Reseller Seat Pool Management: Allocate Seats at Scale

Daniel Okafor··7 min read
MSP team planning seat allocations across client companies

For managed service providers, seat counts never sit still. One client onboards a wave of new hires, another divests a business unit, a third wants to pilot security awareness training in a single department before rolling it out to everyone. When every one of those changes means a support ticket, a spreadsheet, or a call to the vendor, seat administration quietly becomes one of the most tedious parts of running a managed security service. empowsec removes that friction with a central seat pool that resellers allocate to their managed companies themselves - complete with per-company and bulk updates, a usage sync action, permission-scoped delegation, and a dedicated audit log for changes to the pool.

This deep dive covers the day-to-day allocation workflow inside the reseller portal. If you are looking for how seat pools are priced, how packages define capabilities, or how true-up billing works when usage grows beyond the pool, that commercial side is covered in our reseller plans and packages article. Here the focus is operational: how do you move seats between clients quickly, safely, and with a paper trail?

One Seat Pool for All Your Clients

Every reseller on empowsec works from a single active seat pool. Instead of buying fixed license blocks per client, you distribute that pool across your managed companies as allocations. The seats page in the reseller portal opens with a live summary: the total pool, how many seats are currently allocated to companies, how many are actually in use by billable users, how many remain available to allocate, and an overall utilization percentage. If total usage ever grows beyond the pool, the same summary flags the overage immediately, so nothing surprises you at billing time.

The distinction between allocated and used matters in practice. Allocated seats are commitments - the ceiling you have granted a client. Used seats are reality - the billable users who actually exist in that company today. A healthy MSP portfolio usually shows a gap between the two, and the seats dashboard makes that headroom visible both per company and across the whole client base. That is how you spot over-provisioned clients whose allocation could be trimmed, and fast-growing clients who are about to hit their ceiling in the middle of a phishing simulation rollout.

Seat pool
5,000
active pool
Allocated
4,350
across 18 companies
In use
3,612
72.2% utilization
Available
650
ready to allocate
The seats overview in the reseller portal: pool size, allocations, real usage, and remaining headroom at a glance.

Hard, Soft, and Unlimited Limits per Company

Not every client relationship needs the same guardrail, so each allocation carries one of three limit types. A hard limit is a strict ceiling: once the company reaches it, adding another user is blocked, and reseller admins receive a notification that an attempt was stopped. A soft limit permits growth past the ceiling but warns: the user is still added, the company goes over its allocation, and reseller admins are notified - at most once per 24 hours, so a busy onboarding day does not flood anyone's inbox. An unlimited allocation removes the cap entirely, which suits anchor clients on all-you-can-use agreements.

Allocation changes are validated against your pool in real time. If you try to grant more seats than you have available, empowsec rejects the change and tells you exactly how many additional seats you would need. In the other direction, you are deliberately allowed to set a limit below a company's current usage as a downsizing target: the client keeps its existing users but cannot add new ones until headcount drops back under the limit. That is a practical lever when a client is scaling down ahead of a contract renewal and you want the allocation to reflect the new agreement from day one.

CompanyAllocatedUsedLimit type
Cobalt Engineering800655Hard
Atlas Legal150162Soft
Brightline Media-96Unlimited
Nordwind Logistics400388Hard
Per-company allocations with limit types. Atlas Legal runs over its soft limit - allowed, but flagged and notified.

Bulk Reallocation and Usage Sync

Portfolio-wide changes rarely happen one company at a time. Quarterly reviews, annual renewals, or a rebalancing after winning a large client often mean adjusting a dozen allocations at once. The bulk update lets you submit new seat limits and limit types for many companies in a single operation, and empowsec validates the entire batch against the pool as a whole before applying anything. Either the full reallocation fits inside your pool, or the save is rejected with a clear message. A bulk edit can never silently overcommit seats you do not have.

The per-company usage sync closes the loop on data accuracy. It recounts the company's billable users directly from the live user records - excluding your own reseller staff who work inside client accounts - and refreshes the stored usage figure. If the fresh count reveals a soft-limit breach, the warning notification fires automatically. Regular syncs keep utilization numbers honest, which matters when allocation decisions, renewal proposals, and client conversations are all based on them.

Delegation with Permission-Scoped Access

Seat allocation touches commercial commitments, so empowsec gates it with two separate reseller permissions rather than an all-or-nothing admin role. The reseller.seats.view permission lets a team member open the seats page and see the pool summary plus every company's allocation and usage - ideal for account managers preparing a renewal conversation or finance colleagues checking utilization before invoicing. The reseller.seats.manage permission is required to actually change anything: per-company updates, usage syncs, and bulk reallocations all sit behind it.

The same separation carries into the reseller API, where seat endpoints are split into read and write scopes. An integration that only feeds a reporting dashboard can hold a read-only credential, while the automation that adjusts allocations authenticates with a separately scoped key. The empowsec developer documentation covers the seat summary and per-company allocation endpoints in detail, so you can wire seat data into the same tooling you use for your other reporting dashboards.

A Dedicated Audit Trail for Pool Changes

Seats are money, and changes to the seat pool deserve the same evidence standard as invoices. empowsec keeps a dedicated seat-pool audit log that records every adjustment to a reseller's pool - including applied true-ups - together with who performed the action, the values before and after, optional notes explaining why, and the IP address the change came from. When a client disputes a charge, when finance reconciles quarter-end numbers, or when an auditor asks who increased a pool and when, the answer is a quick lookup rather than an archaeology project across emails and chat threads.

P
Seat pool adjusted: 4,000 to 5,000
Performed by A. Reyes - note: Q3 contract expansion - IP recorded
pool adjusted
T
True-up applied after overage
Before and after values stored - performed by M. Duarte
true-up applied
The seat-pool audit log: every pool change with performer, old and new values, notes, and source IP.

Key Takeaways

  • Central seat pool: allocate seats to managed companies yourself, with live visibility into pool size, allocated, used, and available seats.
  • Three limit types - hard, soft, and unlimited - match the guardrail to the client relationship, with notifications when limits bite.
  • Bulk updates reallocate across many companies at once and are validated against the whole pool, so you can never overcommit.
  • Usage sync recounts billable users on demand and excludes reseller staff, keeping utilization figures accurate.
  • Permission-scoped access separates viewing seat data from managing it, so account managers can see without changing.
  • A dedicated audit log records pool adjustments and true-ups with performer, before and after values, notes, and IP address.
Share: