One control plane above, hard tenant boundaries below.
One agency account operates many isolated client businesses: provision workspaces, assign staff and access, control modules and branding, review portfolio activity, and enter an authorized client workspace.
Search account #, name, or owner…StatusPlanGroup by
Client workspace
Plan
Modules installed
Users
Last activity
Status
Summit DentalAGR-000217
Growth
Finance, CRM
6
Sep 6, 2026
Onboarding
Riverside ClinicAGR-000214
Starter
CRM, Scheduling, Tasks
5
Sep 6, 2026
Onboarding
Lakeside FreightAGR-000209
Growth
Finance, Inventory, Tasks+2 more
12
Sep 5, 2026
Active
Vantage RealtyAGR-000203
Starter
CRM, Marketing
9
Sep 1, 2026
Suspended
Harbor LogisticsAGR-000198
Scale
Inventory, Warehouse, Finance+4 more
24
Sep 6, 2026
Active
Bluebird StudioAGR-000191
Starter
Projects, Tasks, Finance+1 more
11
Sep 4, 2026
Active
Northwind TradersAGR-000186
Growth
Finance, CRM, Inventory+3 more
18
Sep 5, 2026
Active
Acme CorpAGR-000177
Scale
Finance, CRM, HR+4 more
14
Sep 6, 2026
Active
Rows per page 25 1–8 of 37
Agency control planeAssistant · confirm to provision
Draft
Confirm
Provisioning requests · 12 September 2026
Yusuf G.Reviewing…
Capabilities
What this module actually does inside Agaro ERP.
01
Portfolio overview
Tenants against the cap, seats, subscription totals, the staff roster, and recent activity across every client — in one rollup.
02
Provision client workspaces
Create a client business as its own isolated workspace, with its own records, users, permissions, and audit history from the first minute.
03
Staff and access
An agency roster with roles: who may view a client, who may manage one, and who may change the agency itself. Listed, auditable, correctable.
04
Module control
The agency decides which modules its clients may install and approves their requests, instead of routing every request upstream.
05
Branding
Set the agency's white-label surface once and let it cascade down to every client workspace underneath it.
06
Enter an authorized client
Open a client workspace as an authorized operator. The entry is scoped, permitted, and recorded like any other action in the system.
Specifications
Engineered to a standard, not a slogan.
Data model
Hard tenant boundaries
Each client is a separate workspace with its own records, users, permissions, and audit history. One control plane sits above them.
Permissions
Agency roles above tenant roles
View and manage are distinct agency roles, and each surface enforces the tier its page requires on the server.
Deployment
Many workspaces, one account
Provisioning a client creates an isolated workspace under the agency account rather than a folder inside a shared one.
Extensibility
Fleet-wide modules
A module built once can be deployed across the agency's client workspaces, subject to the agency's own module policy.
Assistant access
Bounded by the entered workspace
Inside a client, the assistant is bound by that client's data boundary and by the operator's own role and grants.
Audit
Recorded on both sides
Client entry, provisioning, module changes, and staff changes are recorded against the identity that performed them.
Frequently Asked Questions · Agency Mode
What teams ask about Agency Mode before they move their operations.
Only the clients they are assigned to. Agency mode is one account operating many isolated client businesses, with hard tenant boundaries below a single control plane. Each client has its own records, users, permissions, and audit history in workspace isolated PostgreSQL, so a staff member assigned to Acme Industries and not to Harbor Logistics has no route to Harbor's data — not through the interface, not through the API or MCP, and not through the assistant, which inherits exactly that staff member's role, module access, grants, and workspace. There is no cross-client query and no shared assistant memory that could carry one client's figures into another's answer. Access is granted from the control plane by assigning staff to workspaces, and removing the assignment removes the access everywhere at once, because one permission model covers people and AI.
Provisioning and governance, not a client's day-to-day records. From the control plane an agency can create client workspaces, assign staff and their access, control which modules each client has, set branding, review portfolio activity, and enter an authorized client workspace to work inside it. What the control plane does not do is dissolve the boundary underneath it: entering a client means working in that client's workspace under that client's permission model, with the actions recorded there. Module control is how an agency shapes what each client business gets — a bookkeeping client with finance only, a full operations client with inventory and manufacturing — without maintaining separate installations. It is one place to run a portfolio of businesses, and the isolation that makes that safe is enforced below it rather than promised by it.
They work as themselves, inside that client's boundary. Entering an authorized client workspace does not create a super-user: the staff member's role, module access, and grants in that workspace decide what they can see and do, and their assistant inherits the same. Actions taken there are recorded in that client's activity history with the actor and the time, so the client's trail shows who did the work, including when the work was done by the agency. The path never changes — prompt, identity, access, resolve data, engine, action, audit — and it is the same path a click takes. Leaving the workspace ends the access. Because the assistant holds no authority of its own, staff cannot use it to reach further into a client's data than their own account already reaches.
Yes, and it belongs to the client workspace. Every action a client's own users take and every action agency staff take inside that workspace is written to that workspace's history with the actor, the record, and the time, in its own isolated data. The agency can review activity at the portfolio level from the control plane, but the record itself lives with the client, which is what makes the arrangement defensible when a client leaves or asks who touched their books. Assistant-driven work is structurally indistinguishable from hand-entered work: same actions, same trail, attributed to the person who prompted it. One audit trail per workspace, no separate AI log, and no path for a stock movement, a journal, or a payroll run to happen without an entry naming who caused it.
Agaro ERP is an AI native ERP from Agaro Technologies LLC, built so the software can do the work rather than only record it. It covers finance and invoicing, HR and payroll, CRM and leads, marketing, inventory and supply chain, manufacturing, projects and tasks, an app and website builder, a module builder, agency mode, and the AGARO Assistant — one connected workspace instead of a stack of tools that have to agree with each other. ERP has always held the facts: the customer, the price, the hours, the contract, the approvals. Someone still had to find the records, calculate the result, push the buttons, and reconcile what happened. Agaro closes that gap by giving the assistant the same authority the prompting user has and keeping deterministic engines in charge of money, pay, and stock. It is launching soon.
It does not decide; your access does. The prompting user is the identity and their workspace is the data boundary, and the assistant inherits all of it: same role, same module access, same user grants, same model permissions, same workspace. If the user cannot perform an action, the assistant cannot perform it. Every prompt follows one path — prompt, identity, access, resolve data, engine, action, audit — and access is checked before any record is read, so a request outside your permissions stops before data is resolved rather than being declined politely after the fact. The model's role is narrow by design: it selects an action, and Agaro decides whether and how that action executes. Anything that commits or delivers is presented for confirmation, and everything that happens is recorded under your identity in your workspace's audit history.
It means no route from a model to your data skips the business logic. The product interface, the AI assistant, the API, and MCP all resolve to a signed in actor with a workspace, role, modules, and model permissions, then pass through one shared action layer where input validation, authorization, the transaction, and the activity log happen. Only then do the finance, payroll, inventory, CRM, and workflow engines run, against workspace isolated PostgreSQL data and audit history. A button click and an assistant tool call reach the same guarded business logic. Practically, that is why the model never calculates an invoice total, a payroll register, or a stock quantity: the engines do, deterministically, and the same request produces the same result whichever route it arrived on. Same identity, same controls, same business actions, one audit trail.
Agaro ERP is launching soon. We are not publishing a date, because the parts that have to be right — the finance and payroll engines, the single stock-write path, the permission model binding the assistant to the user — are the parts worth finishing properly rather than shipping to a calendar. Early access is by talking to us. Tell us what you run today, which modules matter first, and whether you operate one business or a portfolio of client businesses through agency mode, and we will tell you plainly whether Agaro fits and when. If it does not fit yet, we would rather say so than take the signup. You can sign up on agaro.ai to be told when it opens, or reach Agaro Technologies LLC directly at [email protected] or +1 (571) 278-8979. The company is based in Brambleton, Virginia.
The AGARO Assistant can do anything the prompting user can do. It is not a search box or a summarizer bolted onto a report screen — it creates and updates records, runs workflows, and completes transactions inside the ERP. Ask it to invoice a customer and it resolves the real customer, the catalog item, the stored price, the workspace currency, tax, and payment terms, then calls the finance engine to validate the request, calculate totals, allocate the invoice number, create the invoice, and commit the journal. It can create and assign tasks, move projects, prepare a payroll run, raise a purchase, or record a stock movement, each through the same server action a person triggers by clicking. When something is missing it asks. When an action needs confirmation, such as sending a document to a customer, it presents that action and waits for you.
By the prompting user. The signed in user is the identity and their workspace is the data boundary, so the assistant inherits the same role, the same module access, the same user grants, the same model permissions, and the same workspace. If the user cannot perform an action, the assistant cannot perform it. There is no service account with elevated rights sitting behind the chat window and no side channel into the database. Every prompt follows one controlled path: prompt, identity, access, resolve data, engine, action, audit. Access is evaluated before any record is read, engines validate and calculate before anything is written, and the outcome is recorded under the user who asked, not under the model. The model selects an action; the ERP decides whether and how that action executes. The audit history reads the same whether the work was done by clicking or by prompting.
Get early access to Agency Mode
Agaro ERP is launching soon. Tell us how you run this part of the business today and we will show you how the assistant runs it inside Agaro.