Skip to main content

Activate: A Guide for MSP Partners

What Activate is and how to use each part of it: the dashboard, the five prospect tabs, tenant creation, and inviting contacts.

Activate is where you turn your existing customer base — and any new prospects — into Hatz tenants. It pulls in your book of business from your PSA (or a CSV upload), researches each company automatically, helps you make the AI-readiness case, and lets you generate and send sales material, all before you provision the real tenant. This guide walks through the main Activate dashboard, each tab you'll use when working an individual prospect, and how tenant creation and invitations work.

Who this is for

Activate is used by MSP admins and sales reps. Access depends on your role: not every role can open Activate, and among the roles that can, not every one can create a tenant. See Which roles can use Activate at the end of this article.

If you don't see Activate in your navigation and think you should, contact Hatz support.

The Activate dashboard

When you open Activate, you land on a single list of every prospect and customer you're working — imported from your PSA, uploaded by CSV, or added one at a time.

Getting customers in

Connect PSA. Pick HaloPSA, ConnectWise Manage, or Datto Autotask (other providers show as "Coming soon"), then enter that provider's credentials — each field links out to that provider's setup guide. Once you submit, Activate saves the credential and immediately runs a first sync. If saving the credential fails, nothing is synced; if the credential saves but the first sync fails, you'll be told to retry from the connections menu described below.

The sync is read-only. Activate never creates, modifies, or deletes records in your PSA. From each active customer record it reads and stores only a short list of fields:

  • Company name

  • Website domain

  • Primary contact name

  • Primary contact email

  • That record's identifier in your PSA, so a later sync updates the same customer instead of duplicating it

Nothing else from your PSA is stored, and your credentials are encrypted at rest. The connection stays active after the first sync, so you can re-sync whenever your client list changes. Which records are eligible differs slightly by provider — the provider-specific articles cover the exact rules.

Once connected, a status pill appears showing your PSA connection(s):

  • A green dot means healthy; a red dot means at least one connection has an error.

  • Opening it shows, per connection: when it last synced ("Synced 3 hours ago" / "Never synced"), any sync error inline, a Sync now action, and a Disconnect action.

  • Sync now re-pulls your client list and reports the result the same way the first sync does: "Synced — N added, M updated, K removed."

  • Disconnect asks you to confirm first, and tells you exactly what happens: syncing stops, but customers already imported stay in your table — they just won't refresh on future syncs. You can reconnect later with the same credentials.

  • There's no separate "rotate credentials" option. To change credentials for a provider, disconnect and connect again.

Import CSV. Your file needs a company name column (required) plus optional primary contact name, contact email, and domain columns — Activate auto-detects common header variations (e.g. "Company," "Account," or "Organization" all map to company name), so there's no manual column-mapping step. If it can't find a company name column at all, the upload is blocked with a pointer to the sample file. Use the Download sample CSV link if you want a template to start from.

After upload, every row appears in an editable review step — fix a bad email or missing company name inline before submitting, or remove the row. Company name is required and must be unique within the file; a duplicate (case-insensitive) or invalid email blocks that row until fixed. The import caps at 5,000 rows per upload. When you submit, you'll see "N customers imported, M rows skipped," and if any rows failed (in review or on the server), a Download failed rows button gives you back the original file with an added error column, ready to fix and re-upload.

Revenue calculator

A banner near the top estimates the monthly recurring revenue and margin you could generate from your imported customer count, based on your own package pricing. It's there even before you've imported anyone, so you can model potential earnings from a hypothetical book size.

The customer table

Columns, left to right: a selection checkbox, Customer (name + date added), Source (PSA provider logo, or a CSV icon), Status, Stage, Tenant (the linked tenant's name, once one exists), Domain, and Action.

Status reflects tenant-linkage state, not deal progress:

  • Connected (green) — a tenant is confirmed and linked.

  • Needs Review (purple) — your PSA sync suggested a likely matching tenant, but no one's confirmed it yet. This takes priority over the next state even if the PSA also marked the client inactive.

  • Inactive (gray) — a PSA-sourced customer the PSA itself has marked inactive or closed, with no tenant match pending.

  • No badge — no tenant match was found and the customer is active. This is the normal state for a customer who isn't in Hatz yet; their action is Create tenant. See "Matching customers to existing tenants" below.

Stage tracks how far along the pitch is: Imported → Enriched → Assessed → Ready to Pitch. These four update automatically — enrichment moves a customer from Imported to Enriched, completing the assessment moves it to Assessed, and selecting a template in Use Cases moves it to Ready to Pitch. Note that creating or linking a tenant does not currently advance this Stage value any further — that progress instead shows up in the Status and Tenant columns. Don't rely on Stage alone to tell whether a tenant has been created; check Status and Tenant for that.

Action shows one of three buttons, depending on where the customer stands:

  • Create tenant — no tenant exists yet for this customer. Opens the create-tenant dialog directly (see "Creating a tenant" below).

  • Review match — your PSA sync found a likely existing tenant for this customer but hasn't confirmed it. Opens a side panel (distinct from the full prospect page — see the note below) where you can confirm the suggested tenant, link a different one, or create a new one instead.

  • Invite — a tenant is already linked. Opens an invite to that tenant's first user (see "Inviting a contact" below).

Use the search box and the source/status/stage filters above the table to narrow the list.

The "Review match" panel is not the prospect's detail page. Clicking a row opens the full prospect page with its five tabs (below) — that's where you do all your enrichment, assessment, and resource work. "Review match" opens a separate, narrower side panel used only to confirm or correct a PSA-suggested tenant match, or to create a tenant from that panel instead. Don't confuse the two: it has no tabs, and it's only reachable via the Action column, not by clicking into the row itself.

Bulk actions

Select multiple rows to export them to CSV, or to create tenants for several prospects at once (see "Creating a tenant" below for what the bulk flow asks for).

Click into any row (not a Review Match/Create Tenant/Invite button) to open that prospect's full detail page — this is where you'll spend most of your time, organized into five tabs.

Overview tab

Your at-a-glance summary of everything Activate knows about this prospect.

  • Company Information — industry, size, and a short description of what they do. This fills in automatically when you run enrichment (below), and you can edit any of it by hand.

  • Key Contacts — the prospect's decision-makers and their emails. A contact synced from your PSA appears as the primary contact automatically; add others manually or let enrichment find them.

  • Data Exposure & Shadow AI Risk — an AI-generated assessment of what sensitive data this company's employees may be putting into AI tools you don't control, based on their industry and profile. To confirm it against real device data, run a Shadow AI Scan (below).

  • Shadow AI Scan — collect real, device-level evidence to back up (or correct) that hypothesis. See "Shadow AI Scan in depth" below.

  • Assessment Status — a summary of where the AI-readiness assessment stands, linking to the full Assessment tab.

  • Context for AI — a free-text note where you can add anything specific to this deal (e.g., "the CFO is the real decision-maker and is skeptical of new tools"). Anything you write here shapes the pitch material Activate generates later.

Use Run Enrichment at any time to have Activate (re-)research the company and refresh these sections automatically. Each section updates as its results land, so you can watch progress rather than waiting on the whole run.

Enrichment doesn't always fill in everything. A run can come back partially complete — some sections populated, others left as they were — usually because there wasn't enough public information about that company to go on. A run can also fail outright, in which case nothing is overwritten and the customer stays at the Imported stage. In both cases you can simply run it again.

One thing to watch: while a run is writing to a section, that section's edit controls are locked, and an edit you had open on it closes without saving. Save any manual changes before starting a run rather than during one.

Shadow AI Scan in depth

The Data Exposure & Shadow AI Risk card is inferred from the prospect's industry and company profile. A Shadow AI Scan reports what is actually in use on the prospect's own managed devices: which AI tools, on how many machines, and how many people are affected.

How it works, step by step:

  1. Download the collector script. Two versions are available: a PowerShell script for Windows, or a shell script for macOS/Linux.

  2. Add the ingest link to your RMM. Starting a scan generates a one-time ingest link, unique to this one prospect. Deploy it through your RMM of choice (NinjaRMM, ConnectWise, Datto) or a GPO task, passing the link to the script as a parameter.

  3. Deploy and wait. Run the script across this prospect's managed devices. It reads browser history (Chrome, Edge, Brave, Opera, and Firefox), installed applications, IDE extensions, and globally installed npm packages, matches what it finds against a list of known AI tools, and reports back. Findings appear on the card automatically as devices report in — no manual refresh needed.

What the scan does and doesn't do:

  • A scan is a point-in-time snapshot, not ongoing monitoring. The collector runs once on a device, reports what it found, and exits. Nothing is installed and nothing keeps watching the device afterward. Findings reflect the moment the script ran, so run the scan again when you need current data.

  • No Hatz API key is ever placed on customer machines — only the scoped, expiring ingest link, which ties every finding back to this one prospect.

  • The link is shown only once, at scan creation. If you lose it, you can generate a new one, but doing so invalidates the old one.

  • A scan belongs to exactly one prospect. Don't reuse a link across prospects — start a separate scan for each.

Reading the results: once devices start reporting, the card shows a risk tier (Low / Moderate / High) alongside how many devices were scanned, how many distinct AI tools were found, how many devices and users were affected, and a per-tool breakdown (tool name, category, risk level, and device count).

Managing an active scan:

  • Deploy to more devices reopens the setup steps so you can extend the scan to additional machines.

  • Stop scan requires a second confirming click (so a stray click can't cut it off) and immediately invalidates the ingest link — no further devices can report in. If you stop a scan before any device has reported, there's no evidence yet; you'll need to start a fresh scan to collect any.

Assessment tab

Manage the AI-readiness risk questionnaire for this prospect. There are two ways it gets filled out, and it's worth knowing what each looks like since you're either doing one yourself or sending the other to your prospect:

  • Filling it out yourself (Start/Retake Assessment). Opens a one-question-at-a-time wizard with a progress bar. Every question comes pre-filled with an AI-suggested answer (marked "AI suggested," with a short reasoning note) drawn from enrichment and your notes — accept it or overwrite it; editing an answer clears its AI flag. After the last question, a review screen lists every question and answer with an edit pencil next to each before you submit. Submitting calculates a risk score and level immediately.

  • Sending it to the prospect (Copy Link). The prospect gets an intro screen ("Let's check your AI readiness — takes about 3 minutes... AI has drafted some answers for you"), then the same one-question-at-a-time flow, then a review screen, then a thank-you page. Use Preview to see this exact experience yourself first — it renders the same screen the prospect sees, just read-only (view and step through, no editing, ending in "Close preview" instead of submitting).

Once an attempt exists, this tab shows its status (Not Started / Sent / Completed), and — once complete — the risk score, risk level, a plain-language summary, and a version history if it's been retaken. Before anyone has taken it, you can see a breakdown of question types and preview every question up front.

Use Cases tab

Decide which Hatz apps, workflows, and AI agents to pitch this prospect.

  • Click Suggest use cases to have Activate propose a shortlist grounded in what enrichment found, what the assessment revealed, and any notes you've added — matched against what Hatz actually offers.

  • Include or exclude any suggestion, and add your own custom use cases if you have something specific in mind.

  • This isn't a one-and-done step. As the deal progresses — enrichment turns up new information, the prospect completes the assessment, or you add new notes — click the button again (it becomes Refresh suggestions once you've generated a first round) to get an updated shortlist that reflects everything learned since. Refreshing only replaces AI suggestions you haven't included yet — anything you've already included, or added yourself as a custom use case, is left untouched.

  • MSP Template Matching ranks your own tenant templates by fit for this prospect. Selecting a template here moves the customer's Stage to Ready to Pitch, and — if your role has permission to create tenants — surfaces a Create Tenant button (see "Creating a tenant" below).

Resources tab

Your document library for this prospect, split into two sections:

  • Hatz Resources Library — sales and onboarding collateral. These document types (proposals, etc.) are defined and maintained by Hatz — you're not authoring a template from scratch, you're generating an instance of one of Hatz's documents, filled in for this specific prospect. Click Generate to have Activate write it, using everything gathered so far — company info, assessment results, and the use cases you've included.

  • Post-Sale Onboarding Templates — your own static templates (marked "MSP internal"), which you can view or download as-is. These are for your own internal use and can't be emailed to a prospect from Activate (see the Emails tab below).

Making changes to a generated document. Once a Hatz Resources Library document is generated, open it and use the "Refine this document" panel to request changes in plain language — for example, "make this shorter" or "lead with invoice automation instead." You can also click directly on a specific section to leave a note and revise just that part, leaving the rest of the document untouched. These are edits, not a redesign: you can revise wording, tone, and content, and adjust styling like font and heading color, but you can't restructure the document, add new sections, or change which document type it is — the underlying template stays the one Hatz defines.

Emails tab

A log of every email sent to this prospect's contacts, and where you send new ones.

  • Click Compose to write a new email. Recipients (To, Cc, and an optional Bcc) autosuggest from this prospect's Key Contacts, and your own address is always added to Cc automatically — you can't remove it. The body uses a full rich-text editor (formatting, lists, links), not plain text.

  • Attachments are limited to what you've generated for this prospect — a completed document from the Resources tab's Hatz Resources Library. Your own static "MSP internal" onboarding templates can't be attached here; the send is blocked if you try. Total attachments are capped at 10 MB.

  • A safety check runs before sending: if any recipient's email domain doesn't match this prospect's known domain, contacts, or your own domain, you'll get a confirmation prompt before it goes out — a reminder that prospect materials sent to the wrong company can't be unsent.

  • Each email in the log shows its subject, recipients, attachments, and a rolled-up status for the whole send. Expand a row to see where each individual address landed — Queued, Delivered, Clicked, Bounced, or Failed — with the reason shown on anything that bounced or failed, plus a link to view the email exactly as it was sent.

  • A row showing Send not confirmed means the send is still in progress and hasn't been confirmed yet. Check the per-recipient rows rather than assuming it didn't go out.

Matching customers to existing tenants

When customers sync in from your PSA or a CSV, Activate compares each one against the tenants you already manage and flags the likely matches. This is how you see at a glance which of your clients are already in Hatz and which are still prospects — without cross-referencing your PSA against your tenant list by hand, and without accidentally standing up a second tenant for a customer you onboarded months ago.

There's nothing to configure and nothing to run. Matching happens on every sync, and each customer sits in one of four states, shown in the table's Status column:

  • No badge — nothing in your tenant list resembled this customer, so they're treated as a net-new prospect. Their action is Create tenant.

  • Needs Review — Activate found a likely match but will not link it on its own. Their action is Review match.

  • Connected — the customer is linked to one of your tenants, either because you confirmed a suggestion or because you created the tenant from Activate. Their action becomes Invite.

  • Inactive — a PSA-sourced customer your PSA has marked inactive or closed, with no match pending.

Reviewing a suggested match. Selecting Review match opens a panel showing the tenant Activate thinks this customer is, a confidence indicator, and a short reason for the suggestion. From there you can:

  • Confirm the suggestion — links the customer to that tenant and moves them to Connected.

  • Link a different tenant — search your tenant list and pick the correct one if the suggestion is off.

  • Create a new tenant instead — for a customer who genuinely isn't in Hatz yet.

  • Disconnect — on an already-connected customer, unlinks it from the tenant. This only removes the link in Activate; the tenant itself and everything in it are untouched.

A suggestion is never applied without your confirmation, so a wrong guess can't quietly attach a customer to the wrong tenant. After a first sync of a large client list, working through the Needs Review rows is the quickest way to get an accurate picture of your book.

Creating a tenant

This is how a prospect becomes a real, billable Hatz tenant. You can trigger it three ways: the Create Tenant button in Use Cases (after selecting a template), the Create tenant action in the customer table, or a bulk action across a multi-selection.

For a single customer, the dialog asks for:

  • Tenant Name — pre-filled with the company's name; edit if needed (letters, numbers, spaces, hyphens, underscores, and periods only, 2–100 characters).

  • Template (optional, if your MSP uses tenant templates) — pre-selected if you already picked one in Use Cases.

  • Package — required; if you don't have an available package, you'll be prompted to buy one first.

There's no domain field and no "notify the contact" toggle here — creating the tenant does not automatically email your prospect. Once created, Activate links the new tenant back to this customer for you (reflected immediately in the Status and Tenant columns); if that last linking step fails for some reason, the tenant still exists and you can finish linking it from the customer's Review Match panel.

Creating tenants in bulk works the same way across your selection — you'll confirm a template/package per row in a verification step, then Activate creates and links each tenant, reporting how many succeeded and how many need attention.

Inviting a contact

Once a tenant is linked to a customer (Status shows Connected), the Invite action appears in the table. It opens the standard Hatz invite flow, pre-filled with the prospect's known contact email if you have one (edit or replace it if needed), and lets you choose to invite by email (pick their role, and Hatz sends the invite) or generate a shareable invite link instead. This invites the contact into the tenant you just created — it's the same invite experience used elsewhere in Hatz, just started for you from Activate.

Which roles can use Activate

Access to Activate, and access to the Create Tenant button within it, are two separate permissions — having one doesn't guarantee the other. Here's how role access breaks down:

  • Primary Admin — can access Activate, and can create a tenant.

  • Admin — can access Activate, and can create a tenant.

  • Sales User — can access Activate, but cannot create a tenant.

  • Tenant Manager — cannot access Activate.

  • Compliance Manager — cannot access Activate.

  • Billing Manager — cannot access Activate.

  • Helpdesk — cannot access Activate.

A Sales User can work a prospect through every tab — enrichment, the assessment, use cases, resources, and emails — but won't see the Create Tenant button, since that needs tenant-creation permissions on top of Activate access. That's by design: a Sales User can fully prepare a prospect (template selected, use cases picked, proposal generated) and then hand off to a Primary Admin or Admin to provision the actual tenant.

Roles without Activate access at all — Tenant Manager, Compliance Manager, Billing Manager, and Helpdesk — won't see Activate in their navigation, even though Tenant Manager and Compliance Manager separately hold tenant-creation permission for other parts of Hatz.

Did this answer your question?