- 1 One mistake, wrong client. A tech has Acme's terminal in window A and Globex's in window B. They paste the Globex root password into Acme's prompt. It's already in Acme's
~/.bash_historyand the syslog server. By the time you notice, the audit trail belongs to the wrong tenant. - 2 The
~/.ssh/configforest. Forty hosts namedprod-fw,prod-fw-2,acme-fw-real. Three jump-host chains. No two techs have the same file. Onboarding a new hire means rebuilding the file from a Slack thread. - 3 Five tools per client, none of them talk. IT Glue for docs, Termius for SSH, DBeaver for the database, Postman for the vendor API, a Bitwarden collection for the passwords. Every tab is a different mental model of "which client am I in right now."
- 4 Onboarding by shoulder-surf. The new tech learns the client's network by sitting next to a senior. There's no canonical "here's Acme" document because nobody had time to write it down and the runbooks live in three places.
- 5 Offboarding without proof. The contract ends. You "remove access." But what about the cached SSH key on the senior tech's laptop, the password manager entries that were never deleted, the docs export in someone's Downloads folder? You can't prove the data is gone — you can only assert it.
One workspace per client.
Bulletproof isolation between them.
The day a tech pastes Globex's vault password into Acme's terminal is the day a contract ends. Spaces stop that cold — credentials, runbooks, audit log, and AI context all scoped per client, with a per-Space KMS key you can destroy on offboarding.
Free forever · No credit card · Per-Space KMS on Team+
Client Spaces
- Acme Corp 14
- Globex Industries 8
- Initech 22
- Stark Labs 6
- Wayne Mfg 11
- Soylent Foods 9
Audit log
Acme Corp · last 24hThe MSP's bad day
The five things that cost you a client.
The ShellYard way
Spaces. The engagement in a tab.
- 1
Create a Shared Space for the client.
Name it "Acme Corp." That's it — a customer-managed KMS key is provisioned in our AWS account, scoped to this Space. Every connection, credential, document, IPAM entry, HTTP collection, and DB connection you create from here on lands in Acme's Space and nowhere else.
- 2
Add your techs as members. Assign roles + Groups.
Helpdesk gets read on Documents, no vault. Tier-2 gets the firewall credentials but not the AD service account. Owner gets everything. Module-level RBAC means a Group can be denied the Data Inspector entirely if you don't want them touching production databases.
- 3
Work inside the Space. The whole toolkit comes with it.
SSH, RDP, VNC, serial, SSM, the network toolkit, the HTTP / GraphQL / Realtime client, the six-engine database inspector, the IPAM, Magellan AI — all of it scoped to Acme. Switch to Globex and the workspace flips entirely. You cannot accidentally pull a credential from one Space into another.
- 4
Offboard by destroying the key.
When the contract ends, delete the Space (type-the-name confirmation). The per-Space CMK enters AWS KMS ScheduleKeyDeletion with a 7-day recoverable window. After that, every wrapped secret in the cloud — including in backups — becomes unrecoverable ciphertext. That's cryptographic erasure, and you can hand the client an audit-log CSV that proves the timeline.
What ships
Isolation that survives an audit.
Per-Space customer-managed KMS.
Team and Enterprise: every Shared Space gets its own AWS KMS CMK. Shared credentials wrapped with that key, KMS Decrypt authorized only for Space members, ScheduleKeyDeletion on offboarding = cryptographic erasure.
Group-scoped credentials + folder ACLs.
GROUPKEY narrows a shared credential to a Group inside the Space — Helpdesk sees the office Wi-Fi password, Tier-2 sees the firewall enable secret, the client never sees either. Module-level RBAC can deny entire surfaces by Group.
Per-Space audit log, CSV-exportable.
Every credential read, command run, document edit, HTTP request, DB query, and Magellan call is logged per Space with actor, action, target, timestamp, IP, and user-agent. Team and Enterprise export to CSV — that's your client-facing monthly report.
Magellan stays in the active Space.
BYO Anthropic / OpenAI / Gemini / Ollama key — prompts go direct to the provider, never proxied through us. The AI's context is scoped to the active Space, so Acme's runbooks never leak into a Globex prompt. Cross-Space context is opt-in only.
Compared to the MSP stack
The four things only a workbench gives you.
| IT Glue | Hudu | ConnectWise | ShellYard | |
|---|---|---|---|---|
| Per-client KMS key with cryptographic erasure | No — single tenant DB | No — single tenant DB | No | Yes — per-Space CMK on Team+, ScheduleKeyDeletion on offboarding |
| SSH / RDP / VNC built in | No — docs only | No — docs only | Via ScreenConnect (separate product) | Yes — SSH, RDP, VNC, serial, Telnet, SSM in one app |
| Native cross-platform desktop (mac/Win/Linux) | Web only | Web only | Mixed (web + Windows agent) | Yes — notarized macOS, signed Windows, .deb/.rpm/AppImage |
| BYO-key AI assistant, scoped per client | No | No | Vendor-hosted, no BYO key | Yes — Anthropic / OpenAI / Gemini / Ollama, direct to provider |
Already on IT Glue or Hudu? Team and Enterprise import both — Documents and IPAM in one shot per client.
Before you install
The questions a five-tech MSP asks first.
Is per-client KMS really a separate key per Space?
Can our clients see their own Space?
We already use IT Glue / Hudu. Can we keep them while we evaluate?
Pricing for a 5-tech MSP?
macOS, Windows, Linux — really all three?
Is ShellYard really NOT zero-knowledge?
What happens to a client's data when we offboard them?
Spin up a Space for your next client engagement.
Install. Create a Personal Space to evaluate. When you're ready to invite the rest of the team, upgrade to Team for $49/seat — per-Space CMK, group ACLs, audit CSV, and up to 25 client Spaces come with it.
Free forever · No credit card · Per-Space KMS on Team+