Agencies search for “sub-accounts” because that is the word most tools use for one parent login holding many client accounts underneath it. It is worth being precise about how that maps onto Shifter before building anything, because the right structure depends on it.
On Shifter there is no sub-user inside a plan. The unit that does the job of a sub-account is a workspace: a self-contained space with its own plans, wallet, invoices and team, which the same person can belong to many of, switching between them from the sidebar. Usage is tracked per plan. Get those two facts into your structure and everything else follows.
What a sub-account needs to do
Strip the terminology away and an agency wants four things from a client sub-account.
| Requirement | What it means | How Shifter provides it |
|---|---|---|
| Isolation | One client’s traffic and budget never mix with another’s | Plans never cross workspaces |
| Attribution | You can say what each client cost | Usage is reported per plan |
| Access control | The right people see the right things | Viewer, Billing and Admin roles per workspace |
| Clean offboarding | A client leaves without disturbing anyone else | Remove members, close the client’s plans |
The rest of this guide is choosing how to arrange workspaces and plans so all four hold at once.
Two structures that work
Client-owned workspaces
Each client owns its own workspace. The client funds the wallet and receives the invoices. The agency’s account lead is invited into each client workspace as an Admin and runs the collection from there.
This is the cleanest arrangement when clients are happy to hold their own billing relationship. Isolation is absolute, attribution needs no work because each client’s invoice is its own, and offboarding is the client removing the agency from their workspace. One agency login reaches every client through the workspace switcher.
Agency-owned workspace, one plan per client
The agency owns one workspace, buys a separate plan for each client inside it, and bills clients from each plan’s usage.
This suits agencies that resell collection as part of a retainer. Attribution holds as long as the rule is strict: one client, one plan, never shared. Two consequences are worth knowing before choosing it.
- The wallet is scoped to the workspace, and overage on any plan is covered from that wallet. Every plan in the workspace draws on the same pot, so one client’s spike can consume headroom another client depends on. Watch overage per plan closely, or give high-volume clients their own workspace.
- Everything inside a workspace is visible to its members. Do not invite a client contact into a shared agency workspace, even as a Viewer, because they would see every other client’s plans and invoices.
Many agencies end up with a hybrid: client-owned workspaces for large accounts that want their own billing, and one agency workspace holding plans for smaller clients billed on retainer.
Setting it up
The mechanics are the same for either structure.
- Open the Team page in the workspace you want to manage, from the panel sidebar.
- Invite by email and pick a role. An existing Shifter user gets a one-click Join the next time they sign in and keeps their own account. A new email becomes a short signup with a magic link and no password.
- Switch between workspaces from the dropdown in the sidebar, which appears once you belong to more than one. Everything on screen, plans, wallet, invoices, team, changes with it.
- Buy each client’s plan in the workspace it belongs to. Plans do not move between workspaces afterwards, so buying in the wrong one means buying again.
Each workspace has a soft cap of 10 seats. If you need more for a large client, that is a conversation with support rather than a hard limit. Workspace ownership can also be transferred on request if a client relationship changes shape.
The feature itself is described in introducing Team Workspaces.
Choosing roles
Keep roles to the minimum each person needs.
| Role | Can do | Give it to |
|---|---|---|
| Viewer | See plans, traffic and invoices; browse the catalogue | A client stakeholder who wants to see usage, in their own workspace only |
| Billing | Everything a Viewer can, plus fund the wallet, pay invoices and buy or upgrade plans | Whoever holds the card, on either side |
| Admin | Everything Billing can, plus manage plans and the team | The agency account lead running collection |
Roles are per workspace, not global. The same person can be an Admin in one client’s workspace and a Viewer in another’s, and the role in the active workspace is always the one enforced.
Tracking usage per client
Each plan has a real-time usage view in the panel, on the dashboard overview and on the plan’s own page, updating every minute. It shows the bandwidth remaining in the cycle, a daily consumption trend, and the top traffic destinations by hostname.
Those three together are enough to run client attribution well.
Remaining bandwidth tells you whether a client is on course to finish the cycle inside its allowance.
The daily trend shows when consumption changed, which is usually a new job, a crawler running away, or a client asking for a larger scope without saying so.
Top destinations by hostname is the underrated one. It lets you check that each client’s plan is actually hitting that client’s targets. A plan whose top destination belongs to a different client’s competitor set is a plan with the wrong credentials in a job somewhere.
What usage tracking does not do is split a plan’s traffic after the fact. It does not break usage down by session ID or by which of your jobs sent it. If several clients run through one plan, there is no way to separate them later, which is exactly why the one-plan-per-client rule matters.
A monthly operating routine
Attribution is a habit rather than a report you run once.
- At the start of each cycle, note each plan’s opening allowance and the cycle dates.
- Weekly, compare each client’s consumption against its expected run rate, and reforecast month-end usage as consumed bandwidth divided by elapsed days, times days in the cycle.
- When a trend jumps, check the top destinations before assuming the client’s scope grew.
- Before the allowance runs out, decide per client whether overage should flow from the wallet or whether the job should pause. Overage on residential plans is billed from the wallet at the plan’s own per-GB rate.
- When a client leaves, remove their people, retire the plan’s credentials from every job, and close the plan.
The forecasting method behind the weekly check is in forecasting residential proxy bandwidth.
Credentials are the other half of isolation
Workspaces keep plans apart. Your own systems have to keep credentials apart.
Each plan has its own credentials. Store them per client in your secret manager, give each client’s jobs only that client’s plan, and never copy one client’s credentials into another’s job to get something done quickly, because that is how attribution silently breaks. Do not log full proxy connection strings, which are the most common way credentials leak into a log aggregator.
Session IDs remain yours to name however you like. Prefixing them with a client code, sid-acme-serp-01, costs nothing and makes your own logs readable, even though the panel does not break usage down by them.
FAQ
Does Shifter have sub-users inside a plan?
No. Access is managed per workspace with three roles, and isolation between clients comes from separate plans and, where needed, separate workspaces.
How many clients can one agency login manage?
A single login can belong to as many workspaces as needed, switching between them from the sidebar. The 10-seat soft cap applies per workspace, not per login.
Can a client see our other clients?
Not across workspaces. Within one workspace, every member sees everything, which is why client contacts should only ever be invited into their own workspace.
Can I move a plan from one client to another?
Plans stay in the workspace they were bought in. Buy each client’s plan in that client’s workspace from the start.
The bottom line
The sub-account an agency is looking for is, on Shifter, a workspace, and the unit of attribution is a plan. Give every client its own plan without exception, choose client-owned workspaces where clients hold their own billing and a shared agency workspace where you resell, keep client contacts out of shared workspaces, and read usage per plan every week rather than at invoice time.
Structured that way, isolation, attribution, access and offboarding all come for free. The product is on the residential proxies for agencies page, with rates on the pricing page.