LS Portal Login Systems Live demo ▸
LS Portal · built by Login Systems · ready for the group

Every tool your MSP runs. One place to see it, act on it and prove it.

Login Systems built LS Portal to run its own managed-services business. It reads the PSA, RMM, security, licensing, Microsoft 365 tenants, documentation and satisfaction tools into one place, then gives every seat its own view: dashboards for staff, a portal customers can act in, a wall for the office, and an AI analyst that never invents a number. It has run the Sydney service desk since May 2026, and it is ready for other MSPs in the group.

reads from
portal.example.com.au
The real portal

This is what the team opens every morning.

Screens from the Login Systems portal as it runs today, September 2026. Client and staff names are replaced with invented ones and free text is blurred; everything else is exactly as the team sees it. Click a screen to enlarge.

portal / dashboards / me · account managerMy Day for an account manager: client satisfaction, ticket volume, open work by client and by queue, off-track tickets, sales orders and deployments
My Day, account manager. Satisfaction and ticket volume across the client book, open work by client and queue, sales orders, deployments and quotes in one tabbed panel.
portal / resources · technicianA technician's resource page: open, critical, SLA-breached and closed counts, a 12-week trend, open tickets and an AI development insight
A technician's page. Open and closed counts, SLA position, a twelve-week trend, every open ticket with its billing, and an AI development insight drawn from their own work.
portal / dashboards / managementManagement dashboard: what changed this week, renewal deadlines with cancel-by dates, endpoints missing EDR, exposed services, open ticket counts and top clients by revenue
Management. What changed this week, renewal deadlines with cancel-by dates, endpoints without security coverage, exposed services, ticket counts and top clients by revenue.
portal / dashboards / service-deskService desk dashboard: SLA breached, security alerts, VVIP and critical device counts, open ticket counts, queue depth, tech load and SLA breach watch
Service desk. SLA breaches, security alerts, VVIP tickets and critical devices at the top; queue depth, technician load and the next tickets to breach below.
The problem

The swivel chair is the product gap.

MSPs run on excellent vendor tools that do not talk to each other. The cost is not the licences. It is the questions nobody can answer without an afternoon of exports.

PSA47devicesRMM49devicesEDR44agents

Every console has its own client

Three tools, three device counts, no owner of the truth. The portal resolves every vendor site to one client record and shows the drift as named gaps.

tabs open9consolestime1 pmto 4 pmanswer?maybe

Nine logins to answer one question

"Which clients have devices without an EDR agent?" is two exports and a spreadsheet. The portal answers it on one page, from synced data, every day.

risk raisedemailacceptedsilenceevidencenone

Customers see a PDF, once a quarter

In the portal a customer opens their risk register, accepts a residual risk in two steps or approves a costed proposal, and the account manager sees it change live.

What it does

See it working, not described.

Every panel below is the real product running on sample data. Click into them.

Client 360

One client. One truth.

Every vendor tool has its own version of your customer. The portal brings them together into one client record, so a device, a security agent, a licence seat and a ticket all land on the same page, and the disagreements between tools become a list you can act on.

  • Devices under management with no security agent, per client
  • Domains matched to the right client automatically
  • A client that quietly leaves is noticed the day it happens
  • Paid seats from two distributors against seats actually assigned in the tenant
try it · drag the slider
portal / clients / harbour-legal
Dashboards

Built for the seat, not the org chart.

A technician, an account manager, a project lead and the CEO each land on the view built for their job. Access is capability-based and enforced on the server, so what is on the screen is exactly what that role should see, and changing it takes minutes, not a vendor ticket.

  • Technicians: their tickets, the ones drifting off track, block hours left per client
  • Management: what changed this week, renewal deadlines, critical incidents
  • Finance: profitability per agreement, scored every month
  • Access follows the job, no vendor logins to juggle
try it · change who is looking
portal / dashboards / me
NOC wall

The wall that looks up first.

Two office boards rotate through ticket flow, endpoint health and supplier status. An alarm engine with nine sources evaluates every minute. When a SOC escalation lands, the wall takes over, pages the roster and stays red until someone acknowledges it.

  • Nine kinds of alarm, each with its own tone, so the room hears what kind of problem it is
  • Supplier outages shown for your region only, so an incident in Europe does not wake Sydney
  • Boards only work from inside the office; no login on a wall-mounted screen
  • Every alarm raised once, cleared when the problem clears, recorded
try it · trip the alarm, Esc to close
display / noc1
Client portal

A portal customers act in.

Twenty-one pages, seventeen per-user feature flags, and a risk register where the customer accepts a residual risk in two steps or approves a costed proposal. The record carries their name, the time and the rating as it stood. The account manager's view updates live.

  • Tickets, devices, licences, domains, identities, training, breaches
  • Monthly reports and security summaries published to the portal
  • Customers manage their own colleagues' access
  • A customer can only ever see their own data, whatever they type in the address bar
try it · you are the client
portal / risks
AI reporting

AI that writes words, never numbers.

The monthly service report computes its eight headline KPIs in code and hands them to the model as ground truth it must use verbatim. Validators reject any figure that is not in the KPI block. The narrative is drafted, approved by a human and published to the client portal as a branded PDF.

  • Ask for a report in plain English, for one client or the whole book
  • Last month's open items carry forward so the story continues
  • Staff ask questions of the whole business in plain English and get cited answers
  • The AI only gets smarter when a person approves what it learned
portal / reports / monthly / august-2026
Finance

Margin per agreement, every month.

Recurring revenue, block-hour burn and the effective hourly rate of every fixed-fee agreement, with external technicians excluded from the denominator. One agreement under the floor shows up in September, not at year end.

  • Both Microsoft distributors, Pax8 and Crayon, reconciled per client in minutes, not a day
  • Licence renewal deadlines with the cancel-by date, delivered to Teams each morning
  • Money is visible only to the people who should see it
  • What you pay vendors, what is deployed and what you bill, reconciled monthly, in flight
hover an agreement
portal / dashboards / finance
Security

Five security vendors. One client page.

EDR alerts and SOC escalations, identities without MFA, exposed ports attributed to an office, a cloud host or someone's home, Shadow IT found in the software inventory, phishing results and domain locks. Each signal attributed, linked to the device or identity, and shown to the right people.

  • Unapproved software found across every managed device, rules you control
  • Exposed services traced to an office, a cloud host or someone's home
  • Domain expiry and registry-lock alerts before a customer's website goes dark
  • Breach exposure reported without ever storing a password
  • Microsoft 365 licences, MFA state and tenant posture read straight from the tenant
portal / security
Works with your tools

Your automation and AI assistants can ask it too.

Before a technician opens a new ticket, your automation platform can ask the portal how long similar work took and what fixed it. Staff can ask the same questions from their AI assistant with a personal key that an administrator sets up, narrows and can switch off. Every question is recorded.

  • Automation platforms such as Rewst plug in with a scoped key
  • AI assistants get only the tools and clients an admin allows
  • The one action that writes a ticket previews first and is capped per day
  • Staff file ideas and bugs from the page they are on, tracked to completion
try it · run the automation, set up a key
api / v1 · api / mcp
Live demo

A day inside the portal.

Seventeen moments from 00:00 to 23:59, presented as a guided walk. Drag the sun, click into any panel, or press P to present it full screen.

Space play← → step1–8 key momentsL ledger- + type size
Security and governance

Why the data stays where it belongs.

The browser never talks to a vendor and never holds a credential. Every request passes independent checks before business code runs, and every action, vendor call and model call is audited.

01
BrowserReceives rendered, permission-filtered HTML. Never a vendor key, never a vendor call.
CSP · HSTS
02
Cloudflare Access + Azure ADSingle sign-on with admin approval before any access. Deactivation applies on the next request.
SSO
03
Capability RBAC76 keys bind a page to its API routes. User beats group beats role; deny wins; denials audited.
deny wins
04
Audited API and encrypted warehouseEvery mutating request logged with redaction. Credentials AES-256-GCM at rest, decrypted in memory only.
audited
05
Vendors, read onlyGET-only clients, every outbound call recorded, four signed-off writes in the whole codebase.
read only
Lock, do not hide, in the client portal

A feature a customer has not enabled stays visible but locked, so the next conversation is an upsell, never a mystery.

Tenant isolation

A portal user's client scope is derived server-side from their bindings; every by-id endpoint re-verifies ownership.

Hardened delivery

Non-root immutable images pinned by digest, login throttling on the true peer address, security headers across the board.

Audited on purpose

An adversarial security audit, its findings fixed in code with tests, and RBAC tripwires that fail the build.

the complete list of vendor writesNBN line diagnosticsTeams vetting cardTeams renewal cardMCP ticket creation, dry-run by default
Case study · Login Systems, Sydney

What changed when we ran our own MSP on it.

LS Portal has run the Login Systems service desk, management meetings, finance reviews and customer portal since May 2026. This is what is different now.

For the operating companies

Bring it to your MSP.

Each operating company runs its own copy with its own data, so nothing is shared between businesses unless you decide it should be. Improvements made for one flow to all. The tools you already use decide how much lights up on day one; adding a new vendor is a contained piece of work, not a rebuild.

your MSP / stack
STEP 1
Connect your tools

Read-only keys for each vendor, entered once on an admin screen with a connection test. The portal never writes back to them.

STEP 2
Match your clients

Customers are matched across tools automatically; a mapping screen catches the few that need a human.

STEP 3
Set who sees what

Technician, account manager, executive and finance groups come ready-made; adjust in minutes.

STEP 4
Invite your customers

Portal access per contact, feature by feature, with a switch to turn a client off instantly. Publish the first monthly report.

Pick your tools above and copy the link: it opens pre-selected for your operating company. Login Systems supports the rollout and runs the first walkthrough with your team.

Roadmap

What is landing next.

The portal is improved every week. In flight means it is built and being verified before release; next means it is designed and queued.

In flight

  • Billing reconciliation across vendorsWhat you pay, what is deployed and what you bill, per client and product, closed off each month with the leaks listed.
  • Transactional emailPortal invites by SSO link and report-ready notices on Azure Communication Services.
  • Documentation on the client pageContacts, assets and checklists from the documentation system, plus every expiring certificate and contract in one register.
Next step

See it run on your own numbers.

A walkthrough takes forty minutes: the product live, the client portal from your customer's seat, and what would light up for your stack. Then a scoped plan for your operating company. Login Systems, Sydney.