Why multi-domain Five9 needs governance

Running one Five9 domain is an admin job. Running twenty is a business — and the failure modes change. A contractor with credentials to every client. A bulk edit that hit the wrong portfolio. A customer asking “who changed our routing last Tuesday?” when everyone shares the same Five9 login. The tools that were fine for one domain quietly become your biggest liability at portfolio scale.

9Vault was built for exactly this shape of team. Every customer domain lives in one workspace with shared, encrypted credentials — and Fuse layers object-level access governance, approval workflows, and complete audit trails over the top, so precision control doesn’t mean disrupting the workflow your engineers already know.

Built by practitioners. 9Vault is an independent platform made by people who run Five9 VCC domains every day — including the multi-customer kind. Governance here isn’t a compliance checkbox; it’s the difference between scaling your practice and scaling your risk.

One workspace for the whole portfolio

Everything starts with credentials. Each customer domain’s Five9 API login is stored once, encrypted with AES-256, and shared across the team — engineers use the connection without ever handling the secret. Environment labels (dev, uat, prod) travel with each credential, and the prod label automatically activates production governance on restores and promotions.

  • Connection tests with permission reporting — verify each domain’s login and see what its API account can actually do; readiness checks flag credentials that haven’t been tested in about 30 days.
  • Consistent posture per customer — the same scheduled backup and promotion pipeline patterns, applied uniformly across every tenant instead of reinvented per engagement.
  • Roles that match a services team — owners control roles, MFA policy, and billing; admins manage the team; editors get only the permissions you toggle on: backup, restore, import, export, credential management, VCC edits.

Access control that fits how MSPs work

Fuse decides access in layers, and a member can act only when every applicable layer allows it. Capabilities control what a member may attempt. Access grants control where — scoped by platform, domain, object type, or even a single object id, with explicit allow or deny effects (and deny always wins). And because entering a domain’s credential implies direct access, credential-derived scope is granted automatically — and can be explicitly restricted by an owner when it shouldn’t be.

On top of the grants, tenant-wide governance rules set the guardrails everyone works inside:

  • Delete mode — deletes are owner/admin-only by default, or routed through the approval queue for granted members.
  • Cross-portfolio rules by object type — allow, allow-with-approval, or block actions that reach across portfolio boundaries.
  • Approval workflow — gated actions land on an approvals queue where an admin or owner approves or denies with comments; stale requests expire automatically on your TTL.
Fuse Policy
Acme Retail portfolio
subject sara@acme
portfolio Acme Retail
objects campaigns, skills
update → require approval
bulk → require approval
delete blocked
One engineer. One portfolio. Exact blast radius by design.

The result: a new engineer’s blast radius is a policy decision, not an accident of which passwords they happen to know.

Who did what — even on shared logins

The classic multi-domain audit problem: five engineers share one Five9 service account, so the native audit log says the same username did everything. 9Vault solves this because it isn’t a bystander — it’s a fully functional Five9 configuration editor. Your engineers view, edit, bulk-modify, and manage VCC objects directly inside 9Vault, each signed in as themselves, and the platform records who actually did the work as it happens.

Team Activity captures every meaningful write — VCC changes, credential and team edits, backups, restores, change requests — attributed to the real member’s email, with login, MFA, and session events alongside. Cross-check against the Five9-side audit log and matched rows show the actual 9Vault actor next to the shared Five9 username.

Governance decisions get their own trail: Policy Activity records every grant, policy change, and approval decision, so “who allowed what, and when?” has a filterable answer. Retention for both logs is configurable, and owners can require MFA for the whole team.

What Fuse gives you

Multi-domain governance isn’t one feature — it’s a posture. These are the pieces that make it hold at portfolio scale.

Portfolio Access Control

Scope write access by portfolio, domain, object type, or a single object. Explicit deny beats any allow, so exceptions are enforceable, not aspirational.

Change-request approvals

Route governed writes and deletes through an approval queue with comments, decision history, and automatic expiry — sign-off without a meeting.

Member-attributed audit

Every write is tied to the real team member, even when everyone works through one shared Five9 credential — the answer to “who changed this?” is a filter, not an investigation.

Shared encrypted credentials

AES-256 credential vault shared across every core. Engineers use connections without touching secrets; owners restrict domain access per member when needed.

Roles & per-member permissions

Owner, admin, and editor roles with per-editor toggles for backup, restore, import, export, credentials, and VCC edits — new invites start with everything off.

MFA & retention controls

Enforce multi-factor authentication for the whole team and set retention windows for activity and policy logs to match each client’s compliance posture.

And governance compounds with the rest of the platform: 9Vault backup keeps every domain’s backup posture uniform, Relay runs named pipelines per customer with two-person PROD approvals, and Lumen documentation plus run manifests give you client-ready proof of work for every engagement.

FAQ

Is this a Five9 product?

No — 9Vault is an independent product from 9Vault, LLC, built for teams that run Five9 VCC. Your customers’ Five9 relationships stay exactly as they are; 9Vault adds the management and governance layer your practice operates in.

Everyone shares one Five9 service account. Can we still tell who did what?

Yes — because the work itself happens inside 9Vault. The platform includes a full Five9 configuration editor, so engineers make their changes signed in as themselves rather than as the shared service account. Every write is recorded against the member’s own email in Team Activity, and matched changes on the Five9-side audit log show the real actor alongside the shared Five9 username.

Can I restrict a contractor to a single customer’s domain?

Yes. Grant them scoped access to just that platform, domain, and the object types they need — or add explicit deny rules that override everything else, including credential-derived access. Deletes can be blocked outright or routed through approval.

Will approvals slow my team down?

Only where you choose friction. Approvals apply to the actions you gate — cross-portfolio writes, deletes, PROD promotions — while everyday work inside a member’s granted scope runs untouched. Pending requests expire automatically on your TTL, so the queue never becomes a backlog.

How do onboarding and offboarding work?

New members join as editors with every permission off — you enable exactly what their role needs. Offboarding is one action: suspend or remove the member, and their access ends immediately without touching any customer’s Five9 credential, because they never had it.

Scale your Five9 practice, not your risk

Tell us how many domains you run and how your team is structured — we’ll map a governance model that fits.

Contact 9Vault