Wholesale · multi-tenant
Running gateways for operators who are not you

Many operators, one platform,
nobody sharing a console.

You get a super-admin account on a platform we operate — and it is bounded to your gateways, your subscribers and your alerts. Underneath that, you can do the same for the local operators and subscribers who depend on you.

A shared platform is only acceptable if the sharing is structural. Convenience is a nice reason to use one; not being able to see anybody else is the reason you can.

9
operators on one deployment
80
gateways, each owned by exactly one
302,761
live sessions across them
3
tiers: the platform, you, your subscribers

Three tiers, and they must not see the same thing

We host and operate NOC2; you sign in to it as super admin over your own estate; your subscribers get a portal of their own. Three surfaces, three jobs, and the boundaries between them are enforced rather than remembered.

Three audiences on one platform The platform owner sees every operator and every gateway. Each operator's staff see only their own gateways and subscribers. Each operator's subscribers see only their own connection, through a portal on their operator's own address. THE PLATFORM — we run it hosting, upgrades, collectors so you do not run a NOC tool never in your traffic path YOU — super admin your gateways only your subscribers, your alerts full control, bounded estate THEIR SUBSCRIBERS one connection — their own usage, tickets, outages a separate portal Each surface answers to a narrower question than the one to its left. You must not be able to infer that the platform has other operators on it, how many, or how they are doing — and neither must they, about you. On a shared platform that is not a preference; it is the whole basis of using one. Scoping is resolved in one place, so a new page cannot quietly widen it.

A tenant is an operator, and it owns things

Each operator on the platform is a first-class account rather than a label attached to some servers. Gateways belong to exactly one of them, and everything downstream of that — sessions, alerts, capacity, reports — inherits the same boundary.

NOC2 customers page listing operator accounts, each with contact details and an active status.
Nine operators on one deployment. Each has its own account, its own contacts and its own status. Adding one is an administrative act, not a re-deployment — and the gateways assigned to it immediately stop being visible to everyone else.

What each operator gets to control

Per operatorWhat it means
Its own gatewaysEvery gateway is owned by one operator. Their staff see those and nothing else — in lists, in searches, in alerts and in every figure computed from them.
Its own staff loginsAccounts scoped to that operator, with roles from the same permission set you use. A user can also be assigned to more than one operator where that is genuinely wanted.
Its own subscriber portalA separate sign-in for their end customers, at their own address, showing one subscriber their own connection.
Its own status pageA public page for their customers, which can be switched on or left off per operator.
Its own identityLogo and welcome text on the surfaces their customers see, so the page reads as theirs rather than as yours.
Its own change policyA per-operator threshold for how much change requires approval — a cautious wholesale customer can be cautious without imposing it on the others.
Its own reportingA weekly digest per operator, and a currency per operator for anything with money in it.

The surface their subscribers actually touch

This is the part wholesale platforms usually lack entirely, and it is the one your operator's marketing department will ask about first.

The subscriber portal sign-in page: a simple username and password form.
A subscriber portal, per operator, on their own address. Behind it a subscriber sees their own usage, their own tickets, and whether there is a known problem affecting them — and nothing about the operator's other subscribers or about the network underneath. It is deliberately plain: it is the only screen in the system designed for someone who does not work in a NOC.

An operator beneath an operator

Some wholesale structures are two layers deep: a regional ISP holds the commercial relationship, and local operators sit beneath it serving their own subscribers. The tenant model handles this directly — an operator can be recorded as the parent of another, and an administrator at the parent can see the child's estate while the child sees only its own.

The hierarchy is one level deep by design. Parent sees child; it does not walk an arbitrary tree. We would rather state that plainly than let you design a four-tier reseller programme around an assumption. If your structure is deeper than that, tell us before you sign anything.

Why isolation has to be structural

Filtering at the page

Each screen remembers to apply the operator filter. It works — until someone adds a screen, an export, a report or a search, and forgets.

The failure is silent and it is discovered by the customer who was shown someone else's network.

Resolving in one place

"Which gateways may this account see" is answered by a single authority that every query goes through, rather than re-implemented per page.

A new screen inherits the boundary because there is no other way for it to obtain the list in the first place.

What it changes commercially

No NOC to build

Operations without an operations team

Collectors, alerting, retention and upgrades are ours to run. You get the console on day one instead of a six-month project to stand one up.

Pass it downstream

Give your operators the same deal

Local operators beneath you get their own bounded view rather than screenshots from your staff — and your support desk stops being the only way they can learn anything.

Sell their brand

Their customers see them

The portal and status page carry the operator's identity. You supply the network; they keep the relationship — which is usually the condition of them buying at all.

The bottom line

The question to ask about any shared platform is not whether it has permissions. Everything has permissions. It is whether the boundary is resolved in one place or re-implemented on every screen — because the second kind fails exactly once, and it fails in front of the operator least willing to forgive it.

Nine operators run on this platform today, across eighty gateways carrying just over three hundred thousand live sessions, and each of them signs in to a console that contains only their own.

About the screenshots. Every screen shown is a real production console. Operator names, contact names, contact details, gateway hostnames and site names are all replaced with placeholders before the image is taken; no real operator, person, site or subscriber identifier appears in any image.