Academy
Technical · Course T8

Lesson 1 of 4

The reseller console and the hierarchy

7 min read
In this lesson you'll learn to
  • Navigate the reseller console's six working areas
  • Explain the distributor → reseller → customer hierarchy and where you sit in it
  • Predict which actions your partner tier can and cannot perform

The reseller console is a different product from the customer console, and confusing the two is the most common orientation mistake new partner staff make. The customer console manages devices. The reseller console manages customers.

What's in it

Six working areas, plus a What's New feed:

AreaWhat you do there
DashboardPortfolio overview, for partners with account-wide access
AccountsCreate and manage customer tenants — the heart of the console
Roles & PermissionsManage your own team's users and what they can do
Policy TemplatesReusable policy configurations to seed new customers
PlansAuthor, clone, and assign the feature plans that gate customer consoles
SettingsYour own account security settings

Notice what isn't here: no Devices, no Policies-in-the-customer-sense, no Apps. To work inside a customer's fleet you enter their console — the reseller portal is where you decide what that console contains.

Accounts is the real home screen. The dashboard is reserved for partner users with account-wide access; everyone else is routed to their default landing, which is the customer list. That's a design statement worth internalizing: a partner's daily work starts from the list of customers, not from a metrics page.

The hierarchy

WeGuard models the channel explicitly: distributor → reseller → (sub-reseller) → customer. Your position in that chain determines both what you see and what you can create.

The chain isn't decorative — it's validated at account creation. Creating a reseller account requires a distributor to hang it from; creating a customer account requires both a distributor and a reseller. When you're operating inside your own partner org, those parents are implied by who you are; when a distributor-level user creates accounts on behalf of others, they select them explicitly.

This is also why access is naturally scoped: a partner user sees the accounts beneath them in the tree, and nothing beside or above. Sub-reseller creation is itself a gated capability (newSubResellerActCreation), which matters for distributors building multi-tier channels.

Capabilities are gated, per partner

The console's actions are individually switchable per partner org — creating and updating plans, deleting plans, updating policy templates, deleting policies, adding or removing your own team members, and changing their permissions are all separate capability flags.

The practical consequence: two partners can see the same console with different buttons. When a colleague at another partner describes an action you don't have, that's usually your org's configuration rather than a bug or a version difference — and it's a conversation with your WeGuard account team, not a support ticket.

Knowledge check
1. Which areas make up the reseller console?
2. Most partner users land on Accounts rather than Dashboard because…
3. When creating a customer account, what does the hierarchy require?