Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Customer identity and cloud access

Customer identity and cloud permission packs are separate controls. Identity governs who can enter the customer workspace. A permission pack governs which provider permissions the MSP connection requests. Neither automatically grants Stackyapper tools to customer users.

Customer identity package

The customer identity package is billed once per customer organization and can include customer-owned SAML, SCIM, and a custom access domain.
Configure identity in the customer context:
  1. Select the customer on Customers.
  2. Open its identity configuration.
  3. Use the customer's verified domain and identity-provider metadata.
  4. Generate a customer-scoped SCIM token when provisioning is required.
  5. Store the token directly in the customer's identity provider.
  6. Test with a customer user and verify the customer workspace.
Do not reuse MSP SAML metadata, a SCIM token, or a custom hostname across customers.

Cloud permission packs

Permission packs describe reviewed Microsoft 365 or Google Workspace access. Each pack shows:
  • Read-only or write access classification
  • Included and excluded capabilities
  • Credential boundary
  • Approval requirement
  • Documentation version
Before enabling a pack:
  1. Read the versioned permission documentation shown in the portal.
  2. Confirm the provider tenant belongs to the selected customer.
  3. Confirm the pack is required for the intended workflow.
  4. Acknowledge the documented access and approval requirements.
  5. If the pack is write-capable, have an MSP workspace owner enable it.
  6. Complete customer administrator consent in the provider.
  7. Verify that the returned provider tenant or domain is the intended customer.
  8. Grant Stackyapper tools separately through customer workspace policy.
Enabling a pack records and permits the reviewed setup. It does not create the provider authorization and does not grant tools to customer users.
When the documentation version changes, review the current included and excluded capabilities before renewing the acknowledgement.
To revoke a pack, disable it in Stackyapper and revoke the corresponding enterprise application, OAuth grant, or domain-wide-delegation client in the customer's provider console.