For Managed Service Providers

One pane of glass for every client's access.

Stop chasing onboarding tickets and offboarding gaps across thirty clients. Define each position once, and JML keeps the roster and the proof — across every organization you manage. You do not replace their Entra.

Wholesale. Custom. No per-seat fees. Let's talk.

The reality

Access management at scale is a mess

You don't have an IAM problem. You have a thirty IAM problems at once problem.

Tribal knowledge in spreadsheets

Every client has a different onboarding doc, maintained by a different tech, last updated who-knows-when. New hires get whatever the last hire got — including their mistakes.

No HR-to-IT handoff

HR at the client decides someone got promoted. You find out three weeks later when a ticket arrives saying "why can't I see the new reports?" — or worse, when they still have old access they shouldn't.

Offboarding gaps are your liability

When a client's employee leaves and access lingers, the auditor doesn't blame the client — they blame the MSP. You need a paper trail that proves the leaver file was worked, when, and by whom.

Audit prep takes weeks

SOC 2, HIPAA, or insurance renewal. Pulling five random joiners and five leavers across 30 clients shouldn't take a sprint of screenshots and CSV exports.

Built for MSPs

Multi-tenant console, same product inside each client

Every feature in JML is designed to work across many client organizations from a single operator account.

Multi-tenant console

One JML login, every client org in a single switcher. Same product inside each client. No more juggling 30 admin consoles.

Reusable position packages

Define a 'Front-desk receptionist' or 'Senior accountant' package once, deploy to every client. Per-client overrides for the apps unique to them.

Joiner / mover / leaver files

Client HR marks someone as hired, promoted, or departed. JML opens the exact grant/revoke checklist — your techs execute in Entra, the EHR, and everywhere else, then confirm.

Your team operates it

Clients can log in to their tenant. You run the console. White-label logo per tenant is not live yet — your team is the face of the work.

Evidence packs per tenant

Every grant, revoke, and approval is timestamped and tied to a person, position, and request. Hand the auditor a pack, not a folder of screenshots.

You do not replace their Entra

JML is the roster and the proof. Their IdP and EHR still create and disable logins. You keep the file that shows it was done.

How it works

From onboarding chaos to a repeatable file

  1. Step 01

    Model each client once

    Import (or template) your client's positions and applications. JML becomes the canonical map of who-should-have-what.

  2. Step 02

    Let HR drive the changes

    Client HR triggers onboarding, role changes, and offboarding. JML opens the exact access checklist for your techs.

  3. Step 03

    Execute, confirm, audit

    Your team marks tasks complete in one queue. Techs still disable Entra and the EHR. Every action is timestamped — evidence-pack ready.

MSP wholesale

Wholesale. Custom. Let's talk.

Not per technician. Per managed tenant. You run a multi-tenant console; each client gets the same JML product. Rates are not on this page — email us and we set you up.

What's included

  • Multi-tenant console — same product in each client
  • Your team operates it; clients can log in to their tenant
  • Evidence packs per tenant for audits
  • Data-class tags (PHI, PI, financial) per system
  • You do not replace their Entra
  • Wholesale rates — not published. Let's talk.

Partner billing is not yet self-serve in the app. Email sales@usejml.com and we set you up.