# The best CSP monitoring setup for agencies managing many client sites

> One CentralCSP site per client: 3 to 30 sites by tier from €39.99/month, per-site roles so a client only sees their own data, alert rules routed per client from Business (€129.99), a REST API to feed your own client reports, and a free scanner that doubles as an audit-phase deliverable.

- Canonical: https://info.centralcsp.com/articles/csp-monitoring-for-agencies/
- Published: 2026-08-09
- Language: en
- Publisher: CentralCSP (https://centralcsp.com)

An agency that has built or still maintains forty client sites owns forty attack surfaces, whether the contracts mention security or not. When a compromised WordPress plugin starts skimming card numbers on one client's checkout, that client's customers blame the client, and the client blames whoever built the site. We have sat close enough to that conversation to know how it ends. No clause about hosting being the client's responsibility repairs the reference calls that quietly stop coming afterwards.

The setup that works for agencies is one CentralCSP workspace with one site per client. Site caps run 3, 10 and 30 across Start (€39.99/month), Business (€129.99) and Scale (€349.99), with 5, 25 and 100 team seats, and a custom Enterprise quote past that. Each site keeps its own policy, its own reporting subdomain and its own violation stream, and from Business its own alert rules. Website roles (Viewer, Analyst, Manager, Admin) are granted per site, so a client's developer can be given read access to their own site and nothing else. The REST API, from Business, pulls per-client summaries into whatever reporting you already send. Tier details are on the [pricing page](https://centralcsp.com/en/pricing/).

## Why one security tool per client never adds up

Price the obvious route first. Report URI's entry plan costs $65.99/month for a single domain (August 2026 figure from its pricing page). Fifteen clients means roughly $990 a month before anyone has read a single report, which is more than many of those clients pay for their entire maintenance retainer. Per-domain pricing at that level was designed for a company monitoring its own product, not for a book of thirty small sites. Against that, Business at €129.99 holds ten client sites and Scale at €349.99 holds thirty, on one invoice.

The other reflex, running your own report collector, costs more than it looks once you count it honestly. Browsers send violations in two formats, browser extensions generate most of the noise, and a traffic spike on any one client site hammers the endpoint you now maintain for all of them. That triage burden comes out of billable hours, the exact resource an agency sells. The tools that handle many sites under one roof are compared in [how to monitor CSP across multiple websites](/articles/monitor-multiple-websites-csp/). This article is about the agency-shaped way to run the setup.

## One site per client, one policy per stack

No two client sites share a stack. One is a Shopify build with a tag manager the marketing team keeps feeding, another is a 2019 WordPress site with a page builder you would rather not discuss in front of the client. A single policy stretched across both would be either useless or permanently on fire. Per-site policies mean each one gets a CSP built from its own traffic: connect reporting, let the Builder watch 1 to 90 days of real usage, review the result value by value, enforce. It is the same workflow we describe in [turning CSP reports into a policy](/articles/turn-csp-reports-into-policy/), repeated per client. By the third site it takes an afternoon.

Separation also protects the signal. A relaunch on one client's site produces thousands of violations for a week, and in a shared bucket that noise would bury a genuinely injected script on another client's checkout. Per-site streams keep every client's baseline clean. Report quotas are set per workspace, 250,000 a month on Start, 2 million on Business, 10 million on Scale, and each site carries its own cap underneath, so the client whose relaunch is misbehaving cannot burn through everyone else's share. Ingestion filters restrict which origins may report to each endpoint, which stops a copied header on some forgotten staging clone from polluting a client's stream. The 90-day retention on every plan means the monthly report you owe each client is always covered, with margin left for the client who asks in March about something from January.

## Alert rules routed to each client's channel

From Business (€129.99/month, no cap on alerts), each site carries its own alert rules. There are 16 event types across the report surfaces: new script origin, CSP report spike, new violation type, a new failing origin in NEL reports, a crash spike, and so on. What matters for an agency is that every rule picks its own channels, out of Slack, Microsoft Teams, Google Chat, Telegram, email and signed webhooks. The e-commerce client's site gets a new-script-origin rule posting to your ops Slack and to their own Teams channel. The brochure-site clients get no rules at all, because a weekly dashboard pass covers them. It is the same trade-off we walked through for [small teams](/articles/csp-monitoring-for-small-teams/). Each rule has a cooldown (15 minutes by default) that batches everything found in the window into one message, so a client's Friday deploy is one notification, not forty. Webhook payloads are JSON signed with HMAC-SHA256, so a firing rule can open a ticket in PagerDuty, Jira or whatever your agency already runs. And the delivery history per channel, with retries, is the thing you show the client who asks whether they would have been told.

Start has no alerting, and for a book of content sites that is fine. The moment a client takes card payments on their own pages, PCI DSS 6.4.3 and 11.6.1 enter the conversation, and the evidence tooling for those lives on Scale (€349.99/month) and up. That client should be paying for that line anyway.

## Turning monitoring into a line item clients will pay for

Every Magecart headline does the client education for you. "We watch every script that loads on your site and get alerted when one changes" is a sentence a non-technical client understands, which makes CSP monitoring one of the rare security services that survives contact with a maintenance-contract negotiation.

Two honest moves make it land. During the audit phase, run the [free scanner](https://centralcsp.com/en/tools/csp-scanner/) against the prospect's site: no account needed, a 0–100 score on security and another on quality, plus severity-rated findings with remediation, and a low score on their current site is a better sales argument than any slide. Once the contract runs, use the API to pull each site's data into your own monthly report template, under your own brand. On Start you are reading the dashboard and writing that report by hand, which is fine at three sites and stops being fine at ten. There is no white-label dashboard to resell, and we would rather say that plainly, but nothing stops the report the client reads from looking entirely like yours, and a Viewer role on their own site gives the client who insists on a login exactly that and nothing more.

Where to land: Start at €39.99 covers a three-site book you review by hand. Business at €129.99 is where most agencies end up, with ten sites, alerts routed per client and the API for the reports. Scale at €349.99 takes thirty and adds the PCI DSS module, CVE detection on every client's libraries, SSO and the audit log. The 14-day trial on Start is enough to onboard three client sites and see what their browsers actually load before you invoice anyone.

## Frequently asked questions

### Can a web agency offer CSP monitoring as a paid service to clients?

Yes, and it sells better than most security line items because clients have read the Magecart headlines. The practical model: one CentralCSP site per client (3 to 30 sites depending on tier, from €39.99/month), a monitoring line added to the maintenance contract, and monthly reports built from the REST API, which is included from the Business tier at €129.99/month. The free CSP scanner works as an audit-phase deliverable before the contract is signed.

### How many client sites can one CentralCSP account monitor?

It depends on the tier: 3 sites on Start (€39.99/month), 10 on Business (€129.99), 30 on Scale (€349.99), and Enterprise is custom-quoted beyond that. Each site gets its own policy, its own reporting subdomain, its own violation stream, its own script inventory and, from Business, its own alert rules. Website roles are granted per site, so client sites stay cleanly separated inside one workspace even when a client's own developer has a login.

### Can CSP monitoring be white-labeled for agency clients?

CentralCSP does not sell a white-label skin, so do not promise clients a rebranded dashboard. What is factual: from Business (€129.99/month) the REST API lets an agency pull per-site violation and script data and present it in its own report template, under its own brand. And on every plan a client can be given a Viewer role on their own site alone, which is closer to what most of them were asking for. For most maintenance contracts, a monthly branded PDF built from the API data is what the client actually wanted anyway.

### Do agency clients need real-time CSP alerts?

Only the ones with something to steal. Brochure and content sites are fine with a weekly dashboard review, which is all the Start tier offers since it has no alerting. Sites taking payments or handling logins justify Business (€129.99/month, unlimited alerts), where rules for new script origins, report spikes and the rest of the 16 event types are set per site and routed to a channel per client: your ops Slack, their Microsoft Teams, an email list, a signed webhook into your ticketing system.
