It doesn't provide for allowing clients to manage their own firewalls independently in a sort of secure multitenant scheme.
As long as you can reach the firewalls via ssh and https and get syslogs from them, you can manage multiple customers' firewalls in different data centers / zones / environments.