Customer identity and cloud permission packs are separate controls. Identity
governs who can enter the customer workspace. A permission pack governs which
provider permissions the MSP connection requests. Neither automatically grants
Stackyapper tools to customer users.
Customer identity package
The customer identity package is billed once per customer organization and can
include customer-owned SAML, SCIM, and a custom access domain.
Configure identity in the customer context:
Select the customer on Customers.
Open its identity configuration.
Use the customer's verified domain and identity-provider metadata.
Generate a customer-scoped SCIM token when provisioning is required.
Store the token directly in the customer's identity provider.
Test with a customer user and verify the customer workspace.
Do not reuse MSP SAML metadata, a SCIM token, or a custom hostname across
customers.
Cloud permission packs
Permission packs describe reviewed Microsoft 365 or Google Workspace access.
Each pack shows:
Read-only or write access classification
Included and excluded capabilities
Credential boundary
Approval requirement
Documentation version
Before enabling a pack:
Read the versioned permission documentation shown in the portal.
Confirm the provider tenant belongs to the selected customer.
Confirm the pack is required for the intended workflow.
Acknowledge the documented access and approval requirements.
If the pack is write-capable, have an MSP workspace owner enable it.
Complete customer administrator consent in the provider.
Verify that the returned provider tenant or domain is the intended customer.
Grant Stackyapper tools separately through customer workspace policy.
Enabling a pack records and permits the reviewed setup. It does not create the
provider authorization and does not grant tools to customer users.
When the documentation version changes, review the current included and
excluded capabilities before renewing the acknowledgement.
To revoke a pack, disable it in Stackyapper and revoke the corresponding
enterprise application, OAuth grant, or domain-wide-delegation client in the
customer's provider console.