Skip to content

Customer Management ​

Provider-only feature

Customer management is available to provider organizations (security firms and MSSPs that manage security services for multiple client organizations).

Providers use the Customers page to provision, manage, and monitor their client organizations within Hashiro.

Customer list

Screenshots use fictional demonstration data.

Viewing Customers ​

Navigate to Customers in the sidebar to see all your client organizations. Each customer entry shows:

  • Organization name and logo
  • Account status (active, provisional, deletion-requested)
  • Number of users
  • Creation date

Provisioning a New Customer ​

  1. Go to Customers and click New Customer
  2. Enter the client organization's details:
    • Organization name and short name
    • Contact email for the initial administrator
    • Contact name
  3. Submit the form

This creates the client organization and sends an invitation email to the contact. The initial user receives the client organization's management role.

Customer Lifecycle ​

Provisioned → Invitation Sent → Claimed → Active
                                            ↓
                                    Deletion Requested → Deleted
StatusDescription
ProvisionedOrganization created, invitation pending
Invitation SentEmail sent to the initial contact
ClaimedContact has accepted the invitation and set their password
ActiveOrganization is fully operational
Deletion RequestedClient has requested account deletion (awaiting processing)

Before the Invitation is Claimed ​

While a client organization is still provisional (unclaimed), providers can:

  • Resend the invitation email
  • Delete the provisional organization entirely

Once the invitation is claimed, the organization becomes active and can only be removed through the deletion request process.

Managing Customer Organizations ​

Users ​

Provider access to client-user management depends on the client's provisional state and the caller's permissions. Invitation and provisional-password controls apply before the organization is claimed. A claimed client manages its own credentials.

Settings ​

Review authorized client details and contracted limits. Editing depends on the operation, permissions, and organization ownership.

Access ​

Inspect projects, assets, and findings for explicitly linked clients. A provider relationship does not grant unrestricted access to every per-organization cloud connection or configuration.

WARNING

Client data isolation is maintained at the platform level. Providers can only access client organizations they have an explicit relationship with. There is no cross-tenant data access between unrelated organizations.

Deletion Requests ​

Clients can request the deletion of their own organization from the organization settings page. When a deletion request is submitted:

  1. The request enters a review queue
  2. Platform staff reviews and approves or rejects the request
  3. Approved deletions enter a retention window before permanent removal
  4. During retention, the organization can be restored if needed

This process ensures that no organization is accidentally or maliciously deleted without proper review.

Hashiro. Continuous Threat Exposure Management.