Partner Central
Connect
Complete technical reference for PCC's bidirectional sync engine, multi-CRM adapter architecture, SOC 2 compliance controls, AI provider framework, and deployment infrastructure.
Platform Architecture
A unified command center for your AWS co-sell pipeline. Opportunity stages, engagement health, sync status, CRM connections, and AI insights — all on a single screen. Every metric links to its detail view.
Pipeline at a Glance
Opportunity counts by lifecycle stage with click-through to full list. Stages: Prospect, Qualified, Technical Validation, Business Validation, Committed, Launched.
Quick Actions
Create Opportunity, Create Engagement, Trigger Sync, View Reports — one click from the dashboard. Context-aware shortcuts based on your most recent activity.
Bidirectional Sync Engine
PCC keeps your data synchronized across your systems: AWS Partner Central, your CRM (HubSpot, or Salesforce (coming soon)), and PCC itself. Changes in any system propagate automatically with conflict detection and resolution.
SOC 2 Compliance Foundation
Enterprise-grade security controls baked in from day one. Append-only audit trail, KMS envelope encryption, PostgreSQL Row-Level Security, PII classification, and data residency controls. Not a checklist — a foundation.
Audit Trail
CC7.2- Every action logged: actor, timestamp, IP, resource, outcome
- Append-only with SHA-256 hash chain tamper detection
- 1-year minimum retention, exportable for auditors
Encryption
CC6.1- AWS KMS envelope encryption for all stored credentials
- TLS 1.2+ enforced on all connections (client, DB, Redis)
- Quarterly key rotation with zero downtime
Tenant Isolation
CC6.3- PostgreSQL Row-Level Security policies at the database layer
- Per-request tenant context injection via Prisma Extensions
- Automated cross-tenant data leak testing in CI pipeline
Data Classification
CC6.5- Every field classified: public / internal / confidential / restricted
- PII pseudonymized in all audit logs via SHA-256 with per-tenant salt
- Right-to-erasure cascade deletion preserving pseudonymized audit entries
GET /api/v1/system/compliance returns real-time status of all security controls. Encryption state, access control configuration, AI provider mode, and audit log health — designed for auditor consumption during SOC 2 evaluations.
AI Provider Framework
Contextual AI built into every workflow. Research companies, draft one-pagers, analyze pipelines, and prepare for calls — all using data already in PCC. Choose your AI backend: Amazon Bedrock, HybrIQ v2, or bring your own key.
| Mode | Environment | Auth | Data Residency | SOC 2 |
|---|---|---|---|---|
| bedrock | Self-hosted (default) | IAM instance profile | Customer’s AWS region | Compliant |
| hybriq | SaaS (managed) | HybrIQ API key | PCC managed cloud | N/A (SaaS) |
| direct | BYOK | Customer API key | LLM provider | Customer-managed |
Research Company
3 creditsCompany Overview
Acme Corporation is a Series C enterprise SaaS company specializing in supply chain optimization. Founded in 2018, they serve 200+ mid-market and enterprise customers across manufacturing and logistics verticals. $45M ARR with 40% YoY growth.
Technology Stack
AWS (primary cloud provider), Kubernetes for container orchestration, React frontend, PostgreSQL and DynamoDB for data layer. Currently expanding their ML pipeline on SageMaker.
Strategic Fit
Strong alignment with AWS ISV Accelerate program. Current $2.4M pipeline and expanding AWS footprint suggests significant co-sell potential. Recommend focusing on their SageMaker expansion as a near-term engagement driver.
Research Company
Comprehensive company brief from account context — overview, tech stack, strategic fit.
Draft One-Pager
Professional partner brief from opportunity data, ready for internal or external sharing.
Pipeline Analysis
AI assessment of pipeline health with risk flags and progression recommendations.
Call Prep Brief
Talking points, background context, and suggested next steps for upcoming meetings.
Engagement Summary
Status summary of co-sell engagement progress with timeline and milestones.
Custom Actions
Enterprise tier: build custom AI actions tailored to your workflow via the MCP interface.
GET /api/v1/credits/balance.
AIActionExecution table. A daily encrypted license check-in reports aggregate run counts and token totals — zero PII or business data is ever transmitted. AWS Bedrock costs are billed through your own AWS account.
CRM Adapter Architecture
A plugin-based CRM adapter architecture. Connect HubSpot today, with Salesforce (coming soon). Unified interface with visual field mapping, configurable conflict resolution, and PII-compliant data handling.
OAuth 2.0
Secure authentication with automatic silent token refresh. Users rarely re-authenticate.
Bidirectional Sync
Records flow both ways. Changes in your CRM appear in PCC and vice versa.
Visual Field Mapping
Drag-and-drop field mapping with type compatibility warnings and preview.
Conflict Resolution
Four strategies: last-write-wins, CRM-wins, PCC-wins, or manual review queue.
PII Classification
Per-field data classification. Pseudonymization in logs. Right-to-erasure cascade.
Rate Limit Handling
Automatic retry with exponential backoff. Bulk API for 200+ record syncs.
Notification Pipeline
Every opportunity update, status change, and milestone triggers automatic notifications to the right people at the right time. Dual-mode architecture supports both SaaS channels (Resend, Slack, HubSpot) and self-hosted AWS-native channels (SNS, SES).
Cloud Notifications
Automatic HubSpot deal updates, branded email alerts, and Slack notifications keep your entire team in the loop as opportunities progress.
Self-Hosted Notifications
Runs entirely within your AWS account using SNS and SES. Your partner data never leaves your infrastructure — full control, full compliance.
Quick Setup
A guided setup wizard walks you through notification configuration on first launch. Test connectivity before going live, or skip and configure later from Settings.
Reliable Delivery
Built-in retry logic ensures no notification gets lost. Each channel operates independently — if one has a hiccup, the others still deliver. Full delivery history in Settings.
Integration-Ready
Structured event payloads make it easy to connect downstream systems — trigger workflows, update dashboards, or feed your own analytics from every notification event.
Secure by Default
Self-hosted deployments lock down all public routes. No unauthenticated endpoints on your infrastructure — every notification flows through authenticated channels.
Channel Availability by Deployment Mode
PCC automatically detects your deployment mode and enables only the channels available for that mode. No configuration switching — the right channels activate on startup.
Weekly Co-Sell Digest
Beyond real-time alerts, PCC delivers a personalized weekly email to each co-sell partner — aggregating only the deals and updates that matter to them into one clean summary.
Zero Manual Follow-Ups
Automatically aggregates all relevant deal updates into a single, clean weekly email — no manual follow-ups needed.
Scheduled Partner Updates
Keeps co-sell partners consistently informed with scheduled updates, ensuring they never miss important deal progress or changes.
Personalized Per Seller
Tailors each email to the specific co-seller, so they only see the deals and details that matter to them.
SaaS / AMI Parity
On SaaS, digests go through Resend. On AMI, the same digests go through your AWS SES — same content, same schedule, zero external dependency.
Territory Routing Engine
Automatically assign incoming AWS-sourced opportunities to the correct partner seller in HubSpot based on geographic region. Eliminates manual deal assignment and reduces seller response time from hours to seconds.
| Region | Territory | Assigned Seller | Priority | Status |
|---|---|---|---|---|
| us-east-1 | NAMER | Marcus Webb | 1 | Active |
| us-west-2 | NAMER | Marcus Webb | 1 | Active |
| eu-west-1 | EMEA | Priya Sharma | 1 | Active |
| ap-southeast-1 | APJ | James Tanaka | 1 | Active |
| * | Fallback | Round-robin | ∞ | Active |
Seller Profiles
Per-organization roster of partner sellers. Each profile maps to a HubSpot Owner ID. Active/inactive status controls routing eligibility.
Territory Rules
Map geographic regions (us-east-1, emea, apac) to sellers with priority-based conflict resolution. Lowest priority number wins.
Round-Robin Fallback
When no territory rule matches, the system assigns deals to the next active seller via round-robin rotation. Fair distribution guaranteed.
Routing Audit Log
Every routing decision logged: matched seller, matched rule, fallback method, and submission details. Full SOC 2 compliance trail.
Admin API
Full CRUD endpoints for seller profiles and territory rules. Routing log endpoint for admin visibility. All operations require admin role.
Edge Case Handling
Invalid HubSpot Owner IDs surface errors in routing log. Deleted sellers cascade-delete rules. All-inactive sellers preserve existing behavior.
Org Chart & Rep Mapping
Map your AWS partner rep relationships in one place. Build org charts manually or let PCC auto-infer team structures from deal activity. Rate every rep relationship by deal count, value, engagement frequency, and win rate — so you always know who drives results.
Visual Org Charts
Drag-and-drop org chart builder for AWS partner teams. See reporting lines, team structure, and coverage areas at a glance.
Auto-Inferred Mapping
PCC analyzes deal history from ACE data to automatically suggest team structures and reporting relationships. Review and approve with one click.
Relationship Rating
Every rep is scored by four metrics: deal count, deal value, engagement frequency, and win rate. Instantly identify your strongest — and weakest — partner relationships.
Coverage Tracking
Track rep relationships across all AWS regions in a unified view. Compare engagement and performance across territories side by side.
Engagement History
Full timeline of interactions with each rep — deals worked together, meetings, co-sell events. Context at your fingertips before every partner call.
Exportable Charts
Export org charts as PDF or image for executive briefings, QBRs, and partner planning sessions. Share relationship insights with your leadership team.
Deployment Architecture
PCC supports two deployment modes. SaaS runs on the managed PCC platform with zero infrastructure overhead. Enterprise Self-Hosted deploys as an AMI in your own AWS account for full data sovereignty, dual-mode notifications, and multi-org support.
SaaS
- ✓ Instant setup — no infrastructure
- ✓ Automatic updates & maintenance
- ✓ 99.9% SLA
- ✓ HybrIQ AI (managed)
- ✓ HubSpot + Slack + Resend notifications
- ✓ Multi-CRM integration included
Enterprise Self-Hosted
- ✓ One-click AMI · Multi-AZ HA
- ✓ Data stays in your VPC
- ✓ AWS-native notifications (SNS + SES)
- ✓ Bedrock AI (your AWS account)
- ✓ CIS Level 1 hardened · SOC 2 ready
- ✓ Frictionless first-boot setup wizard
- ✓ Multi-org (MSP support)
- ✓ Dedicated support · Custom SLA
Billing & Metering Coming Soon
AI action billing adapts to your deployment mode. SaaS customers consume credits from a monthly allocation with automatic overage billing. Self-hosted AMI deployments meter executions locally and report aggregate counts via encrypted license check-in — zero business data transmitted.
SaaS Credit System
| AI Action | Credits | Est. Cost | Typical Tokens |
|---|---|---|---|
| Research Company | 3 | ~$0.03 | ~1,200 |
| Draft One-Pager | 5 | ~$0.05 | ~2,000 |
| Pipeline Analysis | 2 | ~$0.02 | ~800 |
| Call Prep Brief | 3 | ~$0.03 | ~1,100 |
| Engagement Summary | 2 | ~$0.02 | ~900 |
Real-Time Balance
Query GET /api/v1/credits/balance to retrieve current credit balance, usage this period, and overage amount. Credits reset monthly on your billing cycle date.
Consumption History
Query GET /api/v1/credits/history for detailed credit consumption history with action-level detail — which action, when, by whom, and how many credits.
Automatic Overage
When credits are exhausted, additional AI actions are automatically billed via Stripe at your tier-specific overage rate. No service interruption — AI actions continue seamlessly.
Monthly Reset
Unused credits do not roll over. Your allocation resets to the plan total (Pro: 500, Enterprise: 2,000) on each billing cycle date.
AMI Per-Run Metering
Self-hosted deployments track all AI action executions locally in the AIActionExecution table. A daily encrypted license check-in transmits only aggregate counts — never business data.
Daily License Check-In Payload
ai_action_runs: number— Total AI action executions since last check-intotal_input_tokens: number— Aggregate input tokens across all executionstotal_output_tokens: number— Aggregate output tokens across all executionsactions_by_type: Record<string, number>— Execution counts grouped by action type
Zero PII Guarantee
- Only execution counts and token metadata are transmitted during check-in
- No opportunity data, partner names, or business content leaves your VPC
- Check-in payload encrypted in transit via HTTPS and signed with ES256 JWT
Billing Flow
- Monthly usage invoice generated from aggregated daily check-in data
- AWS Bedrock inference costs billed directly through your own AWS account
- PCC license fee covers platform usage; AI compute costs are separate and transparent
SOC 2 Compliance Controls
Audit Trail
CC7.2- All AI action executions logged in append-only audit trail with SHA-256 hash chain
- 12-month retention of execution history for auditor review
- Automated monthly reconciliation: raw execution events vs. aggregated billing totals
Encryption & Transport
CC6.1- Check-in data encrypted in transit (HTTPS + ES256-signed JWT)
- No customer business data included in check-in payload
- License token validated server-side before accepting any check-in
Separation of Duties
CC6.3- Invoice generation and approval require different users (enforced by role)
- Credit allocation changes require admin-level authorization
- Overage rate modifications restricted to billing_admin role
API Reference
PCC exposes a comprehensive REST API covering all platform capabilities. All endpoints require authentication via Bearer token and enforce tenant isolation through Row-Level Security. The MCP Server provides the same operations for AI agent integration.
REST Opportunities API
Full CRUD and sync operations for AWS Partner Central opportunities. Lifecycle stage management, search, and bulk operations.
GET /api/v1/opportunities
POST /api/v1/opportunities
PATCH /api/v1/opportunities/:id
POST /api/v1/opportunities/:id/sync
REST Engagements API
Create, manage, and track co-sell engagement lifecycle. Invitation handling, status transitions, and activity logging.
GET /api/v1/engagements
POST /api/v1/engagements
PATCH /api/v1/engagements/:id
POST /api/v1/engagements/:id/accept
REST CRM Integration API
Connect and disconnect CRM providers, trigger manual syncs, configure field mappings, and manage conflict resolution strategies.
POST /api/v1/integrations/connect
POST /api/v1/integrations/disconnect
POST /api/v1/integrations/sync
PUT /api/v1/integrations/field-mappings
REST AI Actions API Coming Soon
Execute AI-powered actions (research, draft, analyze), check execution status, and retrieve action history with token usage. Responses include credits_consumed (SaaS) or tokens_used (AMI) for billing transparency.
POST /api/v1/ai-actions/execute
GET /api/v1/ai-actions/:id/status
GET /api/v1/ai-actions/history
REST Credits API Coming Soon
Real-time credit balance, period usage, overage tracking, and detailed consumption history with per-action breakdown. SaaS deployments only.
GET /api/v1/credits/balance
GET /api/v1/credits/history
REST Territory Routing API
Manage seller profiles, territory rules, and view the routing decision log. Priority-based rule matching with round-robin fallback.
GET /api/v1/routing/sellers
POST /api/v1/routing/rules
GET /api/v1/routing/log
REST Org Chart API
CRUD operations for partner reps, relationship mappings, and performance scorecards. Auto-inference from deal activity data.
GET /api/v1/org-chart/reps
POST /api/v1/org-chart/relationships
GET /api/v1/org-chart/scorecards
REST System API
Health checks, SOC 2 compliance status, audit log queries, and system configuration. Designed for monitoring and auditor consumption.
GET /api/v1/system/health
GET /api/v1/system/compliance
GET /api/v1/system/audit-log
REST Notifications API
Configure notification channels and per-user preferences. Query delivery history with status tracking and retry management.
GET /api/v1/notifications/channels
PUT /api/v1/notifications/preferences
GET /api/v1/notifications/delivery-log
MCP Server Architecture
Partner Central Connect includes a built-in AI assistant powered by the Model Context Protocol (MCP). Ask questions, manage opportunities, trigger syncs, and administer your instance — all through natural language. PCC’s MCP server complements AWS’s own Partner Central MCP by combining AWS data with your CRM, analytics, and platform operations in a single chat interface.
What You Get vs AWS MCP Alone
| AWS Partner Central MCP | PCC AI Assistant | |
|---|---|---|
| Scope | AWS Partner Central data only | Full platform — AWS + CRM + analytics + admin + instance ops |
| Capabilities | Pipeline insights, sales plays, funding recommendations | 79 tools across co-sell, administration, and instance management |
| Authentication | Requires IAM credential setup | Uses your existing PCC login — no additional setup |
| Interface | External AI agent required | Built-in chat panel — no third-party tools needed |
| Team isolation | Single AWS account | Full organization-level isolation with role-based access |
| Audit trail | AWS CloudTrail | Complete operation log with SOC 2 compliance support |
| CRM integration | None | HubSpot, Salesforce (coming soon) |
| Instance management | None | Updates, backups, diagnostics, health monitoring (self-hosted) |
| Safety controls | None | Three-tier guardrails: safe reads, validated writes, confirmed destructive actions |
| Deployment | AWS cloud only | SaaS + self-hosted (your AWS account) |
Ask Your AI Assistant Anything
The PCC AI assistant answers questions that span your entire co-sell operation — not just AWS data:
“Show me opportunities with stalled CRM sync”
- Combines your CRM sync status with AWS opportunity data in one answer
- Identifies exactly which deals need attention and why
“What’s our co-sell pipeline value this quarter?”
- Pulls aggregated revenue data across all your opportunities
- Includes stage breakdowns and trend analysis
“Create a backup before updating the instance”
- Manages your self-hosted instance directly from the chat
- No SSH required — updates, backups, and rollbacks via conversation
“Invite a new user as account manager”
- Handles user management, role assignments, and org settings
- Role-based access ensures users only see tools they’re authorized to use
AWS MCP Integration (coming soon)
PCC’s AI assistant will soon integrate directly with the AWS Partner Central MCP server, bringing AWS-native intelligence into your existing chat workflow:
AWS Pipeline Insights
AI-generated analysis of opportunity health, progression probability, and recommended next actions based on AWS data.
AWS Sales Plays
Recommended co-sell strategies tailored to your industry vertical, customer profile, and partner strengths.
AWS Customer Profiles
AWS-curated intelligence including technology footprint, growth signals, and engagement history for your accounts.
AWS Funding Recommendations
Discover available AWS funding programs, check eligibility, and get guidance on applying for co-sell opportunities.
Data Control by Deployment Mode
| SaaS | Self-Hosted | |
|---|---|---|
| Where your data lives | PCC managed cloud | Your AWS account |
| AI assistant audit log | PCC managed database | Your database (full ownership) |
| AI model provider | Bring your own key (Anthropic, OpenAI, or Bedrock) | Amazon Bedrock in your account (default) |
| AWS API calls | Through PCC cloud infrastructure | Direct from your VPC via IAM role |
| Encryption | PCC managed encryption keys | Your own AWS KMS keys |
| SOC 2 compliance | PCC certification covers your deployment | Achieved through your own controls |
Professional Services
Every co-sell workflow is different. Our engineering team builds custom features, integrations, and workflow automations tailored to your partner operations — from a single enhancement to a full platform transformation.
- One custom feature or enhancement
- Dashboard widget or report
- Workflow rule or automation
- Field mapping customization
- Standard delivery timeline
- Complex integration development
- Custom AI action or model tuning
- Advanced reporting & analytics
- Multi-system data orchestration
- Priority delivery & dedicated support
- Full platform tailoring
- Multiple features & integrations
- Custom deployment configuration
- Dedicated project manager
- Ongoing support & iteration