Teams
For SMBs via MSPs.
- Scales with team size
- 3 agents per user
- Admin console + RBAC
- Audit log (90 days)
For managed service providers
Every client you manage is adopting AI agents. Each agent needs API keys, SSH credentials, 2FA codes. You need to provision, scope, and revoke access across hundreds of clients โ without a shared vault key that one breach blows open.
Your technicians work across dozens of clients. Each client has their own credentials. Today you manage this with shared password vaults, spreadsheets, or "that one document."
When a technician leaves, you scramble to change passwords across every client. Clavitor gives each client their own isolated vault. Your technicians get scoped tokens. Sarah leaves Friday โ revoke her tokens across all clients in one click. Jim starts Monday โ assign him the same role scopes. No passwords to rotate. No entries to touch.
Your MSP gets a company vault for shared infrastructure secrets, plus a personal vault for each of your technicians. Each client gets the same: a company vault for their shared credentials, plus a personal vault for each of their employees. Your technicians get scoped tokens into client vaults โ no shared master key, no all-or-nothing access.
You manage it. You provision agents. You assign technician access. But the data is theirs. If a client leaves, their vaults go with them. Your tokens get revoked. Their credentials are unaffected.
This isn't a limitation โ it's your selling point. "Your credentials stay yours. Always."
Each technician gets scoped tokens into the client vaults they service. The scopes are roles โ "Networking," "Helpdesk," "Full access" โ not individual people. When Sarah leaves on Friday, you delete her tokens. When Jim starts on Monday, you assign him the same role scopes. The credentials in the vault never change. No passwords rotated. No entries touched. No Friday-night scramble.
| Vault | Technician | Scope |
|---|---|---|
| Acme Corp | Sarah | Full access |
| Acme Corp | John | Networking |
| Acme Corp | Peter | Helpdesk |
| Acme Corp | Break-glass | Emergency |
| Bcme Inc | John | Full access |
| Bcme Inc | Sarah | Networking |
The break-glass token is your safety net. It sits in a sealed envelope or a hardware safe โ scoped to the full vault, never used unless everything else fails. The audit log records the moment it's activated, so you know exactly when and why.
Every client vault is replicated cross-hemisphere โ Calgary and Zรผrich. Two sites chosen for geological stability, political neutrality, and maximum distance from each other. If one goes down, the other serves reads and TOTP codes without interruption. Your clients' agents keep working. Their 2FA codes keep generating. No failover you need to trigger โ it's automatic and continuous.
This matters for MSPs more than anyone else. When an infrastructure provider has an outage, your phone rings for every client on that provider. With Clavitor, credential access doesn't go down with the region. Your clients don't notice, and your support queue stays quiet.
AWS UAE went down โ drone strikes physically damaged two of three availability zones. Zero client data affected. That's why we replicate to the other side of the world.
Every credential access is logged โ which technician, which agent, which credential, when, and from where. When a client asks "who logged into our firewall last Tuesday," you have the answer in seconds. When an auditor asks for proof of access control, you export the log.
Password rotations are tracked the same way. When a credential is rotated โ manually or on a schedule โ the audit trail records who triggered it, which entry changed, and which agents picked up the new value. If a rotation breaks something, you trace it back to the exact change.
This is what separates credential issuance from password sharing. A shared password vault tells you the password was accessed โ but not by whom, not by which agent, and not whether it was the human or the bot. Clavitor issues individual tokens to individual actors. Every access is attributed. Every rotation has a cause. Every login to a client's system traces back to a name, a scope, and a timestamp.
This isn't a feature you turn on. It's always running, across every vault, for every client. The audit log is your compliance proof, your incident response tool, and your answer to every "who did what" question your clients will ever ask.
Business case
Credential management isn't overhead โ it's a billable service that improves your margins, cuts operational drag, and raises the security posture of every client you manage.
Per-client vaults with scoped agent access and full audit trails make this a managed offering you can price with confidence. The platform runs at a contractual 99.99% read SLA, fully hosted โ you sell it, we keep it up. Your margin is yours to set.
When a new technician starts, you assign role scopes and they're working in minutes. When someone leaves, you revoke their tokens across every client in one click. No passwords to rotate, no entries to touch, no scrambling on a Friday afternoon.
Their AI agents are already accessing credentials โ probably from environment variables or shared password files. As their MSP, that risk sits on your desk. Clavitor gives you the architecture to fix it properly: every credential scoped, encrypted, and audited across your entire client base.
For SMBs via MSPs.
For MMEs and MSPs with identity.
Advanced security and compliance.
Reseller margin included on every client vault. You set the price, we give you the margin. Volume tiers available โ contact sales for partner rates.
One platform. Every client. Every agent. Every credential. Scoped, audited, revocable.