A portal is not a law firm
MSPs want a privacy SKU without building case software. Fair. ScopeMantle can skin intake, send from a domain the client chooses, and pre-fill vendors from that client's OAuth inventory. That is operations. It is not a lawyer. If your one-pager implies otherwise, rewrite it before the first subject letter goes out.
Client counsel owns legal text. Analysts draft. A checkbox in the case must be false until counsel (or a named delegate) approves send. Operator templates come from the DSAR playbook. Same disclaimer: not lawyer-reviewed.
1. Intake
Subject submits. Case ID generated. Inventory snapshot attaches automatically from that tenant's Google and Okta grants. MSP queue is multi-tenant. Segregation is your SOC story. Audit it. Annually is the minimum I would write in an SOW.
2. Vendor outreach
Articles 15, 17, 20 as starting points. Track replies. Escalate on the playbook clocks, adapted for the client's jurisdiction. India is not GDPR. See DPDPA checklist.
Erasure: you or the client revokes the grant. A letter without revoke is theater you will own in the QBR.
3. Branding and deliverability
MSP logo on the portal. Optional powered-by. Sender domain: SPF and DKIM on the client domain, or you will miss clocks because mail landed in spam. Deliverability is a DSAR control. Put it in the SOW. If you cannot get DNS, do not promise white-label send.
Beta integrations stay labelled. Entra is not GA. Do not write GA into a client statement of work because the sales deck was sloppy.
4. Commercials
70 / 30 wholesale, deal registration, no min commit. Markup is yours. Keep the $5 / $6 public reference visible so the end customer can see we are not running a shadow price list. No fabricated MSP customer counts in our material or yours.
What to tell the client CISO
"We operate the queue and the inventory. Your counsel approves send. Your IdP data never commingles with another tenant. Entra is Beta. Templates are operator-reviewed. HIPAA is not attested on ScopeMantle."
What to do this week
- Write the counsel-gate into the SOW before you demo the skin.
- Check whether you can get SPF/DKIM on a pilot domain.
- Read the assessment bundle if you also sell inventory sprints: MSSP OAuth bundle.
- Demo the partner view.
Week-by-week stand-up
Week 0. SOW includes counsel gate, DNS requirements, employee band, Entra Beta footnote, multi-tenant segregation clause, and a statement that templates are operator-reviewed. If legal on your side will not sign that, stop.
Week 1. Connect the pilot tenant. Snapshot inventory. Rebuild one historical DSAR the client already closed. Count missed processors. That number is the QBR slide and the reason they will not churn in month two.
Week 2. Portal skin. Privacy policy link on the intake form that actually matches the client, not your MSP boilerplate. Identity-verification steps copied from their existing KYC, not a new invention.
Week 3. DNS: SPF, DKIM, maybe DMARC alignment. Send a test to counsel's inbox and to a seed account at a major webmail provider. If it fails, you do not go live.
Week 4. Tabletop a day-7 non-response and an erasure-plus-revoke. Record who clicked what. Then open the portal.
RACI when three companies touch one subject
| Task | MSP | Client | ScopeMantle |
|---|---|---|---|
| Identity verification | Operate if contracted | Owns the standard | Does not verify humans |
| Vendor list | Reviews | Attests completeness gaps (non-OAuth processors) | Supplies OAuth snapshot |
| Letter text | Drafts | Counsel approves | Operator template only |
| Send / track | Operates | Escalates vendors they own commercially | Timestamps, attachments |
| Grant revoke | Executes if scoped | Must authorize | Governance action if connected |
Failure modes that become lawsuits (or just lost clients)
- Analyst hits send at 17:55 because the clock is ugly and counsel is in traffic.
- Two clients' cases visible to the wrong queue. That is your SOC 2, not a product footnote.
- Using support@ for every vendor because the privacy-contact column was empty and nobody filled it.
- Promising 30-day GDPR close on a DPDPA client, or the reverse.
- White-label footer that implies the MSP is the controller when the client is.
- No hash of the inventory snapshot, so a regulator asks how the list was built and you shrug.
Children's data, special-category data, and law-enforcement exceptions are counsel filters. Do not add a product toggle and call it compliance. If the intake form collects too much identity evidence, you created a new pile of personal data. Minimize. The playbook already says that for vendor dumps. Apply it to yourself.
QBR metrics that are not vanity
- Cases opened / closed, median days (clock start defined).
- Vendor non-response rate at day 21.
- Grants revoked on erasure cases.
- Inventory rows missing client ID (should be zero).
- Counsel-gate breaches (should be zero; if not, that is the meeting).
Do not report "customer satisfaction with privacy." Report clocks and misses. The India program adds classification status as a yellow/red if they still have not done the legal work.
When the client is also the controller for employee data
Employee DSARs are messier than customer DSARs because the grant owners are coworkers. You will email vendors about a colleague. Keep the case access list short. Do not let the employee's manager browse the queue "out of curiosity." Multi-tenant segregation includes intra-client RBAC. If your analysts can see every field, that is a design choice you should write down.
Customer DSARs against a SaaS client of your client (you are two hops out) may be out of scope. Say so in the SOW. ScopeMantle inventories the tenant you connect, not the planet.
Pricing conversation without theater
Wholesale 70 / 30. List $5 / $6. No seat min. Custom at 500+ on the end-customer side. Your markup is your problem. Do not tell the client ScopeMantle is "free with the bundle" and then hide a line item. They will find the public price. Trial via /demo. Entra Beta. Templates operator-reviewed. HIPAA not attested. No logo wall.
Field guide: the first live case
Do not open the portal to the public on day one. Run one historical rebuild and one tabletop, then one real case with counsel on a recorded huddle. If send happens without the checkbox, stop the SKU and rewrite the workflow. A single ungated send is how you lose the client and maybe more than the client.
Identity verification stays their standard. If they do not have one, you are not a KYC vendor. Pause. Vendor list comes from that tenant's OAuth snapshot, hashed, attached. Appendix holds low-tier scopes. Internal systems stay on their runbook. You do not crawl their monolith.
Deliverability lab
Before go-live, send test messages to counsel, to a client seed mailbox, and to at least one major webmail provider. Check SPF, DKIM, and whether the From display name matches the privacy policy. If you cannot get DNS, do not promise white-label send. Operate from a shared mailbox they already warm, and write that limitation in the SOW.
Clocks die in spam. That is not a legal nuance. That is DNS. Put an engineer in the stand-up until the tests pass.
When volume spikes
Post-breach DSARs (Drift-class, Context.ai-class) will swamp a two-person queue. Pre-agree a burst rate card. Pre-build the client-ID-to-privacy-contact map in peacetime. Erasure cases need revoke authority in writing before the spike, not during it. Operator templates stay operator-reviewed. Counsel still approves the first letter in a new incident, even if they approved last quarter's boilerplate.
70 / 30 wholesale, $5 / $6 list reference, no seat min, Entra Beta, HIPAA not attested. Playbook.
Mistakes I keep seeing after the first workshop
People export once and call it culture. People revoke by display name after a rebrand. People promise Entra completeness. People put OAuth rows in the user-access matrix. People send DSAR mail without a case ID. People treat a CASB invoice as grant inventory. People change a score threshold the night before audit. People staff an MSSP sprint with someone who cannot read a scope string. Each of those has a fix already on this page. The failure is skipping the fix because the demo looked polished.
Write the one thing you will not skip this week. Put it on a calendar. If you want the inventory to stay current, the 30-day trial is the productized version of the export. Five dollars per employee per month billed annually, or six dollars monthly. No seat minimum. Custom terms at 500+ employees. Microsoft Entra stays labelled Beta. HIPAA is not attested. Templates stay operator-reviewed. No fabricated customer counts on the customers page.
If you are evaluating us next to a GRC tool, keep both jobs honest. If you are evaluating us next to a consent-intercept tool, stack prevention and inventory. If you are an MSP, register the deal before the demo and keep the counsel gate in the SOW. If you are writing a board slide, use last quarter as the only benchmark we will stand behind. That is enough program for a quarter. The next quarter is whether the leftover-grant count actually moved.
A note for the MSP delivery lead
Portal skin is the easy part. Counsel gate, DNS, and multi-tenant RBAC are the product. One ungated send and you pause the SKU. Burst rate card before the next supply-chain headline. Two inventories when the client is both employer and processor for their customers. $5 / $6 list reference, 70 / 30 wholesale, templates operator-reviewed. If you cannot get SPF and DKIM, do not promise white-label send.
What you can do without buying anything
Export the IdP list. Deduplicate on client ID. Revoke three rows you cannot explain. Write the CC9.2 versus CC6.7 sentence for your auditor. Add OAuth grants equals zero to offboarding. Put an extension allow-list in one OU. Schedule a Friday tabletop with a fictional client ID. Hash a file and put it in GRC. Those steps do not require ScopeMantle. They do require a calendar and a human who will not skip them.
When those steps start to rot (and they will, usually by week six), the productized version is daily Google and Okta sync, scores, attestation expiry, bulk revoke, and DSAR snapshot on the same inventory. Price is public. Beta labels stay on the page. We will not invent a case study to make the last paragraph feel finished. Start the trial if the calendar is already losing.
Record the first counsel huddle. If the checkbox can be skipped in the UI, file a ticket with us and do not go live. White-label without a gate is just faster liability. DNS tests stay on the critical path.
Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.