ShellYard
For MSPs and IT consultancies

One workspace per client.
Bulletproof isolation between them.

The day a tech pastes Globex's vault password into Acme's terminal is the day a contract ends. Spaces stop that cold — credentials, runbooks, audit log, and AI context all scoped per client, with a per-Space KMS key you can destroy on offboarding.

Free forever · No credit card · Per-Space KMS on Team+

ShellYard · Spaces

Client Spaces

  • Acme Corp 14
  • Globex Industries 8
  • Initech 22
  • Stark Labs 6
  • Wayne Mfg 11
  • Soylent Foods 9

Audit log

Acme Corp · last 24h
10:42 ssh.opened acme-prod-fw · sara@
10:44 vault.read cred:acme-fw-admin
10:51 bulk.exec 12 switches · ok
11:07 doc.edit runbook · MX firmware
CMK · acme-prod Export CSV

The MSP's bad day

The five things that cost you a client.

  • 1 One mistake, wrong client. A tech has Acme's terminal in window A and Globex's in window B. They paste the Globex root password into Acme's prompt. It's already in Acme's ~/.bash_history and the syslog server. By the time you notice, the audit trail belongs to the wrong tenant.
  • 2 The ~/.ssh/config forest. Forty hosts named prod-fw, prod-fw-2, acme-fw-real. Three jump-host chains. No two techs have the same file. Onboarding a new hire means rebuilding the file from a Slack thread.
  • 3 Five tools per client, none of them talk. IT Glue for docs, Termius for SSH, DBeaver for the database, Postman for the vendor API, a Bitwarden collection for the passwords. Every tab is a different mental model of "which client am I in right now."
  • 4 Onboarding by shoulder-surf. The new tech learns the client's network by sitting next to a senior. There's no canonical "here's Acme" document because nobody had time to write it down and the runbooks live in three places.
  • 5 Offboarding without proof. The contract ends. You "remove access." But what about the cached SSH key on the senior tech's laptop, the password manager entries that were never deleted, the docs export in someone's Downloads folder? You can't prove the data is gone — you can only assert it.

The ShellYard way

Spaces. The engagement in a tab.

  1. 1

    Create a Shared Space for the client.

    Name it "Acme Corp." That's it — a customer-managed KMS key is provisioned in our AWS account, scoped to this Space. Every connection, credential, document, IPAM entry, HTTP collection, and DB connection you create from here on lands in Acme's Space and nowhere else.

  2. 2

    Add your techs as members. Assign roles + Groups.

    Helpdesk gets read on Documents, no vault. Tier-2 gets the firewall credentials but not the AD service account. Owner gets everything. Module-level RBAC means a Group can be denied the Data Inspector entirely if you don't want them touching production databases.

  3. 3

    Work inside the Space. The whole toolkit comes with it.

    SSH, RDP, VNC, serial, SSM, the network toolkit, the HTTP / GraphQL / Realtime client, the six-engine database inspector, the IPAM, Magellan AI — all of it scoped to Acme. Switch to Globex and the workspace flips entirely. You cannot accidentally pull a credential from one Space into another.

  4. 4

    Offboard by destroying the key.

    When the contract ends, delete the Space (type-the-name confirmation). The per-Space CMK enters AWS KMS ScheduleKeyDeletion with a 7-day recoverable window. After that, every wrapped secret in the cloud — including in backups — becomes unrecoverable ciphertext. That's cryptographic erasure, and you can hand the client an audit-log CSV that proves the timeline.

What ships

Isolation that survives an audit.

Per-Space customer-managed KMS.

Team and Enterprise: every Shared Space gets its own AWS KMS CMK. Shared credentials wrapped with that key, KMS Decrypt authorized only for Space members, ScheduleKeyDeletion on offboarding = cryptographic erasure.

Group-scoped credentials + folder ACLs.

GROUPKEY narrows a shared credential to a Group inside the Space — Helpdesk sees the office Wi-Fi password, Tier-2 sees the firewall enable secret, the client never sees either. Module-level RBAC can deny entire surfaces by Group.

Per-Space audit log, CSV-exportable.

Every credential read, command run, document edit, HTTP request, DB query, and Magellan call is logged per Space with actor, action, target, timestamp, IP, and user-agent. Team and Enterprise export to CSV — that's your client-facing monthly report.

Magellan stays in the active Space.

BYO Anthropic / OpenAI / Gemini / Ollama key — prompts go direct to the provider, never proxied through us. The AI's context is scoped to the active Space, so Acme's runbooks never leak into a Globex prompt. Cross-Space context is opt-in only.

Compared to the MSP stack

The four things only a workbench gives you.

IT Glue Hudu ConnectWise ShellYard
Per-client KMS key with cryptographic erasure No — single tenant DB No — single tenant DB No Yes — per-Space CMK on Team+, ScheduleKeyDeletion on offboarding
SSH / RDP / VNC built in No — docs only No — docs only Via ScreenConnect (separate product) Yes — SSH, RDP, VNC, serial, Telnet, SSM in one app
Native cross-platform desktop (mac/Win/Linux) Web only Web only Mixed (web + Windows agent) Yes — notarized macOS, signed Windows, .deb/.rpm/AppImage
BYO-key AI assistant, scoped per client No No Vendor-hosted, no BYO key Yes — Anthropic / OpenAI / Gemini / Ollama, direct to provider

Already on IT Glue or Hudu? Team and Enterprise import both — Documents and IPAM in one shot per client.

Before you install

The questions a five-tech MSP asks first.

Is per-client KMS really a separate key per Space?
Yes. On Team and Enterprise, every Shared Space provisions its own AWS KMS customer-managed key in our AWS account. Shared credentials in that Space are wrapped with the Space's CMK, and KMS only authorizes Decrypt for members of that Space. When you offboard a client and delete the Space, the CMK is moved to ScheduleKeyDeletion (default 7-day recoverable window). Once the key is gone, the wrapped ciphertext is mathematically unrecoverable — that's cryptographic erasure.
Can our clients see their own Space?
Yes — invite them as a member of their Shared Space with the role you want (member, admin, or owner). They see only their Space, never any other client's. On Pro, you get one Shared Space plus two free guest seats. On Team and Enterprise, every non-owner consumes an org seat, but you get full Group-level ACLs (e.g. let the client see Documents/IPAM but not your operational runbooks).
We already use IT Glue / Hudu. Can we keep them while we evaluate?
Yes. Team and Enterprise ship bidirectional importers for both IT Glue and Hudu — Documents and IPAM (subnets, hosts) come across in one shot per client. You can run both in parallel for as long as you want. ShellYard's outbound side is a documented .shellyard-space.zip archive, so you're never locked in either way.
Pricing for a 5-tech MSP?
Five Team seats is $245/month — that's $49/seat/month for unlimited HTTP collections, all six database engines, Documents/IPAM, per-Space CMK, group ACLs, audit CSV export, and up to 25 Shared Spaces (one per client). If you need more than 25 clients, Enterprise at $99/seat lifts that to unlimited Spaces and adds per-Space audit filtering for client-facing reports. No setup fee, no per-Space charge, no "talk to sales" gate.
macOS, Windows, Linux — really all three?
All three, same desktop app, same Space data syncing across them. Signed and notarized on macOS (Apple Developer ID). Authenticode-signed on Windows via Azure Trusted Signing — first install may see a SmartScreen warning until reputation builds; click More info → Run anyway. Linux ships as .deb, .rpm, and AppImage.
Is ShellYard really NOT zero-knowledge?
Correct, and we're going to say it out loud: we are not zero-knowledge. The per-Space KMS keys live in our AWS account, not yours. We're protecting against the threats MSPs actually have — a stolen laptop, a former tech, an audit-log discovery request, an offboarding cleanup — and we use KMS access policy + EncryptionContext binding + audit logging to enforce per-Space isolation. If you need keys-in-your-own-AWS-account, that's an Enterprise conversation; the default is keys in ours.
What happens to a client's data when we offboard them?
Delete their Space (type-the-name confirmation; no accidental clicks). Cloud-side: members detached, resources deleted, audit row recorded, the per-Space CMK moved to ScheduleKeyDeletion. After the 7-day recoverable window the CMK is gone — every wrapped secret in that Space's cloud copy becomes unrecoverable ciphertext, including anything in backups. Metadata rows (connection names, document titles) are deleted as normal rows.

Spin up a Space for your next client engagement.

Install. Create a Personal Space to evaluate. When you're ready to invite the rest of the team, upgrade to Team for $49/seat — per-Space CMK, group ACLs, audit CSV, and up to 25 client Spaces come with it.

Free forever · No credit card · Per-Space KMS on Team+