INNOVEXUS
Solution · MSP PAM

PAM for MSPs. Free.Per-client appliance isolation. Real audit. No enterprise quote.

Most MSPs serving small and mid-market clients can't afford enterprise PAM contracts — and shouldn't. CyberArk and BeyondTrust price for hundred-million-dollar MSPs, not for a 5-engineer team running 20 client networks. Innovexus is built for that scale: self-hosted appliances give each client genuine isolation, the platform is free and open source — no licence key, no seat count, no per-client subscription — and the audit trail is auditor-ready for client compliance reviews.

§ 01 / The problem

MSP PAM economics have always been broken.

MSPs serving SMB and mid-market clients face a structural problem: enterprise PAM is priced for the customer's spend, not the MSP's margin. The economics force compromises that hurt clients and the MSP.

/ 01

Per-client PAM is unaffordable.

CyberArk or BeyondTrust at $30K+/yr per client deployment is impossible at MSP margins. The math doesn't work for clients paying $5K–$30K/yr for managed services. Most MSPs end up using shared internal credentials across clients — a compliance disaster the moment one client is audited.

/ 02

Multi-tenant SaaS PAM mixes client data.

Some MSP-edition PAM products use shared infrastructure with logical tenant separation. For regulated clients (healthcare, finance, government-adjacent), this is an audit problem — clients want to know their credentials live on isolated infrastructure, not in a shared vault that other MSP customers can access if a tenancy boundary fails.

/ 03

Engineer churn breaks credential hygiene.

Most MSPs have engineers come and go every 12–18 months. Without a real PAM tool, departing engineers retain knowledge of client credentials in personal notes, password managers, and memory. The cleanup is manual and rarely complete.

/ 04

Client audits ask the wrong questions for the MSP's tooling.

When a client passes through a SOC 2 audit, the auditor asks "how does your MSP attribute privileged access into your environment?" — a question the MSP's spreadsheet-and-1Password setup cannot answer. The MSP loses the engagement or scrambles for emergency tooling.

§ 02 / How Innovexus solves it

One appliance per client. Sized for MSP economics.

Innovexus's self-hosted appliance model fits MSPs naturally: each client gets their own appliance with isolated credentials, isolated audit, isolated infrastructure. The MSP deploys one free appliance per client — no licence, no subscription, no per-client fee; the only cost is the infrastructure the appliance runs on. Each appliance's audit trail stays with the client — when the engagement ends, the client retains evidence; when a new engagement starts, the appliance starts clean.

/ 01

Your own appliance per client

Each MSP client gets a separate self-hosted appliance with isolated compute, vault, and audit infrastructure. No shared storage, no logical-only tenancy boundaries, no risk of cross-client data exposure. Clients in regulated sectors get audit-ready isolation evidence on day one.

/ 02

Zero licence cost fits MSP margins

The full platform is free at every fleet size — SMB clients, mid-market clients, and the larger ones all run the same appliance with no device caps, no seat counts, and no feature gates. The MSP's only cost per client is the compute the appliance runs on, so PAM stops being a line item that has to be recovered in the client's bill.

/ 03

MSP-engineer attribution across all clients

MSP engineers carry one set of FIDO2 hardware keys. Per-client appliances authorise the engineer's identity for the assets they're permitted to reach. The MSP's engineer roster is centrally managed; per-client access scopes are enforced at the appliance. One engineer offboard removes access across every client appliance simultaneously.

/ 04

Client-handover-clean audit trail

When the MSP engagement ends, the client receives the full audit trail for the engagement period — every session, every credential access, every config change. The appliance can be transferred to the client's direct ownership or decommissioned. The handover is itself an audit artefact for the client's SOC 2 / ISO 27001 review.

/ 05

Bundled NOC + SOC alongside PAM

Each client appliance includes the NOC and SOC workspaces alongside PAM. For MSPs that also provide network monitoring or security operations, this consolidates three vendor relationships into one. The MSP's service offering tightens; the client's vendor count shrinks.

§ 03 / How it works in practice

MSP setup, in plain language.

Most MSPs onboard their first 5 clients within the first month. Here's the actual sequence and where the operational discipline matters.

  1. 01

    Size the appliance per client

    Inventory each client's device count and feature needs. Every client runs the same free appliance — there is no tier to choose. Download the OVA from innovexus.io/downloads (a free account is all that's required) and size the VM resources to the client's fleet. The MSP prices its managed service on the value delivered; there is no Innovexus licence line item to pass through.

  2. 02

    Provision per-client appliances

    Each client gets their own appliance, provisioned in the MSP's account. Appliances are administratively separated — engineer access is granted per-client based on the engagement scope. The MSP can manage 5 or 50 client appliances from one engineer console.

  3. 03

    MSP engineer onboarding

    MSP engineers receive FIDO2 hardware keys (YubiKeys typically) at hire. Their identity is enrolled once in the MSP's identity provider, then mapped to per-client appliances based on the engagement assignment. New client signed = engineer added to that appliance's access scope; engineer departs = access removed across every appliance simultaneously.

  4. 04

    Client onboarding workflow

    For each new client, vault their device credentials, configure baseline collection on their network gear, set drift alert thresholds appropriate to the client's change cadence. Most client onboardings take 2–4 hours of engineer time; some need a week for larger fleets.

  5. 05

    Audit handover at engagement end

    When an MSP engagement ends, the per-client audit trail belongs to the client. Export the full audit bundle, transfer appliance ownership to the client (or decommission). The handover is documented and itself an audit artefact for both parties.

§ 04 / Other approaches, honestly

How this compares to other approaches.

MSP PAM has a few common patterns. Honest read on each.

BeyondTrust PRA / Bomgar for MSPs
Industry-standard, expensive

BeyondTrust PRA is widely used by MSPs for privileged remote access into client environments. Capability is strong, especially for vendor-style remote support. Trade-offs: enterprise pricing typically lands at $20K+/yr starting; multi-year contracts; built primarily for the larger end of the MSP market. Best fit at MSPs with 50+ clients and the budget for enterprise PAM tooling.

Delinea / ManageEngine MSP editions
Multi-tenant, scales further

Delinea (Secret Server MSP edition) and ManageEngine PAM360 MSP edition use shared-infrastructure multi-tenancy with logical client separation. They scale to MSPs serving hundreds of clients more efficiently than self-hosted appliance models. Trade-offs: shared infrastructure is harder to evidence to regulated clients; pricing varies. Better fit at very large MSPs (200+ clients) where self-hosted appliances become operationally heavy.

Shared 1Password / Bitwarden vault
What most small MSPs actually use

A shared password manager with team folders per client. Free or cheap, fast to set up. Trade-offs: no session recording, no automated rotation, weak attribution, no client-owned audit trail at engagement end. Compliance review by any client of any sophistication finds gaps immediately. Works for small MSPs with low-compliance clients; doesn't scale to regulated clients.

Connectwise / Kaseya / Datto PAM modules
Bundled with RMM

Some RMM platforms include credential vaulting. Capability is limited compared to dedicated PAM tools. Convenient if the MSP already runs the RMM. Trade-offs: no dedicated session recording, weaker audit trail, multi-tenant with logical separation. Acceptable for low-stakes engagements; insufficient for regulated client work.

Solution · MSP PAM · FAQ

Common questions

Direct answers to the questions teams ask when evaluating this workflow.

01

How many clients can one MSP manage on Innovexus?

Operationally, the self-hosted appliance model is clean up to ~50 client appliances managed by one MSP. Above 50, the operational overhead of appliance-by-appliance administration starts to compete with shared-infrastructure MSP editions of Delinea or ManageEngine. Most MSPs in our customer base run 5–30 client appliances. We have a few running 40–50 efficiently. If you're running 100+ clients today, BeyondTrust or Delinea's MSP editions are likely the better operational fit and we'll say so on a discovery call.

02

Can MSP engineers manage credentials across all client appliances from one console?

Yes. The MSP carries one engineer identity (one FIDO2 hardware key) that authorises across every appliance the engineer is assigned to. The console shows all assigned client appliances with per-client device discovery, session brokering, and audit. There is no per-appliance login dance — the hardware key authenticates once and the role policy at each appliance controls access scope.

03

How does cost scale for an MSP serving 20 clients?

Innovexus licensing for 20 clients costs exactly what it costs for one: nothing. There is no licence, no seat count, and no per-client fee — the MSP's only cost is the compute for 20 self-hosted appliances, typically a small VM per client on infrastructure the MSP already runs. For comparison, a single CyberArk MSP deployment for one similar-sized client typically runs $30K+/yr — spend that Innovexus eliminates across the entire portfolio.

04

What happens to the audit trail when a client engagement ends?

The audit trail belongs to the client, not the MSP. At engagement end, the MSP runs a documented handover: full audit export delivered to the client, appliance transferred to the client's direct ownership or decommissioned per the client's preference. The handover is itself an audit artefact (signed by the appliance's identity key) that proves the engagement boundary cleanly. Both parties retain the export for their own records.

05

Can the MSP white-label Innovexus to clients?

White-labelling at the platform UI level is on the roadmap but not currently shipped. What we do support today: clients see a per-client subdomain at their appliance, the MSP's name appears on engineer attribution in the audit trail, and the MSP's logo can be added to exported audit bundles. For full UI rebranding ("Innovexus" replaced with the MSP's product name), the platform is open source at github.com/Innovexus/agents — rebrand in your own fork, or open a discussion on GitHub if you want to coordinate with the project.

06

How does this handle clients who already have their own PAM?

Co-existence is fine. Many MSPs serve clients where the client owns their PAM (e.g., the client runs CyberArk for their internal team and the MSP needs privileged access into a subset of systems). The MSP's Innovexus appliance handles MSP-engineer access; the client's PAM continues to handle their internal team. The boundary is clear: MSP audit trail in Innovexus, client audit trail in their tool, both can be reconciled for compliance reviews.

Stop doing PAM with a shared password manager. Per-client appliances, MSP economics.

FREE · OPEN SOURCESELF-HOSTED

Download the free appliance from innovexus.io/downloads, start with one client, and see if the self-hosted model fits how your team actually works. Add more clients as you go — no trial clock, no per-engineer lock-in, no enterprise contract, no cost at all.