One dashboard, one client per organization.
Keep client projects in separate organizations and limit each member to the servers or projects they need. Organizations share your account subscription; they separate access and resources.
Organizations, team members and per-resource scoping is available on the Business plan. Compare plans →
What tends to go wrong.
A contractor needs access to one site. Shared credentials or overly broad permissions can give them access to other client resources as well.
Client projects need separate membership and resource lists, even when your agency manages them under one subscription.
Three developers, eleven client sites, and a deploy that broke something last Tuesday with no record of who ran it.
How each of those is handled.
On top of the five roles, each member carries a scope — all servers and projects, or a specific list. A client's developer is given their project and the rest of the organization is outside what their session can reach.
Organizations are separate spaces with their own servers, projects and members. The same person can hold a different role in each and switch between them from the console, without a second login.
Move a server and its projects to another organization in the same Depfloy account. You must be an Owner of the destination organization. This changes resource grouping within your account; it does not transfer the server to an independent client account.
Every deploy, server change, environment edit and permission change is recorded with the member who made it, filterable by person and date. "Who ran that deploy" has an answer.
Connect a Cloudflare API token and the zones on that account are editable from the same console as the servers. Adding a domain to a project opens its A record for you, unproxied so the certificate can be issued, and the guided setups for Google Workspace, Microsoft 365, DMARC, Resend and Postmark merge into the SPF record that is already there rather than adding a second one — two SPF records is the mistake that quietly breaks a client's mail. Cloudflare is the only DNS provider Depfloy connects to.
Manager runs servers and the team but not billing. Developer has full access to servers and sites but cannot create new servers. That line — shipping code versus spending money — is usually the one an agency actually needs.
The feature that matters here is unglamorous: a scope field next to a role. It is the difference between handing someone a project and handing them the keys to every client you have.
Agencies questions
Can a client have their own login without seeing my other clients? + −
What happens when a client leaves? + −
Can I tell which client site is down without opening each one? + −
Can I bill clients separately? + −
Do contractors need a paid seat? + −
Other ways people use Depfloy
Try it on one server.
7 days free, no credit card. Connect a machine you already have.