Technical · Course T8Lesson 1 of 4
The reseller console and the hierarchy
7 min read- Navigate the reseller console's six working areas
- Explain the distributor → reseller → customer hierarchy and where you sit in it
- Predict which actions your partner tier can and cannot perform
The reseller console is a different product from the customer console, and confusing the two is the most common orientation mistake new partner staff make. The customer console manages devices. The reseller console manages customers.
What's in it
Six working areas, plus a What's New feed:
| Area | What you do there |
|---|---|
| Dashboard | Portfolio overview, for partners with account-wide access |
| Accounts | Create and manage customer tenants — the heart of the console |
| Roles & Permissions | Manage your own team's users and what they can do |
| Policy Templates | Reusable policy configurations to seed new customers |
| Plans | Author, clone, and assign the feature plans that gate customer consoles |
| Settings | Your own account security settings |
Notice what isn't here: no Devices, no Policies-in-the-customer-sense, no Apps. To work inside a customer's fleet you enter their console — the reseller portal is where you decide what that console contains.
Accounts is the real home screen. The dashboard is reserved for partner users with account-wide access; everyone else is routed to their default landing, which is the customer list. That's a design statement worth internalizing: a partner's daily work starts from the list of customers, not from a metrics page.
The hierarchy
WeGuard models the channel explicitly: distributor → reseller → (sub-reseller) → customer. Your position in that chain determines both what you see and what you can create.
The chain isn't decorative — it's validated at account creation. Creating a reseller account requires a distributor to hang it from; creating a customer account requires both a distributor and a reseller. When you're operating inside your own partner org, those parents are implied by who you are; when a distributor-level user creates accounts on behalf of others, they select them explicitly.
This is also why access is naturally scoped: a partner user sees the accounts beneath
them in the tree, and nothing beside or above. Sub-reseller creation is itself a
gated capability (newSubResellerActCreation), which matters for distributors
building multi-tier channels.
Capabilities are gated, per partner
The console's actions are individually switchable per partner org — creating and updating plans, deleting plans, updating policy templates, deleting policies, adding or removing your own team members, and changing their permissions are all separate capability flags.
The practical consequence: two partners can see the same console with different buttons. When a colleague at another partner describes an action you don't have, that's usually your org's configuration rather than a bug or a version difference — and it's a conversation with your WeGuard account team, not a support ticket.