Service Provider to Service Provider Delegation and Inventory Management
Applies To: WatchGuard Cloud
This feature is available only to participants in the WatchGuard Cloud Beta program.
This topic is for Service Providers that want to manage inventory across delegated Service Provider accounts. Review this topic for information on different inventory models and implications for ownership, billing, reporting, and operational control requirements.
Overview
Service Provider to Service Provider delegation in WatchGuard Cloud enables tier-1 Service Providers to manage the inventory for another Service Provider account, as well as the inventory of any accounts they manage. The tier-1 or tier-n Service Provider account that delegates access to their account is called the delegated account. The tier-1 Service Provider that receives access to the delegated account becomes the parent account.
Service Providers can only manage a delegated account in the same cloud region as their account.
Multi-Tier Management in WatchGuard Cloud
WatchGuard Cloud is a multi-tenant, multi-tier system. Each Service Provider account can create and manage customer accounts in up to five tiers or levels (for example, tier-1 Service Provider > tier-2 Service Provider > tier-3 Service Provider > tier-4 Service Provider, tier-5 Subscriber). In the case of Service Provider to Service Provider delegation, when the delegated account manages multiple levels of accounts, the number of tiers that the parent Service Provider can access is still limited to a total of five tiers.
Inventory Management for Delegated Service Provider Accounts
Delegation provides centralized visibility and operational control, while each account remains independent. Delegation does not automatically merge accounts or inventory. Both Service Provider accounts (parent and delegated account) continue to exist, retain their configurations, and maintain ownership of their existing licenses.
Before you allocate inventory to a delegated Service Provider, determine where license ownership, billing responsibility, usage reporting, and operational control should reside. Discuss existing business rules with the delegated Service Provider to make sure that allocations from the parent Service Provider to Subscriber accounts within the account hierarchy adhere to existing rules.
Choose the delegated management model that meets your joint business needs:
Independent Ownership
With the independent ownership model, the parent Service Provider manages only security configurations for the delegated Service Provider; they do not manage the inventory of the delegated account. Each Service Provider retains ownership of its own licenses, manages its own renewals, and reports usage separately. The delegated Service Provider operates as an independent business entity and requires full control over their own license procurement, renewal cycles, and customer billing.
Key Characteristics
- License ownership remains with the account that purchased the license.
- Each account manages its own inventory, renewals, and compliance.
- Usage reporting remains local to each account and is not aggregated.
When a license is purchased and activated, it automatically appears in the corresponding account in WatchGuard Cloud. When the license is activated by the delegated Service Provider, they retain control of the license and inventory management. Licenses that are owned by the delegated account are not included in cumulative usage reporting. Usage remains local to the delegated account.
Centralized Inventory Management
In addition to central management of security configurations, Service Provider to Service Provider delegation can be used to centrally manage licenses and allocations. In the centralized inventory management model, the parent Service Provider owns the licenses and allocates inventory to the delegated Service Provider. The parent Service Provider can view cumulative usage reporting across the entire managed hierarchy of accounts.
Key Characteristics
- Licenses are owned and managed by the parent account.
- Inventory is centrally allocated to delegated accounts.
- License usage rolls up to the parent Service Provider.
- Consolidated reporting and operational control at the parent Service Provider level.
Supported Licensing for Centralized Inventory Management
This table describes each licensing scenario and when it is possible to centralize inventory for a product in the parent account.
|
Parent Service Provider License |
Delegated Service Provider License |
Can Centralize Licenses and Inventory in the Parent Account? |
|---|---|---|
|
Term |
Term |
Yes. Activate all term licenses in the parent Service Provider account. For devices, a transfer of ownership is required to manage them in a single account. For more information, go to Transfer of Ownership for Fireboxes and Access Points. |
|
Term |
MSSP Points |
Yes. Allocate users or endpoints from term licenses (including term licenses purchased with MSSP Points) to all managed accounts from the parent Service Provider account. |
|
Term |
Subscription |
No. Before you can centralize licenses in the parent account, the parent Service Provider account requires a subscription license. |
|
MSSP Points |
Term |
Yes. Allocate users or endpoints from licenses purchased with points to the subscriber accounts in the delegated Service Provider account. |
|
MSSP Points |
MSSP Points |
Yes. For more information, go to Transition to Centralized Inventory Management. |
|
MSSP Points |
Subscription |
No. Before you can centralize inventory and use points for all accounts, you must activate a subscription license in the parent Service Provider account or remove the subscription license from the delegated Service Provider account. |
|
Subscription |
Term |
Yes. Allocate users or endpoints from subscription licenses to the delegated Service Provider account when the term licenses expire. To avoid disruption of service, make sure to allocate subscription users or endpoints to the delegated Service Provider account before the expiration date. |
|
Subscription |
MSSP Points |
Yes. Allocate subscription users or endpoints to Subscribers in the delegated Service Provider account before licenses from the MSSP Points expire. Monthly licenses purchased with MSSP Points expire on the last day of the month. |
|
Subscription |
Subscription |
Yes. Allocate subscription users or endpoints to Subscribers in the delegated Service Provider accounts to manage all Subscription licenses from the parent Service Provider account. |
Transition to Centralized Inventory Management
If your inventory management model is currently independent ownership, you can transition to centralized inventory management with Subscription licenses or MSSP Points owned by the parent Service Provider.
In these procedures, the parent Service Provider allocates users or endpoints to the delegated Service Provider from a license owned by the parent Service Provider.
Caution: To avoid service disruption, the parent Service Provider must make sure that there is sufficient inventory to cover usage in their account, the delegated account, and any accounts managed by the delegated account. For information on allocation and usage, refer to the Allocation and Usage Report .
To transition to centralized license management of Subscription licenses, in WatchGuard Cloud:
- Select Overview > Inventory.
- On the Allocation page for a specific product, allocate users or endpoints from a Subscription license to the delegated Service Provider account. For more information, go to Allocate Devices, Users and Endpoints in WatchGuard Cloud.
- (Optional) When subscription users and endpoints have been allocated from the parent Service provider to all of the Subscribers in the delegated Service Provider account, you can cancel the delegated Service Provider's subscription contract.
To transition to centralized license management of point-based licenses, in WatchGuard Cloud:
- Select Overview > Inventory.
- On the Allocation page for a specific product, allocate users or endpoints from a license purchased with MSSP Points to the delegated Service Provider account. For more information, go to Allocate Devices, Users and Endpoints in WatchGuard Cloud.
- Confirm that there is sufficient inventory allocated to the delegated Service Provider to cover the usage required by the delegated account and accounts it manages.
Overallocation occurs when more users or endpoints are allocated than there are available in the inventory. For information overallocation, go to Inventory Overallocation in WatchGuard Cloud.
- Log in to the delegated Service Provider's WatchGuard Cloud account.
- On the Inventory > Allocation page, edit the allocation quantity from the delegated Service Provider's license to 0. For more information, go to Deallocate Inventory.
The delegated Service Provider account now relies on inventory allocated from the parent Service Provider's license. - In MSSP Command, stop new usage in the delegated Service Provider account. For more information, go to Manage MSSP Services in MSSP Command Help.
- (Optional) To consolidate points, request a refund or transfer of points from the delegated Service Provider to the parent Service Provider. For more information, contact your WatchGuard representative.
If the delegated account revokes Service Provider access, any licenses allocated by the parent Service Provider are removed from the delegated account, and usage reporting reverts to the delegated account.
Transfer of Ownership for Fireboxes and Access Points
Devices that were activated in a delegated account remain in that account. You cannot transfer these licenses to another Service Provider. To consolidate Firebox or access point inventory in the parent Service Provider account, you must transfer ownership of each device. This process removes existing configuration and requires reconfiguration. For more information about the transfer of ownership process, go to the Transfer of Ownership knowledge base article.
To manage these devices without transfer of ownership, you could create an operator in the delegated account and use that account to manage device licenses and configuration. For information on how to create an operator, go to Add Operators to Managed Accounts.
Hybrid Inventory Management
In between the independent ownership and centralized inventory management models, there is a scenario where both Service Providers — the parent and the delegated accounts — need to manage inventory independently. For example, hybrid inventory management could occur when the parent Service Provider allocates Subscription licenses to the delegated account for centralized operations, while the delegated account continues to manage its own inventory through its own Term licenses. Hybrid inventory management can also be one step in the transition from independent ownership to centralized inventory management.
With hybrid inventory management, the parent Service Provider can view cumulative usage reporting for the licenses they allocate to the delegated Service Provider. Licenses that are owned by the delegated account are not included in cumulative usage reporting. Usage remains local to the delegated account.