Managed customer workspaces are an optional Stackyapper mode for MSPs. The
company-wide workspace, app, access, AI-client, and Audit concepts still apply;
each managed customer adds a separate tenant boundary.
Use a managed customer workspace when the customer requires distinct users,
connections, policies, Audit scope, or lifecycle controls. Do not use naming
conventions as a substitute for a workspace boundary.
Scope safety
Before configuring an app or changing access:
Check Current workspace in the sidebar.
Confirm the customer name and domain.
Confirm the provider tenant belongs to that customer.
Make the change.
Verify the resulting activity inside the same workspace.
Customer users should not receive access to the MSP's internal workspace unless
that is an intentional, reviewed exception.