Solutions · Agencies

Every client's stack, separated and checked the same way

Agencies run many stacks at once, often on the client's own provider accounts. Ahena keeps each client in its own organization, each app in its own project and each environment's credentials apart, so nothing leaks between clients.

The agency version of the problem

The same work, multiplied by every client:

  • Keys for many clients' providers end up in shared password vaults, spreadsheets and local files.
  • Each client's setup is slightly different, and remembering it lives in someone's head.
  • Handing a project over, or bringing a new developer in, means walking through every dashboard.
  • A client's production settings change and nobody notices until something breaks.

How the separation works

  1. Agency
  2. Client organization
  3. Project
  4. Environment
  5. Provider connections
  1. Organization per client

    Each organization has its own members, plan and activity log. People outside it can't even tell it exists: its ids return "not found".

  2. Project per app

    A client's apps are projects inside their organization, each with its own environments, connections and plans.

  3. Credentials bound to one environment

    Each provider credential is encrypted and bound to its organization, project and environment, so a copied value can't be decrypted anywhere else, and it's never shown back.

  4. Same checks everywhere

    Doctor, drift and ahena deploy-check work the same way for every project, so every client gets the same pre-release checks.

  5. Repeatable stacks

    Recipes (ahena recipe) give new projects a recommended stack to start from.

Good to know

  • Each organization is billed separately; one person can belong to many organizations.
  • Ahena manages the providers on its integration list. Client infrastructure on other platforms isn't managed.
  • Ahena connects to accounts you or your client own; it doesn't resell provider services.

Questions

How can an agency separate provider credentials between client projects?

Give each client its own Ahena organization and each app its own project. Credentials are stored per environment, encrypted and bound to that organization, project and environment, and never displayed, so one client's keys can't be used in another's project.