Customer Management
Customers group services, portal logins and a subscription. Administrators manage customers from Customers; customer portal views use the signed-in account's customer association.
Create and invite
Choose New Customer, enter the first name, optional last name, contact email and plan, and save. The panel creates the customer and linked tenant organization, and provisions the login through Keycloak. Email delivery depends on Settings → Email; a saved customer does not prove that an invitation arrived.
Open the customer detail page to review contact information, services, usage, subscription and logins. Use its invitation action for additional users. Each login joins the customer's organization. Check invitation delivery and use the resend action when needed. Edit the subscription to change the plan.
Portal access
Portal actions depend on the plan's permissions and optional capabilities. Customers may view their service status, URLs, logs and metrics, or start, stop and restart services where permitted. Template deployment has its own checks. An administrator's view is broader; do not use an admin session to test customer access. See Service Plans, API Keys and Tenant MCP.
Suspend and reactivate
Suspension changes the customer status, attempts to disable its Keycloak logins, revokes panel sessions and queues stop jobs for running services. The session middleware also checks the customer's suspended state. These steps cross the database, identity provider and background worker: check the resulting login and service states, and investigate reported failures.
Reactivation enables the account and attempts to enable its logins. It does not automatically restart stopped services. Review and start the required services separately. Subscription status remains a separate entitlement decision.
Delete with a recovery plan
Customer deletion is not a complete data-erasure workflow. It does not walk Docker services and volumes to provide a complete application-data removal procedure.
A customer that still owns a service cannot be deleted. The panel answers "This customer still owns services" and changes nothing. Delete each service, or reassign it to another customer, then delete the customer. The same applies while a service is being moved to the customer: wait for the move to finish.
When the delete goes ahead it happens in two parts:
- At once, as one step: the customer record, the logins that belong to this customer alone, their sessions and API keys, and the API keys of the customer's organization are removed from the panel. If any part fails, none of it happens and the customer is fully intact. From this moment those logins and keys no longer work in the panel.
- In the background, retried until done: the customer's sign-in accounts in Keycloak are deleted and its secrets namespace is removed. If Keycloak is down these jobs keep retrying; a job that finally gives up is written to the panel log and the audit log with the remaining Keycloak user IDs, for an operator to remove by hand.
A login that also belongs to another organization is not deleted. That includes the customer's first login. It keeps its account, its sessions and its Keycloak sign-in, and its membership of this customer is removed.
The customer's organization is kept but closed. Its record stays for the audit trail with the status terminated, and nothing can join it: no new user, no invite, no role or project assignment.
The delete is refused with nothing changed if the panel cannot read what it needs, cannot reach Keycloak to look the accounts up, or cannot queue the background jobs. Try again once the service is back. If two Keycloak accounts share one of the customer's email addresses, remove the duplicate in Keycloak first; retrying does not help.
A deleted customer's email address can be used again once the background job has removed its Keycloak account, normally within seconds. Until then, creating a customer, inviting a user or adding an organization user with that address is refused with "This email address cannot be used for a new login": the panel never gives a new login an existing sign-in account, because that account would keep its old password. The same message appears for any address that already has a Keycloak account, whoever it belongs to. If an address stays blocked, an account for it is still in Keycloak and an administrator has to remove it there. Not removed by a delete: the customer's AI gateway key and its Keycloak group.
If Keycloak is reachable for that check but fails while the account is being created, the customer is created without a sign-in account and the temporary password shown does not work. Invite the customer's own email address again on that customer: the panel creates the missing account and sends the set-password email.
Before deleting, inventory services, volumes, backups, exports and external accounts. Preserve any required recovery material, handle service removal first, and verify each cleanup result. Treat deletion as destructive; the panel does not provide an undo action or a comprehensive erasure report.
The v2.12.8 customer UI does not provide the previously described complete data export. Arrange application-specific exports and your retention/erasure process with the hosting administrator. Audit records are operational evidence, not a certification that every copy of customer data was removed.