🌐 Remote Sites · many properties, one workspace

Every site you run. One workspace.

Connect any number of websites, stores and platforms to one OpsIQ account. Each site keeps its own widget theme, its own analytics and its own scope, but you operate them all from a single admin. Built for agencies, multi-brand businesses, hosting clients and SaaS founders running multiple properties.

Unlimited sites on EnterprisePer-site theme & scopeSigned connectorsOne bill to you
12 sites · one admin
Each brand themed natively
Live 12 sites. One workspace. Synced. OpsIQ workspace synced example.com live · 412 today shop.example live · 84 today client-a.com live · 218 today client-b.io no events 2h
Many properties, one workspace

Every site you run. One admin.

Unlimitedsites on Enterprise
Per-sitetheme & scope
White-labelon Business
One billper-client optional
Connected Sites · add new site

Add a site in three fields. Live in minutes.

Give a site a label, a domain and a group. OpsIQ mints a unique site_key, hands you a drop-in snippet, and the row flips to ● Active the moment the first beacon lands.

  1. 1
    Site Label & Domain

    Name the property and paste its URL (with https://).

  2. 2
    Group or Tracking mode

    Self site for full isolation, or join a group to share identity.

  3. 3
    Drop in the snippet

    One line in your <head> binds tracking and chat to the workspace.

embed · paste once
<script src="https://cdn.opsiq.ai/w.js"
        data-site="sk_9f2a…b41c"></script>
  • Unique site_key per domain
  • Verified by heartbeat
  • Duplicate-safe hostnames
12 sites · one admin
⚡ Active in seconds
Verifying Connected Sites · Add New Site SITE LABEL My Second Store DOMAIN https://store2.example.com GROUP Self Site ▾ + Add Site LABELSITE KEYSTATUSVISITS example.com sk_9f2a…b41c Active 412 store2.example sk_7c1e…a8d0 minting… No ping Active 1
One workspace · native to every brand

A native look on every site, sealed scope underneath.

Your team works in a single admin while each property keeps its own brand, and each site is its own sealed unit, isolated at the data layer.

Per-site theming · shared workspace

One operations workspace. A native look on every brand.

Your team works in a single admin, but the customer-facing widget on each site carries that brand's own colours, agent name, welcome popup and copy. Switch the active site in the workspace switcher and the whole screen (analytics, tickets, chats) re-scopes to it.

  • Per-site widget theme: colours, agent name, avatar, welcome popup and tagline per domain.
  • Workspace switcher. The active site or group drives every number and list on the page.
  • White-label. Remove the "Powered by" badge on Business; the brand sees you, not us.
Theming Workspace · widget theme per-site example.com shop.example client-a.com Support Replies instantly Hi — how can I help? Check my order status 💬
Scope & isolation · enforced

Each site is its own sealed unit.

Site isolation is enforced at the data layer. Your agency staff see every connected site; a client login is scoped to its own site only: its analytics, tickets and chats, never another client's. Every query is filtered per-row by the site you're allowed to see.

  • Data-layer isolation. site_key scoping is applied in the query, not just hidden in the UI.
  • Role + site permissions. Staff see all sites; a client portal login sees only its own.
  • Cross-tenant safe. Clients can't reach each other's rows even with a guessed key.
Scoped Site isolation · per-row scope client-a.com tickets · chats · analytics client-b.io tickets · chats · analytics shop.example tickets · chats · analytics ⚿ Agency staff — all sites ⚿ client-a login — own site only ✓ allowed ⨯ blocked
Connectors · signed & verified

Plug in a platform, not just a page.

Beyond plain websites, OpsIQ connects to platforms through connectors. Drop a folder with a settings.json and connector.php into /connectors/ and it appears as a tile to configure and enable. Ship WHMCS and opsiq_saas out of the box, build your own declarative connector, and turn on "Require signed connectors" so only trusted, untampered packages install.

WHMCS & opsiq_saas. First-party connectors for hosting and SaaS, configured from a settings drawer.
Build your own. Declarative connectors auto-build their settings form from a schema; no core changes.
Signature enforcement. Block unsigned packages and re-verify installed ones against their signed manifest.
Signedtamper-checked installs
Autodiscovered as tiles
Connectors · install WHMCS hosting · signed opsiq_saas SaaS · signed build-your-own declarative manifest + sig ✓ Verified unsigned.zip ⨯ blocked tamper check
Marketplacebrowse, buy & install
Builder wizardsix-step no-code .zip export
Static scansafety check on upload
Group domains · shared identity

Treat a family of domains as one.

Self sites stay isolated. But when several domains belong to one company, join them into a Group: they share visitor identity, consent and workspace resources across the group, while tracking stays stamped with the real domain. Pick a primary site, and every added domain still counts as one site.

Shared identity & consent. A visitor recognised on one group domain is known on the rest.
Real-domain tracking. Every event is still stamped with the actual domain it happened on.
One primary site. Set the group's primary; rename a group anytime while its group_key stays stable; only empty groups can be removed.
Shared Acme Group · 3 sites shared identity acme.com ★ primary shop.acme.com stamps shop.acme.com help.acme.io stamps help.acme.io identity token
Built for agencies & multi-brand teams

One team. Many properties. One bill.

Resellers, multi-brand businesses and SaaS founders run every property from a single admin, and can carry per-client billing so each connected site keeps its own subscription while you keep the margin. Central analytics roll up across all the sites you can see, with a per-site filter for the detail.

Central analytics · per-site filter

Every property, side by side.

Compare visits, conversions, support load and response time across all connected sites at once, then drill into any single one. Ask the admin AI a cross-site question ("which sites had a refund spike this week?") and get one permission-aware answer.

Roll-up · all sitesLive
Central analytics · all sites Filter: All sites ▾ Total visits · all sites 14,208 Open tickets · all 37 Avg first reply 2m 41s Visits by site example shop client-a client-b
ScopeOnly the sites you can see
01

Cross-site roll-up

Totals across every connected site, plus a row per property so you can compare visits, support load and response time at a glance.

02

Per-site drill-down

Pick one site or group in the workspace switcher and the whole page re-scopes to it: analytics, tickets and chats.

03

Cross-site AI

Ask a natural-language question and the admin AI answers only over the sites you have permission to see: one workspace, one answer.

Under the hood

The depth that keeps it solid.

Manage, secure and extend every connected site, with edit-in-place, per-site signing secrets, deep connector behaviour and live engagement tooling.

Site management · edit, archive & codes

Rename, re-domain, archive, without losing a thing.

Edit a site's label or domain anytime and it takes effect immediately. The Default (installed application) site is locked so it can never be deleted, and new sites are pre-configured: they inherit the base client-chat config, so a fresh domain starts working before you touch a setting. Remove a site and its history is archived, not destroyed.

  • Edit label & domain anytime. Change either in place; updates apply immediately across the workspace.
  • Default site can't be deleted. The installed application's primary site is locked to keep the workspace anchored.
  • Integration Codes viewer: HTML, JS, PHP, WHMCS, sales-bridge and bot-blocker snippets, per site, on demand.
Live Connected Sites · manage app.example.com ★ Default Codes 🔒 Remove shop.example.com store.example.com| Edit Codes Remove Integration Codes · store.example.com HTML JS PHP WHMCS Sales Bot-blocker <script src="//opsiq.app/w.js" data-site="sk_7c1e…a8d0"> </script> Copy
API security · per-site secret & signed identity

Every site carries its own signing secret.

Each connected site gets its own webhook secret. That secret signs an HMAC-SHA256 identity token (built from the site_key, the secret, the visitor's role and an 8-hour expiry) so cross-origin chat and admin handshakes can be trusted without exposing credentials. The token is verified server-side on every request; tamper with a field and it fails closed.

  • Webhook secret per site. Generated and shown alongside each site's integration codes; never shared between sites.
  • HMAC-SHA256 identity token: site_key + secret + role, valid 8 hours, secures cross-origin chat and admin.
  • Verified server-side. A tampered payload or expired token is rejected before it touches your data.
Live Identity token · HMAC-SHA256 site_keysk_7c1e…a8d0 webhook secretwhs_•••••••• roleclient exp+8h HMAC SHA-256 token server If a field is tampered or the token expires role=client → role=admin token 403 · rejected
Connector depth · capability levels & workflows

Connectors aren't just settings. They ship behaviour.

A connector declares capability levels (L1 settings → L6 health checks & tests) so you see at a glance how deep an integration goes. The richer ones emit triggers, expose actions your workflows and AI can invoke, and ship pre-built workflow recipes you turn on with one click. Settings forms build themselves from a declarative schema.

  • Capability levels L1–L6. A maturity badge shows exactly which features a connector supports.
  • Triggers & actions. Connectors emit events and expose steps that automations and the AI can use.
  • One-click recipes & declarative settings: pre-built workflows and auto-generated forms from settings.json.
Live Connector · WHMCS ● enabled · signed CAPABILITY LEVELS L1 L2 L3 L4 L5 L6 TRIGGERinvoice.overdue WORKFLOW RECIPEDunning nudge ▶ One-click on ACTIONsend_reminder() Declarative settings · auto-built from settings.json API URL https://billing.example/api API Key •••••••••••• Save
Engagement & protection · per site

Capture feedback, block the bots, sync instantly.

Each site can run its own feedback survey popup: rating, choice, free-text or email-capture, with its own trigger rules. The anti-bot Banned IP list is enforced server-side with a real 403 (cached for five minutes, not just a client-side hide), and every config change propagates live to the widget on every site, with no redeploy. Drop-in templates cover WooCommerce, custom PHP, HTML/JS, WHMCS and a sales feed.

  • Survey popup per site: rating, choice, text or email-capture surveys with per-site trigger rules.
  • Anti-bot banned IP. Server-side 403 enforcement, cached five minutes; abusive IPs never reach your data.
  • Real-time config sync. Theme, survey and settings changes go live across every site without redeploying.
Live Engagement & protection · per site How was your experience? Tell us more (optional)… Submit feedback Anti-bot · banned IP 203.0.113.66 → /beacon bot 403 Config change · live Multi-platform integration templates WooCommerce Custom PHP HTML / JS WHMCS Sales feed
Everything in Remote Sites

The whole surface, in one place.

Heartbeat verificationStatus flips to ● Active on the first beacon; Last Ping and Visits Today update per site.
Per-site widget themeColours, agent name, avatar, welcome popup and copy per brand, native to each site.
Workspace switcherPick the active site or group and the whole admin re-scopes: analytics, tickets, chats.
Per-row site scopeIsolation enforced at the data layer; clients can't reach each other's rows.
Role + site permissionsAgency staff see all sites; a client portal login sees only its own.
Signed connectorsWHMCS, opsiq_saas and declarative build-your-own, auto-discovered as tiles.
Signature enforcementBlock unsigned packages and re-verify installed connectors against their manifest.
Group domainsShare visitor identity and consent across a domain group; tracking keeps the real domain.
Group primary siteSet a primary for each group; only empty groups can be removed.
Central analyticsRoll up visits, conversions, support load and response time across every site.
Cross-site AIAsk natural-language questions answered only over the sites you can see.
White-labelRemove the "Powered by" badge on Business; the brand sees you, not us.
Per-client billingEach site can carry its own subscription, and you keep the reseller margin.
For agencies who resell

Looks like the agency built it.

Make every surface yours, then ask one AI a question across every property you serve.

White-label everything

Remove "Powered by OpsIQ" from the chat widget on Business plans, use your own custom domain for the account portal, and put your agency's branding on the customer-facing surfaces, so clients see your brand, not ours.

0OpsIQ branding
Customdomain & portal

Cross-site AI questions

"Show all open billing tickets across all client sites." "Which sites had a refund spike this week?" The admin AI runs the query across every connected site you have permission to see: one answer, one workspace, fully auditable.

1answer, all sites
Auditablepermission-aware
Why one workspace

One OpsIQ vs a separate tool per site.

Running a different chat, analytics and ticketing login on every property means duplicated work, scattered data and no roll-up. Remote Sites keeps each brand distinct while your team operates from one place.

CapabilityA separate tool per siteOpsIQ Remote Sites
Where your team worksOne login per siteOne shared workspace
Per-site brandingRe-set up each toolPer-site theme, one admin
Data isolationSeparate accountsPer-row site scope, one DB
Cross-site reportingExport & merge by handBuilt-in roll-up + filter
Cross-site AI questionsNot possiblePermission-aware, one answer
Shared visitor identityNone across domainsGroup domains
Platform integrationsRebuild per toolSigned connectors, reused
BillingMany invoices to juggleOne bill · per-client optional
Full feature list

Everything in Remote Sites & Connectors.

Every capability, grouped. ★ marks a stand-out.

FeatureWhat it does
Site management
Unlimited connected sitesAdd as many websites, stores and platforms as your plan allows, each its own isolated unit.
Unique site_key per domain ★A cryptographic identifier binds tracking, chat and API to that one workspace.
Drop-in embed snippetPaste one script and go live in minutes; one beacon powers tracking and chat.
Heartbeat verification & live statusStatus flips to ● Active on the first beacon; Last Ping and Visits Today update per site.
Client chat pre-configured per site NEWA new site inherits the base client-chat config, so it works before you touch a setting.
Default / installed application site NEWThe primary site is locked and cannot be deleted, anchoring the workspace.
Duplicate domain protection NEWThe same hostname can't register twice; you reuse the existing site instead.
Site label & domain edit NEWEdit either anytime; the change applies immediately across the workspace.
Site removal (archive) NEWStop accepting new data while keeping every record already collected.
Integration codes viewer NEWHTML, JS, PHP, WHMCS, sales-bridge and bot-blocker snippets, per site, on demand.
Branding & appearance
Per-site widget theme ★Colours, agent name, avatar, welcome popup and copy per brand, native to each site.
White-label modeRemove the "Powered by" badge on Business; the brand sees you, not us.
Security & isolation
Per-row data-layer isolation ★site_key scoping is applied in the query itself, not just hidden in the UI.
Role + site permissionsAgency staff see all sites; a client portal login sees only its own.
Cross-tenant safety ★Clients can't reach each other's rows even with a guessed key.
Multi-domain
Group domains (shared identity) ★Family domains share visitor identity and consent across the group.
Group primary siteMark one primary per group; only an empty group can be removed.
Real-domain event trackingEvery event is stamped with the actual domain it happened on.
Visitor continuity across group domains ★Recognised on one domain → known across the whole family.
Self vs group site mode NEWSelf sites stay isolated; grouped sites share identity and resources.
Dynamic group rename NEWRename a group anytime while its underlying group_key stays stable.
Analytics & reporting
Central analytics roll-upAggregate visits, tickets and first-reply time across every site.
Per-site drill-downPick a site and the whole page re-scopes to that property.
Cross-site AI ★Permission-aware natural-language questions over only the sites you can see.
Multi-tenant billing
Per-client billingEach site carries its own subscription so you keep the reseller margin.
Connectors & integrations
Connector marketplaceBrowse, buy and install from a curated catalog hosted by OpsIQ.
WHMCS connectorFirst-party signed hosting connector, configured from a settings drawer.
opsiq_saas connectorFirst-party signed SaaS connector out of the box.
Connector builder wizard ★Six-step no-code generate-and-export a .zip, no core changes.
Declarative connector settings NEWSettings forms auto-build their fields from a settings.json schema.
Signed connectors ★Require a trusted OpsIQ signature before a connector installs.
Signature enforcement ★Re-verify installed connectors against their manifest to catch tampering.
Connector upload & install.zip validation plus a static safety scan before it's installed.
Connector actions NEWReusable steps a connector exposes for workflows and the AI to invoke.
Connector triggers NEWEvents a connector emits to fire automations and AI workflows.
Connector workflow recipes NEWPre-built workflows you turn on with one click.
Connector capability levels NEWL1 settings → L6 health checks & tests, shown as a maturity badge.
Build-your-own connector ★Drop a folder into /connectors/ and it auto-discovers as a tile.
API & integration security
Webhook secret per site NEWEach site gets its own secret that signs and verifies identity tokens.
HMAC identity token signing NEWHMAC-SHA256 over site_key + secret + role, valid 8 hours, secures cross-origin chat & admin.
Engagement & events
Sales conversion bridgeJS + PHP snippets to send conversions from any platform.
Multi-platform integration templates NEWWooCommerce and custom-PHP snippets ready to drop in.
Survey popup per site NEWRating, choice, text or email-capture survey with its own trigger rules.
Anti-bot banned IP enforcement NEWServer-side 403, cached five minutes; abusive IPs never reach your data.
Workspace & sync
Workspace switcherPick the active site or group and the whole admin re-scopes to it.
Real-time config sync NEWTheme, survey and settings changes go live across sites with no redeploy.
FAQ

Questions before you connect.

Short answers for agencies, multi-brand teams and resellers weighing up one workspace.

Starter: 1. Launch: 1. Growth: 5. Business: 15. Scale: 40. Enterprise: unlimited. Every domain you add, including each member of a group, counts as one site against your plan.
On Connected Sites, enter a Site Label and Domain, pick a Group/Tracking mode, then Add Site. OpsIQ mints a unique site_key and gives you a drop-in snippet. The row flips from ○ No ping to ● Active the moment the first beacon arrives.
Never. Site isolation is enforced at the data layer; permissions are enforced per-row in every query, so even a guessed key can't reach another client's rows.
Yes. Issue them a portal login that scopes to their own site. They see their analytics, tickets and chats, nothing else, while your agency staff see every connected site.
A Self site stays fully isolated. A Group joins several domains of one company so they share visitor identity and consent, while every event is still stamped with the real domain it happened on. You can set one primary site per group.
Connectors plug OpsIQ into platforms like WHMCS and opsiq_saas, or your own declarative build-your-own connector dropped into /connectors/. Turn on "Require signed connectors" to block unsigned packages and re-verify installed ones against their signed manifest.
Yes. Each site carries its own widget colours, agent name, avatar, welcome popup and copy, so it looks native to that brand, all operated from one shared workspace.
Optionally. Each connected site can carry its own subscription, invoiced separately and settled monthly, so you keep the margin between your reseller cost and your client price.