Agency mode

Clients, staff, support access, and branding

Provision client workspaces, copy safe configuration, deliver setup links, manage agency staff, and apply default or client specific branding.

Agency Admins use Agency → Clients to provision and support client workspaces. Agency Staff can read the roster where allowed, but provisioning, support access, setup link delivery, and branding controls remain Admin operations.

Provision a client workspace

Select New client tenant and provide:

  • Client name
  • First administrator email
  • An optional source workspace to copy configuration from

Choose Start fresh to use the new workspace defaults. To use a repeatable setup, select the agency home workspace or an existing client as the source.

Template provisioning copies modules, branding, and settings. It does not copy users or business data. This is important when using an existing client as the source because their contacts, invoices, payroll, and other records must remain isolated.

Deliver the first administrator setup

After provisioning, agaro shows the set password link for the first administrator and attempts the configured branded delivery path. The link is single use and expires after seven days.

Copy the link from the completion dialog if direct delivery failed or the client needs another secure channel. Do not paste it into a public ticket. The roster shows Resend while setup remains pending, and an Agency Admin can issue another delivery.

The first administrator should complete password setup, sign in, enroll two factor authentication if required, and verify the workspace name before adding data.

Open a client for support

Select Access on the client row and review the confirmation. The dashboard switches to the client's workspace context.

Before any mutation:

  1. Confirm the workspace name and account number.
  2. Confirm the client requested the change.
  3. Make the smallest necessary change.
  4. Review the resulting activity history.
  5. End the support context when finished.

Agency support access does not grant authority beyond the supported agency and target client.

Invite agency staff

Open Agency → Staff and select Invite staff. Configure:

  • Email address
  • Agency role, Admin or Staff
  • Workspace role, Manager, Employee, or Viewer
  • Optional permission sets
  • Expiration, 24 hours, 7 days, or 30 days

The result includes a single use invitation link. agaro attempts to send the invitation email and also lets you copy the link. Pending invitations can be resent.

Pending live invitations reserve staff capacity. Creating repeated invitations to the same address does not create unlimited extra reservations.

Manage agency roles

Use the role control on the staff roster to promote or demote a member. The owner cannot be removed or demoted from Admin. An agency must retain at least one Admin.

Removing a member revokes their agency membership. If you remove yourself and are not the owner or last admin, you leave the agency surfaces immediately.

Set agency default branding

Open Agency → Branding to define the agency identity applied through the branding cascade. Supported fields can include the application name, logo, mark, primary colors, tagline, support identity, and email sender presentation.

Use publicly reachable HTTPS image URLs or approved same origin brand assets. Unsafe URL schemes and protocol relative values are rejected.

Branding applies to interface and supported emails. It does not change the legal identity of agaro or create a physical office or registration for the agency.

Override one client's branding

From the client roster, select Branding for a client. A client override takes precedence over the agency default for that workspace. Leave a field unset when the client should inherit the agency value.

Use client overrides for a specific logo, name, or color set. Keep common agency support identity at the agency level so future clients inherit it consistently.

Authentication emails

Open Agency → Branding → Authentication Emails to manage supported branded authentication communication for the agency context. Workspace level authentication email settings also exist for individual workspaces.

Keep invitations, activation, password reset, verification, and login alert messages clear. Do not remove the security purpose, expiry facts, or destination action from a template in favor of promotional copy.

Troubleshooting

Provisioning says the plan capacity is full

Agency Starter allows up to 10 client workspaces. Upgrade to Agency Growth for unlimited client workspaces. Staff admission is also capped by the plan's staff capacity.

The first admin did not receive email

Use Resend while setup is pending and copy the displayed single use link through a secure channel. Review authentication email delivery configuration if repeated sends fail.

Copy from template skipped modules

The target client must be allowed to receive each module. Plan, paid add on, catalog, or agency policy restrictions can cause a module to be skipped. The provisioning result reports skipped modules.

Branding saved but the old brand remains

Reload the client surface and confirm whether a more specific client override exists. Client branding takes precedence over the agency default.

A staff member cannot open a client

Support access is an Agency Admin operation. Also verify the person's workspace role and permission sets for the target capability.