Key facts
| Tenant separation | Workspace and scoped keys per client; events attributed on export |
| Event classes | Authentication, key lifecycle, admin changes and inference metadata |
| Export | SIEM platforms including Splunk, Sentinel, QRadar and Datadog |
| Client delivery | Compliance evidence packs through your portal and reporting cadence |
| Retention | Per-tenant retention configuration matched to client policy |
| Content control | Prompt retention configurable; metadata-first for most tenants |
| Deployment | Cloud, VPC, on-prem and air-gapped for tenants with stricter needs |
| Status | Audit export is live; assistants and responses endpoints are coming soon |
TL;DR
- Separate events at the workspace and key layer, then aggregate for reporting.
- Package monthly evidence packs as a paid service line.
- Offer retention options mapped to each client's policy.
- Keep metadata-first capture unless a client purpose justifies content.
- Use the same event schema whether tenants run cloud or disconnected.
How it works, step by step
- Provision a workspace and scoped key set per tenant, named for reporting and offboarding.
- Route each tenant's audit export into a collector that tags events with the client identifier.
- Define a standard evidence pack: activity summary, key lifecycle changes, admin changes and any policy overrides.
- Agree a reporting cadence and retention period with each client, and configure retention per tenant.
- Keep metadata-first capture as the default, with content capture only under an approved client purpose.
- Automate pack generation so monthly reporting costs minutes rather than a day of analyst time.
- For tenants with stricter requirements, deliver the same schema from a VPC, on-prem or air-gapped deployment.
Try it yourself
Open the AI API key security checklist →
Tenant separation is the product
Managed AI services sell trust, and trust is mostly attribution. If events from two clients share a stream, every report and every investigation becomes ambiguous. Separate at the layer the platform already supports: a workspace and scoped keys per tenant, retrieval indexes inside the same boundary, and per-tenant audit exports.
From there, a collector tags and normalises events with the client identifier. Your portal presents them under your brand, and the underlying platform stays invisible — while each client's records remain traceable to their own keys and workloads.
Evidence packs as a service line
Clients rarely want a raw log feed; they want an answer to a question their auditor will ask. Package events into a monthly evidence pack: total activity by feature, key creation and rotation, administrative changes, policy exceptions and any escalation or override recorded in the workflow.
- Standardise: the same pack format for every client reduces effort and looks professional.
- Automate: generate packs from the collector rather than by hand.
- Charge for it: recurring compliance reporting is a durable service line, not a favour.
Retention and stricter tenants
Retention is where clients differ most. A professional services firm may want short windows; a regulated tenant may need long metadata retention. Configure per tenant, document the choice, and keep content capture out of the default path so retention decisions stay simple.
Some tenants will require VPC, on-prem or air-gapped delivery. Keep the same event schema and pack format across deployments, so reporting does not fracture and your analysts do not learn a second process. That consistency is what makes sovereign delivery economically viable for an MSP.
Honest comparison
| MSP concern | Plugsky | Single-account platform | In-house build |
|---|---|---|---|
| Tenant separation | Workspace and keys per client | Manual filtering | You design tenancy |
| Audit export | Per-tenant streams to SIEM | Shared account logs | Your pipelines |
| Evidence packs | Generated from tagged events | Ad hoc | Your tooling |
| Retention options | Configurable per tenant | Usually fixed | Fully yours |
| Sovereign tenants | VPC, on-prem and air-gapped options | Rarely | High effort |
| Cost to serve reporting | Automated, minutes per client | Manual effort | Engineering heavy |
Frequently asked questions
How do we stop tenant logs mixing?
Separate at the workspace and key layer, and have your collector tag every event with the client identifier. Mixing rarely happens in the platform; it happens in aggregation.
What goes in a monthly evidence pack?
Activity by feature, key lifecycle changes, administrative and policy changes, exceptions and overrides, plus retention confirmations. Keep the format identical across clients.
Can clients choose their retention period?
Yes. Retention is configurable per tenant; document the choice in the service agreement and align it with their records policy.
Should we log prompt content for clients?
Default to metadata. Content capture should require a documented client purpose, restricted access and a short retention window.
How do we serve tenants who need on-prem?
Deliver the same event schema and pack format from a VPC, on-prem or air-gapped deployment. Consistency keeps reporting and analysis in one process.
How do we charge for this?
As a recurring compliance reporting service, often bundled into a premium tier. The work is continuous, so the fee should be too. See the live pricing page for platform plan structure.
How quickly can we onboard a tenant?
With a provisioning script and standard pack template, onboarding is a workspace, keys, retention settings and reporting cadence — hours rather than weeks.