You get a super-admin account on a platform we operate — and it is bounded to your gateways, your subscribers and your alerts. Underneath that, you can do the same for the local operators and subscribers who depend on you.
A shared platform is only acceptable if the sharing is structural. Convenience is a nice reason to use one; not being able to see anybody else is the reason you can.
We host and operate NOC2; you sign in to it as super admin over your own estate; your subscribers get a portal of their own. Three surfaces, three jobs, and the boundaries between them are enforced rather than remembered.
Each operator on the platform is a first-class account rather than a label attached to some servers. Gateways belong to exactly one of them, and everything downstream of that — sessions, alerts, capacity, reports — inherits the same boundary.
| Per operator | What it means |
|---|---|
| Its own gateways | Every gateway is owned by one operator. Their staff see those and nothing else — in lists, in searches, in alerts and in every figure computed from them. |
| Its own staff logins | Accounts scoped to that operator, with roles from the same permission set you use. A user can also be assigned to more than one operator where that is genuinely wanted. |
| Its own subscriber portal | A separate sign-in for their end customers, at their own address, showing one subscriber their own connection. |
| Its own status page | A public page for their customers, which can be switched on or left off per operator. |
| Its own identity | Logo and welcome text on the surfaces their customers see, so the page reads as theirs rather than as yours. |
| Its own change policy | A per-operator threshold for how much change requires approval — a cautious wholesale customer can be cautious without imposing it on the others. |
| Its own reporting | A weekly digest per operator, and a currency per operator for anything with money in it. |
This is the part wholesale platforms usually lack entirely, and it is the one your operator's marketing department will ask about first.
Some wholesale structures are two layers deep: a regional ISP holds the commercial relationship, and local operators sit beneath it serving their own subscribers. The tenant model handles this directly — an operator can be recorded as the parent of another, and an administrator at the parent can see the child's estate while the child sees only its own.
The hierarchy is one level deep by design. Parent sees child; it does not walk an arbitrary tree. We would rather state that plainly than let you design a four-tier reseller programme around an assumption. If your structure is deeper than that, tell us before you sign anything.
Each screen remembers to apply the operator filter. It works — until someone adds a screen, an export, a report or a search, and forgets.
The failure is silent and it is discovered by the customer who was shown someone else's network.
"Which gateways may this account see" is answered by a single authority that every query goes through, rather than re-implemented per page.
A new screen inherits the boundary because there is no other way for it to obtain the list in the first place.
Collectors, alerting, retention and upgrades are ours to run. You get the console on day one instead of a six-month project to stand one up.
Local operators beneath you get their own bounded view rather than screenshots from your staff — and your support desk stops being the only way they can learn anything.
The portal and status page carry the operator's identity. You supply the network; they keep the relationship — which is usually the condition of them buying at all.
The question to ask about any shared platform is not whether it has permissions. Everything has permissions. It is whether the boundary is resolved in one place or re-implemented on every screen — because the second kind fails exactly once, and it fails in front of the operator least willing to forgive it.
Nine operators run on this platform today, across eighty gateways carrying just over three hundred thousand live sessions, and each of them signs in to a console that contains only their own.
About the screenshots. Every screen shown is a real production console. Operator names, contact names, contact details, gateway hostnames and site names are all replaced with placeholders before the image is taken; no real operator, person, site or subscriber identifier appears in any image.