Anythink for agencies

Run a backend for every client from one set of reusable models, roles and workflows, with a project per client, separate environments, branding and a clean handover.

Last updated

An agency builds the same kind of thing again and again, for different clients. Each client needs their own data, their own people signing in and their own look, but you don't want to rebuild the data model, the roles and the automations from scratch every time. And when the work is done, the client expects to take it over.

On Anythink, a client is a project, or a small set of them. You keep one template project that holds what you reuse, copy it into each new client project with anythink migrate, brand the Anythink dashboard for the client, invite the right people and, at the end, hand the client the keys. Each step below shows the Anythink dashboard, the CLI and an AI assistant (MCP), and links to the guide that covers the detail.

This page is for agencies, freelancers and in-house teams that look after several customers. If you haven't used Anythink before, read Core concepts first.

What you'll build#

  • A billing account for each client, so costs, invoices and access stay apart.
  • An agency-template project that holds your reusable data model, roles, menus and workflows.
  • For one example client, Acme, three projects: acme-dev, acme-staging and acme-prod.
  • Roles for your own staff and for the client's team, and invitations for both.
  • Acme's name, logos and colours in the Anythink dashboard.
  • A handover that leaves the client in control and your staff out, or on a lower level of access if you keep supporting them.

An agency is not a built-in object. There's no "agency" level above billing accounts. You get the structure by how you use billing accounts, projects, roles and migrate.

Step 1: Give each client a billing account and a project per environment#

A billing account is the organisation that pays. It holds the payment method, the invoices and the team, and every project belongs to exactly one billing account. Everyone on a billing account can see all of its projects, so a billing account per client keeps one client's projects out of sight of another's people. A project can't change billing account later, so create the client's account first and put their projects in it from the start.

Inside the client's account, an environment is a project. Each has its own database, API, files, users, keys, secrets and plan, so a mistake in development can't touch production. Use one naming pattern for every client: <client>-dev, <client>-staging and <client>-prod. A plan is chosen per project, so a small plan can cover development and staging while production gets the plan the traffic needs.

In the Anythink dashboard

  1. Open My Anythink and select Accounts in the sidebar. Create an account with Organization Name Acme Ltd, the client's billing address as Admin Email, a Currency and a Billing Cycle Day of Month. Select Create Account.
  2. Use the account selector to switch to it. Open the account and select Create Project.
  3. Enter the Project Name acme-dev, choose a plan and select Create Project. Repeat for acme-staging and acme-prod.
  4. Wait for each project to show Active before you open it.

The Admin Email receives invoices, and a paid plan needs a payment method on the account first. See Account, billing and projects.

With the CLI

bash
anythink accounts create --name "Acme Ltd" --email billing@acme.com --currency gbp
anythink accounts list
anythink accounts use a1b2c3d4

anythink plans
anythink projects create "acme-dev" --plan <plan-id> --region lon1
anythink projects create "acme-staging" --plan <plan-id> --region lon1
anythink projects create "acme-prod" --plan <plan-id> --region lon1
anythink projects list

accounts use sets the active billing account that projects create and projects list then use. Replace <plan-id> with a full id from anythink plans. Run projects list until each project says Active, then save a profile for each:

bash
anythink projects use acme-dev
anythink projects use acme-staging
anythink projects use acme-prod
anythink config show

projects use names each profile after the project, in lower case with hyphens.

With an AI assistant (MCP)

text
Create a billing account called Acme Ltd with billing email billing@acme.com and make it active. Show me the plans, then create projects acme-dev, acme-staging and acme-prod in lon1 on the plan I choose.

The assistant runs accounts_create, plans, projects_create and projects_list. See Connect Claude to your backend with MCP.

The active CLI profile is shared by every terminal and tool on your machine. On an agency machine with many clients, that's an easy way to change the wrong client's project. Name the profile on every command that changes data:

bash
anythink --profile acme-staging entities list

--profile applies to that command only. Environments and migrating data covers profiles and the full promotion checklist.

Step 2: Build a template project once#

Make one project that is never a client's. Call it agency-template and keep it on your own billing account. It holds what you reuse: the data model your projects usually start from, the roles you give to staff and to client teams, a sidebar menu, and any workflow you tend to want. You keep improving it, and copy it forward to new clients.

Here the template carries one entity and two roles.

Entity Field Type Notes
enquiries name Small text Required. The name field.
enquiries email Small text Required.
enquiries message Large text
enquiries status Small text, select display Options new, in_progress and closed. Default new.
Role enquiries Notes
Agency staff read, create, update, delete For your own developers. Also tick the model and workflow permissions they need.
Client editor read, create, update For the client's team. No delete, no model changes.

In the Anythink dashboard

  1. Open agency-template. Go to Settings › Data Model, select Add Entity, name it enquiries and select Create Entity.
  2. Add the four fields from the table. For status, choose the Select display and add the options.
  3. Open Settings › Users and select the Roles & Permissions tab. Select +, enter Agency staff, tick API Access and select Create Role. Repeat for Client editor.
  4. Select each role. Under Data Model Permissions, tick the actions from the table, then select Update Role.
  5. Add a sidebar menu for the client role, so Client editor sees only enquiries. See Menu configuration.

With the CLI

bash
anythink --profile agency-template entities create enquiries
anythink --profile agency-template fields add enquiries name --type varchar --required --name-field
anythink --profile agency-template fields add enquiries email --type varchar --required
anythink --profile agency-template fields add enquiries message --type text
anythink --profile agency-template fields add enquiries status --type varchar --display select --options "new,in_progress,closed" --default new

anythink --profile agency-template roles create "Agency staff" --description "Agency developers"
anythink --profile agency-template roles create "Client editor" --description "A person on the client's team"
anythink --profile agency-template roles list

Note: Role permissions are managed in the dashboard. Use the steps above, including to tick API Access. The CLI can then show you what a role holds with anythink roles permissions list <role-id>.

With an AI assistant (MCP)

Note: Role permissions are managed in the dashboard. Your assistant can create the roles and show what they hold, and walk you through ticking the permissions.

text
In agency-template, create an enquiries entity with a required name that is the name field, a required email, a large text message, and a select field called status with new, in_progress and closed and a default of new. Then create roles Agency staff and Client editor and list them.

The assistant runs entities create, fields add and roles create through the cli tool. For every field type, see Model your data. For roles, see Roles and permissions and Permissions reference.

Add a workflow to the template#

A workflow you want in every client project, such as an email to the client when an enquiry arrives, belongs in the template too. Build and test it once there. See Build your first workflow and Workflow recipes for building one.

In the Anythink dashboard

  1. In agency-template, open Workflows and create the workflow with its trigger and steps.
  2. Test it with a record, then leave it disabled in the template, so it never sends anything from there.

With the CLI

bash
anythink --profile agency-template workflows export 12 -o notify-new-enquiry.json

The exported file loads into any project with workflows seed. Put {{KEY}} placeholders in values that differ for each client, such as the recipient's address, and fill them at seed time.

With an AI assistant (MCP)

text
In agency-template, export workflow 12 to notify-new-enquiry.json.

The assistant runs workflows export through the cli tool.

Step 3: Roll the template out to a client#

anythink migrate copies one project's setup into another. It reads the source, compares it with the target by name and creates what the target is missing. Always run it with --dry-run first, and check the --to profile before the real run, because migrate writes to the target.

bash
anythink migrate --from agency-template --to acme-dev --include-roles --include-menus --include-workflows --dry-run
anythink migrate --from agency-template --to acme-dev --include-roles --include-menus --include-workflows

It copies every non-system entity with its fields and relationships, and with the flags above, roles with their permissions, menus and workflows. Include menus together with roles, because a menu belongs to a role. Workflows arrive disabled, so nothing runs until you've set up the client's secrets and connections and switched it on.

Three things to know when you reuse a template:

  • It only adds. Anything that already exists on the target is skipped, so a later change to a field in the template isn't applied to a project that already has it. Make that change in the client's project directly.
  • It doesn't copy people or credentials. Users, API keys, secrets, integration connections and email templates are set up in each project.
  • Don't copy records unless you mean to. Leave --include-data off for a client project, unless the template holds reference data they should start with.

For a workflow you want to place with client-specific values, load the exported file instead:

bash
anythink --profile acme-dev workflows seed notify-new-enquiry.json --var notify_email=hello@acme.com --enabled

--var fills {{notify_email}} and --enabled switches the workflow on.

In the Anythink dashboard

The Anythink dashboard has no migrate screen. To copy by hand, create the same entities, roles and menus in the client's project. Use the CLI for anything beyond a few entities, because it keeps options and relationships identical.

With the CLI

Use the commands above. With no --include-* flag, migrate asks which parts to copy, so name them with flags in a script.

With an AI assistant (MCP)

text
Preview a migration from agency-template to acme-dev that includes roles, menus and workflows. Show me the summary and don't change anything.

The local anythink-mcp server runs migrate through its cli tool. It has no terminal to ask which parts to copy, so name them in your request. Review the dry-run summary before you ask for the real run. See Environments and migrating data for what each flag copies.

Build the client's real work in acme-dev, then promote it forward with the same command, from acme-dev to acme-staging, and from acme-staging to acme-prod.

Step 4: Invite your staff and the client's team#

There are two kinds of people, and you manage them in different places.

  • Account access is a level on the billing account: Viewer, Admin or Owner. It decides what someone can do in My Anythink: see projects and invoices, create and delete projects, manage the team.
  • Project access is an invitation to a project with a role. It's what gives a person a seat in the Anythink dashboard and decides what they can do there.

Invite agency staff with a project role such as Agency staff, and the client's team with Client editor. Give your own people Admin on the billing account if they create projects, and the client's decision-makers Viewer, or Owner for the person who will take over (step 7). Seeing a project in My Anythink isn't the same as having a seat in it, so a billing account Viewer can't open a project they haven't been invited to.

In the Anythink dashboard

  1. Open the client's account and select Manage Team. Owners can select Invite User, enter an Email Address and choose an Access Level, then select Send Invitation.
  2. Open a project, find Team Access and select Invite User. Enter the Email Address, choose a Role such as Client editor and select Send Invitation.
  3. Repeat for each environment. Give the client's team a seat in acme-staging and acme-prod, and keep acme-dev for your staff.

Someone who already uses My Anythink is added straight away. A new person gets an email with an invitation link that lasts 7 days. Pending invitations can be cancelled or resent. To take access away, remove the person from the project's user list, or from the account team.

With the CLI

Invitations to a project and to a billing account are sent from My Anythink. Use the steps above. The CLI helps with the roles you'll invite people into:

bash
anythink --profile acme-prod roles list

anythink users invite is for a different job: it creates an app user inside a project, for example one of the client's customers signing in to the client's app. Invite rather than create with a password, so they set their own:

bash
anythink --profile acme-prod users invite jo@example.com Jo Bloggs --role-id 104

With an AI assistant (MCP)

Invitations from My Anythink aren't available through the MCP server. Your assistant can walk you through the steps above, and can invite an app user:

text
In acme-prod, invite jo@example.com, Jo Bloggs, as a Client editor.

The assistant runs roles list to find the role, then users invite. See Manage app users and team members for how app users and team members differ, and Account, billing and projects for the access levels in full.

Set Allow registrations, Default role for new users and Allowed Application URLs in each project, under Settings. They aren't shared between projects, and they aren't copied unless you use --include-settings.

Step 5: Brand the Anythink dashboard for each client#

Branding is a project setting, so each client's project looks like the client's own product. You set the name, two logos, a primary colour, a grey and a corner radius on one page, and everyone who signs in to that project sees it. System emails such as invitations and password resets use the project name and a matching shade of the primary colour.

Set it per project, so Acme's acme-prod looks like Acme and another client's looks like theirs. Do the same in acme-staging, so the client recognises it when they review there.

In the Anythink dashboard

  1. Open the project and go to Settings › Organisation Settings.
  2. Under General Settings, enter the client's Name and Description.
  3. In the Branding card, upload a Square Logo and a Standard Logo. Each is one image file, up to 5 MB.
  4. Under Theme, choose a Primary Color, a Gray Color and a Corner Radius.
  5. Select Save Changes.

Only project administrators can open Organisation Settings, so your client's team can't change it by accident.

With the CLI

Branding is managed in the Anythink dashboard. Use the steps above. The CLI sets the name and description when you create a project:

bash
anythink projects create "Acme" --description "Acme customer portal" --plan <plan-id> --region lon1

With an AI assistant (MCP)

Branding is managed in the Anythink dashboard. Your assistant can walk you through the steps above.

Your client's own app, such as their website or a customer portal, can run on their own domain. Add its address under Allowed Application URLs on the same page. See Customise the Anythink dashboard for logos, colours and where each setting shows, and Anythink SDK: sign-in and sessions to build a sign-in page in the client's own style.

Step 6: Set up each client's own secrets, keys and connections#

Nothing sensitive travels between projects. The client's API keys, secrets and integration connections are created in each project, with that client's values, so one client's credentials never sit in another's project.

In the Anythink dashboard

  1. Open Secrets in the project and create each secret the workflows use, such as an email provider key. See Store API keys and tokens as secrets.
  2. Open Integrations and connect each provider for this client. See How integrations work.
  3. Open My Account, select the API Keys tab and create a key for each server-side caller, with only the permissions it needs.
  4. Open Workflows and enable each workflow once its secrets and connections are in place.

With the CLI

bash
anythink --profile acme-prod secrets create PARTNER_API_KEY

anythink --profile acme-prod api-keys create acme-website \
  --permissions enquiries:create \
  --expires-in 90 \
  --save-as acme-website \
  --yes

Switch workflow 12 on in the dashboard once the client's secrets and connections are in place.

With --save-as, the key goes into a new CLI profile and is never printed. Create one key for each job, with the smallest set of permissions that works.

With an AI assistant (MCP)

text
In acme-prod, create an API key called acme-website that can only create enquiries, expiring in 90 days, saved as the profile acme-website.

Ask for --save-as so the key doesn't pass through the conversation. See API keys for rotation, revoking and least privilege.

Step 7: Hand a project over to the client#

Handover means the client controls the billing account and the project, and your staff no longer have access unless you've agreed to keep supporting them. Because a project belongs to one billing account, this works when the project was created in the client's own account, as in step 1.

Work through the list in order:

  1. Promote and check. Run the checklist in Environments and migrating data for acme-prod. Sign in as a Client editor and check they can do their work and nothing else.
  2. Invite the client as Owner. Their decision-maker needs the Owner level on the billing account, which is the level that manages the team and sets a spend cap. Give them a seat in each project they'll use.
  3. Ask the client to add a payment method. Only Admins and Owners can add or change the card, and they need one before paying invoices or creating a paid project.
  4. Replace your credentials. Revoke the API keys you created and create new ones for the client's systems. Secrets and connections you set up with your own accounts should be re-entered with the client's.
  5. Remove your staff. You can't remove yourself from an account team, so the client's Owner removes your people from the account team and from each project's user list. If you're staying on, ask them to lower your level to Viewer or Admin and keep a project role such as Agency staff.
  6. Give them a map. Send the client the project's API address and project id, found on the project page, and links to the docs for their team.

In the Anythink dashboard

  1. In the client's account, select Manage Team and invite the client's contact with the Owner access level.
  2. Open each project, find Team Access and invite the client's team with their roles.
  3. Ask the client's Owner to open Manage Team, then remove your staff or change their levels from the dropdown. Changes apply immediately.
  4. In each project, open My Account, select API Keys and revoke the keys you created.

With the CLI

The account team and project invitations are managed in My Anythink. Use the steps above. The CLI covers the keys:

bash
anythink --profile acme-prod api-keys list
anythink --profile acme-prod api-keys revoke 42

Give the client a profile of their own: they create one with anythink projects use acme-prod, signed in as themselves, so no credentials of yours are in their hands.

With an AI assistant (MCP)

Team access is managed in My Anythink. Your assistant can walk you through the steps above, and revoke API keys:

text
In acme-prod, list the API keys and revoke key 42.

The assistant runs api-keys list and api-keys revoke through the cli tool. Check the id before you confirm.

What you get, and the limits#

What you get

  • A project for each client, and for each of their environments, with its own data, users, files, secrets, keys and plan.
  • A billing account for each client, so costs and access stay separate.
  • A template project that migrate copies into each new client: data model, roles, menus and workflows.
  • Branding for each client's Anythink dashboard and system emails.
  • Role-based access for your staff and the client's team, with invitations from My Anythink.
  • A handover that leaves the client as Owner of their account and projects.

Limits to plan around

  • No agency level. There's no parent organisation over billing accounts, and no single view across all your clients. Switch accounts with the account selector.
  • A project belongs to one billing account. Create each client's projects in the client's account from the start if you want to hand them over.
  • Everyone on a billing account sees all of its projects. That's why each client gets their own account. A seat in a project still depends on an invitation to it.
  • migrate only adds. It doesn't update fields or workflows that already exist on the target, and it doesn't copy users, groups, secrets, API keys or connections.
  • Workflows arrive disabled. Enable each one in the client's project once its secrets and connections exist.
  • Role permissions are dashboard-only. The CLI and MCP can create roles and show what they hold.
  • Invitations are sent from My Anythink. The CLI and MCP server don't send project or account invitations. users invite adds an app user inside a project.
  • Branding is per project and set in the dashboard. It covers the project name, two logos, colours and corner radius. Your client's own app can use their domain.
  • Billing is managed in My Anythink. Plans, invoices, payment methods and spend caps are set there, per billing account and per project.
  • Deleting a project is permanent. Take a backup first if the plan includes them.

Next steps#