a report rather than sharing an administrator password. Keep at least one active administrator; the application blocks removal of the last one.
Treat invitation links as credentials
An invitation is bound to an email and chosen role, has a single-use token and expires after 48 hours. Share the private link only with its intended recipient, or deliver it through configured transactional email. Revoke unused invitations if a handoff changes. One email belongs to one workspace in this release, and an invitation does not silently change an existing member’s permissions.
Separate masking from permission
Presentation masking replaces sensitive labels when sharing the interface. It does not remove workspace access or anonymise the stored inventory. Administrator exports deliberately contain unmasked records after password confirmation. Review saved reports and downloads before forwarding them, even if the screen was masked during a demonstration.
Offboard in both systems
Remove workspace access to invalidate existing sessions. Disconnect and erase a stored connector credential when it is no longer needed, then separately revoke the application role or credential in Azure. Before deleting a workspace, export approved records and resolve subscription cancellation. UK data-protection requests can also be made by contacting the business; self-service billing controls do not remove statutory rights.
Sources and further reading
Related field guides
Put the process to work.
Explore the current Azure retirement catalogue, then try a small estate scan. Read the coverage limits before acting on a match.