Learn

Workflow Automation for Agencies: Client Ownership and Handoffs

Agencies should build each client's automations in an account the client owns and pays for. Compare what Zapier's terms, Make's agreement and n8n's license allow, how each platform isolates clients, and use a handoff checklist covering credentials, spend, incidents and offboarding.

Start with the selection criteria. Use this page when you know the category and need a practical framework for narrowing the field.

UpdatedSeptember 30, 2026
Browse tool profiles

Editorial guide

Guide

Start with the criteria, tradeoffs, and shortlist logic before you open individual tools.

Short answer: build each client's automations in an account or instance the client owns and pays for, and join it as an invited member or contractor. That one decision settles most agency problems at once:

  • whose terms apply;
  • who holds the credentials;
  • whose budget the usage hits;
  • how you leave cleanly.

It is also the only delivery model that stays within the standard terms of all three platforms in this guide:

  • Zapier: its terms limit the service to your own internal business purposes and prohibit using it "to provide a hosted or managed service to others".
  • Make: its Master Services Agreement limits use to your internal purposes "and not for the benefit of any third parties", unless Make's documentation permits otherwise. It does allow contractors to use the service to provide their services to the customer.
  • n8n: n8n's license FAQ says its Sustainable Use License allows paid consulting and managed automation in several forms. It rules out hosting n8n for clients to build their own workflows, and it rules out white-labeling.

None of these standard terms lets an agency resell platform access or rebrand the product. Running client work in the agency's own Zapier or Make subscription falls outside both vendors' default grants, so do it only with the vendor's written confirmation or partner-agreement terms.

Charge for design, build, maintenance and support, and let the platform bill the client directly. The rest of this guide shows how to set that up, where each platform draws its lines, and what to hand over when an engagement ends.

Three delivery models

Model

What it looks like

Zapier

Make

n8n

A. Client-owned (recommended)

Client holds the account or instance and pays the vendor; agency is an invited user

Fits the terms. The client needs Team or Enterprise so the agency gets its own seat; Professional has one seat

Fits the terms: contractors may use the service to provide their services to the customer

Fits: n8n's Help Center says consulting on a client's own instance needs no license on your part; the client's own plan or license applies

B. Agency-run for clients

Agency's own account or instance runs automations on the client's behalf; clients see only results

Conflicts with the terms: a managed service to others

Outside the agreement's default internal-use grant; get Make's written confirmation or partner-agreement terms first

n8n's current license FAQ allows it when clients cannot see, build or edit workflows; an undated n8n Help Center answer says hosting clients' workflows and credentials needs an Enterprise license. Get written confirmation from [email protected] first

C. Clients build inside your product

Clients configure their own workflows through your interface, API or an AI agent

Not covered by the standard terms; would need a separate agreement with Zapier

Not covered by the standard terms; would need a separate agreement with Make

Not allowed under the Sustainable Use License; requires a commercial (embed) license

Model A is the default because it holds under every source above, including the stricter reading of n8n's license. The n8n license FAQ also allows you to install and manage n8n on a client's own server, "as long as you don't offer hosting as well", which n8n says would compete with its Cloud offering.

The license FAQ describes a partner program for managing n8n across multiple client environments as "in development". Until it exists, n8n's own advice is to email [email protected].

If you are unsure whether a Model B arrangement fits, send the vendor a short architecture description and keep the written answer with the client contract. For more on n8n's editions and permitted uses, see Is n8n free? and n8n Cloud vs self-hosted.

How each platform isolates a client

Isolation need

Zapier

Make

n8n

Unit that separates clients

One Zapier account per client

One organization per client; each organization has its own plan, billing and credit usage

One instance per client (client's Cloud workspace or server)

Agency access

Invited user in the client's account. This needs the client on Team or Enterprise, because Professional has one seat; Team also adds shared app connections and admin visibility of all assets

Invited user in the client's organization; the Teams plan adds multiple teams and team roles, and below Teams you cannot set team roles

User account on the client's instance; shared projects vary by plan (1 on Cloud Starter, 3 on Pro)

Credentials

Client connects its own apps, or shares connections inside a Team account

Client creates connections in its own organization. Make's credential requests, which let someone authorize a connection the requester cannot see, only work inside Enterprise or Make Partner organizations, so they rarely apply to a client-owned Core or Pro organization

Client enters credentials on its own instance; exported workflow files carry credential names and IDs, not secrets

Spend owner

Client's task pool on the client's plan

Client organization's credits

Client's executions (Cloud) or infrastructure (self-hosted)

Moving work

Copy assets to another account copies Zaps, Tables, Forms, Interfaces, Chatbots and Agents; the originals stay in the source account

Blueprints export a scenario as JSON; team items (scenarios, connections, webhooks, data stores and more) cannot be moved between teams

Export and import workflows as JSON, or use the CLI (credential exports can contain secrets; keep them out of shared files)

Entry prices for the client's own plan:

Platform

Entry price, billed annually

Month-to-month

Zapier

Team $69 (2,000 tasks, up to 25 users). Professional ($19.99, 750 tasks) has one seat, so the agency cannot be invited

Team $103.50; Professional $29.99

Make

Core $12; Pro $21; Teams $38 (per 10,000 credits)

$16, $28 and $51

n8n Cloud

Starter €20 (2,500 executions); Pro €50 (10,000 executions)

Higher; see n8n's pricing page

Full plan detail is on Zapier pricing, Make pricing and n8n pricing.

What moving work really involves

Handovers fail on the details the export leaves behind. Zapier documents several catches for copying assets to another account:

  • It asks for app connections to be re-authenticated in the destination account.
  • It turns copied Zaps and agents off.
  • It replaces global variables with static values.
  • It leaves run history behind.
  • It does not copy related assets automatically, such as a Table a Zap uses, and the copies take the destination folder's permissions.
  • It leaves the originals in place. Turn off or delete them once the copies are live, or both will run.
  • It gives Zaps that use Webhooks by Zapier a new webhook URL, so every external system that posts to the old URL must be updated.

Make blueprints carry modules, settings and mappings, but the recipient has to create connections again. Webhooks and data stores belong to exactly one team and cannot be reassigned, so when work moves to another team or organization, plan to recreate them and update anything that calls the old webhook address. n8n exports can include credential names and IDs, and HTTP Request nodes imported from cURL may hold authentication headers, so clean them before sending a file anywhere.

All of this is easier if the work was built in the client's account from day one. Then the handover is a change of people, not a migration.

The client isolation and handoff checklist

Use one row per client. The owner is the person accountable, not whoever happens to have access.

Area

Question to settle in writing

Good default

Account and license owner

Whose name is on the platform contract and invoice?

The client. The agency is never the billing party for platform usage

Credential owner

Who created each connection, and who can revoke it?

Client staff authorize connections with a dedicated service account where the app supports it. The agency never receives passwords by email or chat

Agency access

Which agency users have access, and at what role?

Named individuals, least privilege, listed in the contract; no shared agency login. On Make below Teams you cannot set team roles, so limit access through organization roles and remove users at offboarding

Per-client spend

Who watches usage, and what happens at the limit?

Client-owned plan with usage alerts; the agency reports monthly usage against the forecast. On Make Enterprise, a team credit cap pauses scenarios when reached

AI model provider

Whose API key or AI credits does each workflow use?

The client's own provider account, or a separate key per client with spend caps set in the provider console. Never one agency key shared across clients, which mixes spend, rate limits and data processing. On Zapier, AI steps also draw from the client's task pool

Incident owner

Who is alerted when a run fails, and who decides to pause it?

Failure alerts go to both the agency on-call and a named client contact; n8n error workflows or equivalent alerts are configured before go-live

Change control

Who approves changes to live automations?

Client product owner approves; the agency keeps a change log

Data and retention

Which personal or regulated data flows through, and where are logs kept?

Documented per workflow; execution-log retention matches the client's policy

Offboarding

What happens on the last day?

The client removes agency users, rotates any credentials the agency touched, and confirms every workflow still runs under client-owned connections

On offboarding, check how removal works on each platform. When a user is removed from a Zapier account, ownership of their Zaps and folders moves to a user the account owner designates, or to the owner. In Make, only an organization owner or admin can remove users. Test the removal in advance so no automation is still running on an agency member's personal connection.

Worked example: a synthetic three-client register

Everything below is invented. "Example Agency" builds automations for three clients and keeps this register in its project workspace.

Client (synthetic)

Platform and owner

Credentials

Spend guard

Incident owner

Offboarding plan

Client A, retail

Zapier Team account owned by Client A; two agency users invited

Client's operations lead connected the store, CRM and email apps; connections shared inside the account

Client A's task pool and Client A's own AI provider key; agency sends a monthly usage report

Agency on-call, then Client A's operations lead

Remove agency users; reassign their Zaps to the operations lead; confirm webhooks unchanged

Client B, B2B services

Make organization owned by Client B on the Pro plan

Client B's admin created connections directly while screen-sharing; credential requests are not available in a Pro organization

Client B organization's credits; alert at 80%

Client B's admin, with the agency on a support retainer

Remove agency users (owner or admin action); agency deletes its local blueprint copies

Client C, healthcare-adjacent

n8n Community Edition on Client C's own server, installed and maintained by the agency under contract; Client C runs the hosting

Client C's IT created credentials on the instance

Server monitoring and execution volume reviewed monthly

Client C's IT, with an error workflow alerting both parties

Revoke agency SSH and n8n accounts; hand over runbook and backup-restore test result

What the agency does not do in this example:

  • It does not run Client A's Zaps inside the agency's own Zapier account.
  • It does not add a margin to Client B's Make credits.
  • It does not host Client C's n8n on agency servers. That would count as offering hosting, which the n8n license FAQ excludes when you also manage the instance.

Pricing your services without reselling

Keep the two invoices separate. The platform bills the client for plans and usage; the agency bills for design, build, maintenance, monitoring and training. n8n's license FAQ explicitly permits charging for workflow creation, setup, maintenance, training and consultancy. Zapier's Solution Partner Program pays referral commissions and offers lead sharing and certification. Its public description includes no right to resell Zapier or to run clients' Zaps in your own account. If you earn a referral commission, disclose it to the client. Budget your retainer for the work that scales with each client:

  • incident response;
  • change requests;
  • usage reviews;
  • credential rotation;
  • at least one offboarding rehearsal.

For how the three platforms meter usage, see AI workflow automation pricing explained. For the wider platform choice, see AI workflow automation platforms compared.

Who should not use this setup

  • Agencies that want to sell automation as their own branded product. That is Model C. It needs a commercial agreement with the vendor before you build, not after.
  • Agencies planning to host n8n for many clients on shared infrastructure without written confirmation from n8n. The sources disagree on when that needs an Enterprise license, so do not rely on your own reading.
  • Clients who will not own an account or assign a technical contact. Without a client owner for credentials and incidents, you cannot hand the work over, and you carry risk you cannot price.
  • One-off, low-value automations. If a client needs two simple Zaps, a short screen-share while the client builds them in their own account may serve them better than a managed engagement.

To compare how the platforms differ for the builds themselves, see no-code vs low-code vs self-hosted AI workflow automation and Make vs Zapier.

Evidence boundary

Official sources

Editorial guidance grounded in official product sources.

FAQ

Common questions

Can an agency run clients' Zaps in the agency's own Zapier account?

Not under Zapier's standard terms. They make the service available for your own internal business purposes and prohibit using it to provide a hosted or managed service to others. Build in an account the client owns and pays for, and join it as a user. That needs the client on Team or Enterprise, because Professional has a single seat.

Can I host n8n for my clients?

It depends on who can touch the workflows, and n8n's own sources differ. The current license FAQ allows running client automations on your own instance when clients receive only outputs and cannot build or edit workflows, and allows managing n8n on a client's own server if you do not also host it. An undated n8n Help Center answer says hosting clients' workflows and credentials on your instance needs an Enterprise license. Hosting n8n so clients build their own workflows, or white-labeling it, is not allowed. Get written confirmation from [email protected] before relying on agency hosting.

How should an agency get access to a client's app credentials?

Have the client authorize connections in its own account, ideally with a service account, rather than sending passwords. In Zapier, Make and n8n the client can connect apps directly in its own account, organization or instance while the agency watches. Make's credential requests hide credentials from the requester, but they only work inside Enterprise or Make Partner organizations, so they rarely help with a client-owned Core or Pro organization.

If you prototyped in your own Zapier account, what breaks when you copy Zaps to the client's account?

Zapier's Copy assets to another account feature requires app connections to be re-authenticated, turns copied Zaps and agents off, replaces global variables with static values, leaves run history behind, and gives Zaps using Webhooks by Zapier a new webhook URL. The originals stay in your account, so turn them off once the copies are live, and update every system that posts to the old URL.

Who should own the automation if the client has no technical staff?

The client still holds the account and pays the vendor. Name a business owner who approves changes and receives failure alerts, give the agency an admin role under a support contract, and write down the escalation path. If nobody at the client can take that role, the engagement cannot be handed over safely.

Next steps

Take the next evaluation step

Use these next pages to evaluate the strongest candidates, supporting profiles, or follow-up guides against the selection criteria.

View all tools