Browse
On this page

Document a client: knowledge base, vault, procedures, domains and network

Open a client's Documentation tab on a fresh instance with nothing in it, and fill in one real example of each section: a knowledge base article with its client-visibility setting, a masked password vault entry, a step-by-step procedure, a domain's registrar and expiry, the office network's subnet, and what Assets and Imports are for before you ever touch them.

You need Edit access to the client's Documentation tab

What you will have

  • See every section under a client's Documentation tab, in the order an MSP would actually fill them in.
  • Add a Knowledge Base article and set who at the client can read it.
  • Add a Password Vault entry, and reveal it the same masked, self-hiding way a tech would.
  • Write a Procedure with ordered steps for a job that repeats.
  • Fill in a domain's registrar and expiry, and see that a Domains row does not, by itself, show up on Expirations.
  • Add a matching row on Expirations by hand, and see it colored by how soon it falls due.
  • Document a subnet on the Network section's three cards.
  • See what Assets and the Imports door are for, without needing to use either one yet.

Why it works this way

Client Visibility is three separate controls on an article or vault entry, not one switch. "Not marked internal" is the MSP-only lock and wins over everything else when turned on. "Hidden from client portal" is the one that actually opens or closes it to the client's own users, and it ships off, which means visible. "Visible to specific users" narrows that further to named people instead of everyone. There is no single toggle actually labeled "visible to all client users" - that plain-English idea just means leaving Hidden from client portal off.

A Domains row and an Expirations row are two different lists that happen to describe the same fact. Filling in a domain's expiry date only updates the Domains section; nothing carries that date over to Expirations on its own, so a domain's renewal only shows up as a colored countdown once someone adds a second row for it there by hand.

The Password Vault's reveal window never puts the secret in a normal text field. It draws one character per colored, numbered cell so a zero and a letter O can never be misread, counts itself down from 30 seconds, and logs who looked, at which entry, and when - a shape forced by what the field actually is, a secret meant to be read once and put away, not left sitting on screen.

Importing from a documentation provider like IT Glue or Hudu is safe to run more than once: each imported row is stamped with its own external id, so a later import updates that same vault entry, article, or procedure instead of duplicating it, and anything a technician has since deleted here stays deleted rather than being brought back.

Steps

  1. Open Bluebird Dental's Documentation tab.

    The tab opened straight to Knowledge Base, one of eight sections listed under Documentation in the left menu: Knowledge Base, Password Vault, Procedures, Domains, Network, Expirations, Assets, and Imports. Every section on this brand-new client read empty, each with its own one-line message and an obvious button to add the first row.

    Open Bluebird Dental's Documentation tab.
  2. Add a Knowledge Base entry for the front desk PC.

    New Entry opened a plain form: a required Title, a rich-text Content box with its own formatting toolbar (bold, headings, lists, links, images, tables), an optional Resolution box in the same rich-text editor, a Category dropdown, and a comma-separated Tags field. Title got "Front desk PC restart steps", Content explained the hang, Resolution walked through the restart, and Tags got "front desk, workstation". Saving it landed the new row on the list with Source "Manual" and Status "Draft".

    Add a Knowledge Base entry for the front desk PC.
  3. Set who can see it from Client Visibility.

    Opening the saved article showed a Client Visibility panel with three controls: "Not marked internal" (off, meaning it is not staff-only), "Hidden from client portal" (off, meaning the client's own portal users can already see it), and "Visible to specific users" with an Add User door for narrowing that further to named people. Left exactly as it shipped, this article is visible to every Bluebird Dental portal user, which is the right call for a front-desk restart guide the client's own staff would actually want to read.

    Set who can see it from Client Visibility.
  4. Add a Password Vault entry for the guest Wifi.

    New Entry on Password Vault asked for a Name, a Category (Login, Wifi, Api Key, Certificate, License Key, MFA, or Other), a URL, a Username, a Password with its own Generate button, a Base32 TOTP Secret for one-time codes, and Notes. This entry got the name "Northwind guest Wifi", category Wifi, username "guest", and a password of Northwind-Guest-2026 - a demo value, not a real network key. The Notes line recorded that this is the guest network only, not the staff Wifi.

    Add a Password Vault entry for the guest Wifi.
  5. Reveal the password to check it, the same way a tech would.

    The eye icon on the entry opened a pop-up that spells the password out one character per colored, numbered cell instead of a plain text field, with Letters, Numbers, and Symbols called out underneath. A line under the grid counts down from 30 seconds until the window hides itself, and Copy password puts the value on the clipboard without ever displaying it in a field. Every reveal like this one is logged against the entry's history with who looked and when.

    Note: The password shown here, Northwind-Guest-2026, is a demo value typed in for this walkthrough. A real vault entry's revealed secret should never end up in a screenshot, a chat message, or a ticket.
    Reveal the password to check it, the same way a tech would.
  6. Write a Procedure for onboarding a new hire's laptop.

    New Procedure asked for a Title, an optional Description, a Status (Draft by default), and a Steps list built with Add Step, each step getting its own title, an optional content box, and an Optional step checkbox. This one, "New hire laptop setup", got three ordered steps: join the domain and rename the machine, install the scheduling software, and connect to the guest and staff Wifi profiles, the last one pointing back at the vault entry from the last step. Saved, it listed on Procedures with Status Draft, Steps 3, and Scope Client.

    Write a Procedure for onboarding a new hire's laptop.
  7. Fill in the domain's registrar and expiry dates.

    Bluebird Dental's own domain, bluebirddental.example.com, was already listed on Domains, added automatically from the client's Company Information, with every other column reading Unknown or a dash. Opening it exposed an Edit Domain form: Registrar, Expires At with its own Auto-Renew toggle, DNS Provider, comma-separated Nameservers, and an SSL Certificate block with its own SSL Expires At and SSL Issuer. This one got GoDaddy as registrar, an expiry of March 1, 2027, Cloudflare as DNS provider, and Let's Encrypt as SSL issuer, with Auto-Renew left off.

    Fill in the domain's registrar and expiry dates.
  8. Confirm the expiry now shows on the Domains list, not on Expirations.

    Back on the Domains list, the Expires column now read Mar 1, 2027 in green, next to the SSL Expires date beside it. That date lives only on this row: the Domains section keeps its own facts about a domain, and none of them, on their own, feed the separate Expirations list a few doors down the same menu.

    Confirm the expiry now shows on the Domains list, not on Expirations.
  9. Add a matching row on Expirations by hand.

    New Expiration asked for a Name, a Type (SonicWall License, SSL Cert, and similar examples, chosen here as Domain), an Expires At date, an Alert Days Before count defaulted to 30, and Notes. Naming it "bluebirddental.example.com domain renewal" and matching the same March 1, 2027 date landed a new row reading Active, 166 days, in green - the same three-color scheme (green, amber inside 90 days, red inside 30 or past) the Domains dates use, just tracked as its own separate fact.

    Note: Expirations is a list kept entirely by hand. Nothing on Domains, or anywhere else in Documentation, adds a row here on its own.
    Add a matching row on Expirations by hand.
  10. Document the office network's subnet.

    Network splits into three cards: Configurations for physical gear like firewalls and switches, Networks / Subnets for the subnets themselves, and VLANs. New Network on the middle card asked for a Name, a required Subnet / CIDR, a Gateway, a VLAN, a Location, and a Description. This one got the name "Front office LAN", subnet 10.42.0.0/24, gateway 10.42.0.1, and a location of "Bluebird Dental - main office", and it now lists on that same card next to the still-empty Configurations and VLANs tables.

    Document the office network's subnet.
  11. See what Assets is for, without adding one yet.

    New Asset on the still-empty Assets section opened the smallest form in all of Documentation: a required Name, a free-text Type, and Notes. Assets is meant for gear nobody actively monitors, like a spare switch or a rack, that still deserves a record. Leaving this one unsaved kept Bluebird Dental's Assets list honestly empty, exactly the state a brand-new client should be in until there is something worth writing down there.

    See what Assets is for, without adding one yet.
  12. See the Imports door without running one.

    Bulk Imports offers three doors: Import from IT Glue, Import Passwords CSV, and Import CSV, each landing on an empty table with columns for Source, Target, Status, Rows, When, and By once something has actually run. Any of the three brings in a routing preview to confirm before anything writes to the client's Documentation, and a second run of the same file updates the same rows instead of duplicating them. None of the three were run here, so Bluebird Dental's import history stayed empty on purpose.

    See the Imports door without running one.

Other ways to do this

Visible to specific users

On any article or vault entry's Client Visibility panel, leave Hidden from client portal off but use Add User under Visible to specific users to name only certain people.

The whole client should not see something, but more than nobody should - a billing contact needing one password, say, without opening it to every portal user.

Share links

Open a saved article or vault entry and use New link under Share links to hand it to someone outside the portal entirely, choosing how long the link works (1 hour to 30 days), an optional open cap, and an optional passphrase.

The person who needs it is not a portal user at all, such as a vendor or a client's own outside contractor.

Bulk import from a documentation provider

From Documentation > Imports, Import from IT Glue (or a CSV export from another vault) pulls articles, passwords, procedures, and assets in one pass instead of typing each one in by hand, with a routing preview shown before anything commits.

A client is moving from another MSP's documentation tool and already has this written down somewhere else.

If it did not work

  • If a new network row will not save, check the Subnet / CIDR box: it has to be written in CIDR form, like 10.42.0.0/24, and a plain IP address or range is turned down.
  • If a domain's renewal never shows up anywhere as a warning, remember that Domains and Expirations are two separate lists; add a row on Expirations for it by hand.
  • If a vault entry or article seems to have disappeared, turn on Show archived above its list; Delete only archives a row; nothing is destroyed until someone restores or truly removes it.
  • If a client's own portal users cannot see an article they should, check Hidden from client portal is off and Not marked internal is off before checking anything else.

Questions this page answers

What is the Password Vault section for?

It keeps this client's shared logins in one place. You can store a login, a wifi key, an API key, a certificate, a license key or an MFA seed. The list shows Name, Category, Username, Folder and Updated. The Password column holds buttons, not the secret. Click "New Entry" to add a row.

How do I read a password, and is that recorded?

Find the row and click the eye button in the Password column. Its tip reads "Reveal". A window opens with the password spelled out. Under it a line counts down: Hides automatically in 30s, then 29s, and the window shuts at zero. "Copy password" puts the secret on your clipboard instead. Every reveal is logged with who looked, which entry, and when.

The vault list is empty. Is that a problem?

No. An empty vault means nothing is stored for this client yet, and the list says so. A failed load reads as a warning instead, so an empty list always means empty. Click "Show archived" to bring back entries that were archived and not deleted.

How does the Password Vault work?

Password Vault is a section on a client's Documentation tab. It holds that client's logins. An entry takes a name, a category, a web address, a user name and a password. The categories are Login, Wifi, Api Key, Certificate, License Key, MFA and Other. Use the eye on a row to reveal the password in a large pop up. It shows one character per cell, in colour, with a number under each one. That way you cannot mix up a zero and a letter O. The pop up hides itself after 30 seconds. The copy icon copies the password without showing it. Use the entry name to open the whole record.

How are vault passwords protected?

Each secret field is encrypted on its own with AES-256-GCM. The password, the code secret and the notes each get their own key parts. The key for a client is worked out from one master key kept just for the vault. That master key is held apart from every other secret. User names are not encrypted. Every reveal and every copy is stamped with who did it and when.

I deleted a vault entry. Can I get it back?

Yes. Delete only archives the entry. Nothing is destroyed. Turn on Show archived above the vault list to see it. Archived rows carry an Archived badge. Use the restore arrow at the end of the row. You can also open the entry and use the Restore button in the banner at the top. Neither one asks you to confirm. An archived entry is read only. You still see its name, category, web address, user name and dates. The password and the code stay hidden. You cannot reveal or copy them until you restore it. This door is for staff. Clients never see archived items.

What is the Procedures list for?

Procedures are runbooks for jobs you do again and again, such as restarting a firewall or checking a backup. A procedure has a Title, a Description and a Status. Under those you build the steps. Add Step gives you a step title and a detail box. You can mark a step optional, move it up or down, or remove it. The list shows how many steps each one has. Clients can read procedures but never edit them.

What is the Network section for?

It holds this client's network notes in three cards. "Configurations" lists gear like firewalls, switches and routers, and "Add Device" adds one. "Networks / Subnets" lists each subnet, and "New Network" adds one. "VLANs" lists each VLAN, and "New VLAN" adds one. An empty card tells you which button to press.

Why will my new network not save?

The "Subnet / CIDR *" box has to hold a subnet written in CIDR form, like 192.168.1.0/24. Anything else is turned down and the form tells you so. A name is required too. Later, an IP you add to that network must sit inside the subnet, or it is turned down the same way.

What does the Network section hold?

Network is a section on a client's Documentation tab. It has two cards. The first, Configurations, is the gear list: firewalls, switches, routers, access points, servers, printers and more. A row takes a name, a device type, a maker, a model, a serial number, an address, a host name, a place, a firmware version and notes. You can drop a config file on the form to keep a backup. The second card holds the networks, VLANs and addresses the client uses. There is no status field. This section is hidden when the MSP module is off.

What does the Domains section hold?

Domains is a section on a client's Documentation tab. A row holds the domain, the registrar, the expiry date and whether it renews itself. It also holds the DNS provider, the name servers, the SSL expiry date and the SSL issuer. Lookup fills some of that in from public records. Auto-Discover finds domains the portal already knows about. Dates go red or amber as they get close. These rows do not feed the Expirations section. Add a row there yourself if you want it on that list. This section is hidden when the MSP module is off.

How does the Expirations list work?

Expirations is a list you keep by hand. Nothing feeds it for you. Add a row with a name, a type, a date and notes. The types are SSL Certificate, Warranty, License, Domain, Contract, Subscription and Other. Alert Days Before sets how early you get warned. It starts at 30. A date turns red inside 30 days, or once it is past. It turns amber inside 90 days. Further out it stays green. Each row shows a state: Expired, Expiring Soon or Active. Use Acknowledge once you have dealt with one. That state then wins over the rest.

What are Assets?

Assets is a section on a client's Documentation tab. Use it for gear you do not monitor, such as a rack, a monitor or a spare switch. A row ships with three fields: Name, Type and Notes. An admin can add more fields to the section. Rows take tags, files and links. You can archive a row and restore it later, the same as the other doc sections.

Does the article editor do rich text?

Yes. The toolbar has bold, italic, underline and strike through. It has headings, lists, quotes, code, tables, colour and alignment. You can add links and images. Paste an image or drag one in and it uploads by itself. There is also a picker that links the article to another record in the portal.

How do I attach a file to a doc?

Most doc types have a Files panel. Drop files on it, or use Upload. On a new record the files wait until you save, then they upload. Vault entries, articles, procedures, domains and asset style docs all have the panel. Expirations and network configurations only get it on their own edit page. Files are a staff panel. Clients never see it.

What is the Knowledge Base?

Knowledge Base is a section on a client's Documentation tab. It holds write ups for that client. Think network notes, or how you set something up. A new article asks for a Title and Content. You can add a Resolution, a Category, a Folder and Tags. Both text boxes take rich text. Articles are searchable. To let the client read one, open it. Find the Client Visibility panel. Turn on Visible to all client users. Or name people under Visible to specific users. MSP Only (internal) keeps an article away from every client.

Can I share a vault entry with a client?

Yes. Open the entry and find the Client Visibility panel. It has three controls. MSP Only (internal) hides the entry from every client. That one wins over the rest. The sharing switch reads Visible to all client users or Hidden from client portal. Visible to specific users lets you name people instead. The vault list also has a lock icon per row for MSP Only, and a Shared chip. One thing you cannot do is open what a client keeps in their own My Vault. Staff are shut out of it, even while viewing as them.

Was this helpful?

Last validated 2026-09-16