Certificate expiry shouldn’t be something a client discovers before the agency does.
In this article
- Why does SSL certificate management need to be centralised for an agency?
- What actually goes wrong with client SSL certificates?
- How does Sentinel monitor SSL across multiple client sites?
- SSL certificate management checklist for agencies
- FAQ
Agencies should manage client SSL certificates by tracking validity, expiry and chain configuration for every site in one place, rather than relying on browser warnings or client complaints to reveal a problem. Sentinel monitors certificate validity, expiry and chain or hostname issues continuously, so an agency can renew or fix a certificate before it breaks a client’s checkout or login page.
Key takeaways
- An expired or misconfigured SSL certificate breaks trust indicators and can take checkout, login or API endpoints offline – see SSL certificate expiry.
- Sentinel monitors certificate validity, expiry and chain or hostname issues across every client site from one account.
- Auto-renewal tools fail silently often enough that they still need independent monitoring, not just trust.
- Certificate ownership and renewal method should be recorded per client, the same way domain and hosting ownership is.
Why does SSL certificate management need to be centralised for an agency?
Because certificates fail quietly, per site, and the agency is usually the last to know unless something is actively watching. A browser warning on a client’s checkout page is not an acceptable first alert – by the time a client or their customer sees it, the damage to trust and conversions has already happened.
Sentinel monitors SSL certificate validity, expiry and chain or hostname issues, giving an agency one place to see certificate status across every client instead of checking each site individually.
What actually goes wrong with client SSL certificates?
The most common failure is simple expiry – a certificate that was never set to auto-renew, or where auto-renewal silently failed. Beyond expiry, chain and hostname issues are just as disruptive: a certificate that’s technically valid but misconfigured for a subdomain, or missing an intermediate certificate in the chain, can still break trust in a browser. A full breakdown of causes and consequences is covered in SSL certificate expiry.
How does Sentinel monitor SSL across multiple client sites?
Sentinel monitors SSL certificate validity, expiry and chain or hostname issues as a standing check per client site, alongside uptime, DNS and domain monitoring. Alerts are configurable per monitor, so a certificate issue on one client can be routed to the specific person responsible for that account rather than a shared inbox.
SSL certificate management checklist for agencies
- Record the certificate issuer and renewal method (automated or manual) for every client site.
- Monitor validity, expiry and chain or hostname issues centrally, not on a per-site basis.
- Name an alert contact who can act on a renewal, not just receive a notification.
- Confirm the certificate covers every subdomain and endpoint in use, not just the primary domain.
- Re-check certificate status after any hosting or CDN migration, since these commonly break auto-renewal.
Original Sentinel evidence

Frequently asked questions
Does auto-renewal mean an agency doesn’t need to monitor certificates?
No. Auto-renewal tools can fail silently – a DNS change, hosting migration or expired validation token can stop renewal without any warning. Independent monitoring catches that before a client’s visitors do.
What’s the difference between a certificate expiring and a chain or hostname error?
Expiry means the certificate’s validity window has passed. A chain or hostname error means the certificate is still valid but misconfigured – for example, missing an intermediate certificate, or not covering the exact subdomain being accessed. Both produce a browser warning, but they need different fixes.
Who should receive SSL alerts for a client site – the agency or the client?
Usually the agency, since certificate renewal is typically a technical task the client isn’t equipped to action. The agency can then decide whether to loop the client in, rather than the client discovering the problem first.
Stop finding out about certificate failures from your clients
Sentinel monitors SSL certificate validity, expiry and configuration across every client site alongside uptime, DNS and domain status. This article is part of Sentinel’s guide to website monitoring for agencies.