This section takes you from “signed contract” to “fully deployed client”: creating the client’s workspace (or letting them register through your signup link), rolling out the Insightful agent across their machines with your RMM tooling, and confirming everything reports correctly. Each topic has its own page:
Adding a client — the two ways to bring a client into your portal.
Deploying the agent at scale — mass-installing the agent without client credentials.
Verifying the rollout with Deployment Health — confirming every machine reports, and catching broken installs.
Adding a client
This page explains the two ways to bring a client company into your Managed Service Partner (MSP) portal and helps you pick the right one for each client.
Which option you use depends on who should own the account and who runs the setup.
Option A — you create the workspace (recommended for managed rollouts).
From the portal, create the client’s organization yourself:
Go to your Clients tab and choose New organization → Create organization.
Enter the client’s company name and basic details (such as timezone).
Optionally, enter the email address of the client’s admin — they’ll be invited to their new workspace. You can also skip this entirely if the client should have no direct access at first.
Create. The workspace appears in your client list immediately.
Workspaces created this way are ready for agent deployment right away:
The in-app onboarding wizard is skipped — nobody at the client has to click through setup screens.
The workspace starts on a trial, so you can deploy and evaluate before activating a paid subscription.
Use this option when you run the rollout end to end and the client just consumes the result.
Option B — client self-signup link.
Share your unique signup URL and the client registers their own workspace, which is automatically attached to your portal:
In your Clients tab, choose New organization → Get signup link and copy your link.
Send it to your client (or embed it in your own onboarding materials).
The client opens the link, fills in the standard Insightful signup form, and their new workspace lands in your client list.
With this option the client owns their account and their admin login from day one, and they go through the normal onboarding experience. Use it when clients should be self-sufficient or when you’re onboarding many clients through a campaign.
Keep your signup link safe. The link is a standing invitation: anyone holding it can register a workspace under your portal. Treat it like a password:
Share it only with actual prospects and clients.
If it leaks, a campaign ends, or you simply want a fresh one, rotate it with Generate new link in the same dialog. Rotation takes effect immediately — every copy of the old link stops working with an “invalid or revoked signup link” error.
Comparing the two options:
| You create the workspace | Client self-signup |
Who owns the account | You (client admin optional, by invitation) | The client |
Onboarding wizard | Skipped — deployment-ready immediately | Normal signup experience |
Best for | Fully managed rollouts | Self-sufficient clients, signup campaigns |
Deploying the agent at scale
This page explains how to install the Insightful agent across a client’s entire machine park using your own RMM or software-distribution tooling.
Once a client workspace exists, the machines need the agent. As an MSP you don’t have to touch each machine or ask the client for credentials — the portal gives you an installer you can push through your own tooling.
How it works:
Open the client in Deployment Health and choose Add employees → Company computers
Download the installer for the client’s platform (Windows, macOS, or Linux), or copy the installation URL — a link valid for 48 hours that downloads that client’s pre-configured installer.
Feed the installer to your RMM / software-distribution tool and push it to the client’s machine park.
Machines install silently and start reporting into the client’s workspace automatically — the installer is bound to that specific client, so nothing can end up in the wrong workspace. Employees show up on your dashboard after installation, with no sign-ups required.
No client credentials are involved at any point: the download link itself authorizes the installer download. That is exactly what makes it suitable for unattended mass deployment.
Security of the installation link:
The link is valid for 48 hours and cannot be revoked early — while it’s live, treat it like a secret. Don’t post it in shared channels or ticket systems with broad access.
When it expires, simply generate a fresh one; there’s no limit on how often you can do this.
Only Admins and IT Managers can generate installation links.
Good to know:
Generate the link per client — each link produces that client’s installer only.
Verifying the rollout with Deployment Health
This page explains how to read the Deployment Health dashboard — your tool for confirming a rollout succeeded and for catching broken installs afterwards.
Deployment Health is your fleet dashboard: for any client, it shows one row per employee with everything you need to know about their devices and agent status.
What each row shows:
Every device the employee reports from: computer name, agent version, operating system version, last received data, and whether the device is online right now.
Whether the operating system has denied the agent any required permissions on a device.
When the employee first and most recently reported data.
Whether the employee is currently on approved time off.
An overall health status — the quickest signal of all.
The three statuses:
Status | Meaning |
Healthy | The agent reported within the last 24 hours and has no permission problems. |
Stale | No data for more than 24 hours, or the agent is reporting but the operating system has denied it required permissions on some device. |
Inactive | The employee is deactivated, was invited but never installed, has never reported any data, or has reported nothing for 7+ days. |
Two built-in rules keep the signal honest:
Time off doesn’t raise alarms. If an employee has approved time off overlapping the last 24 hours, a data gap alone won’t mark them Stale — vacations are not broken installs. (A permission problem still shows, since it needs fixing regardless.)
Dead beats misconfigured. An employee who stopped reporting entirely stays Inactive even if their devices also have permission problems — the more severe condition wins, so your attention goes where it matters.
How to use it in practice:
Right after a rollout: open the client in Deployment Health and confirm every expected employee shows up as Healthy. Anything Inactive with “no data ever” usually means the installer didn’t reach that machine.
Ongoing: check the dashboard regularly (or after OS updates at a client, which commonly reset agent permissions). Stale rows with permission issues mean the agent runs but can’t capture everything — fix the OS permissions on the affected device.
Who can see it: Admins, IT Managers, and Productivity Managers (for their assigned clients). Finance Managers have no access.
Everything in Deployment Health works from the portal directly — you never need to enter the client’s workspace to monitor a rollout.
This article covers the Insightful Partner Portal (for MSPs managing client workspaces), not the standard Insightful application.
