Modular packaging
Agent Management, script workflows, and optional Monitoring ship as separate entitlements.
Multi-tenant MSP script orchestration
Trustholm proves which signed scripts ran on which client machines, so MSPs can hand auditors and cyber insurers clean evidence instead of digging through RMM logs.
Agents, signed PowerShell, and optional monitoring - buy what your SKU includes.
Agent Management, script workflows, and optional Monitoring ship as separate entitlements.
Visual overview of what ships today-links to deep feature pages below.

Built for MSPs
Each MSP organization operates in its own boundary. Customers, scripts, agents, and audit history stay scoped to your tenant-separation buyers should expect as baseline.

Modular packaging
Agent Management, script orchestration, and optional Monitoring ship as packaged modules so owners do not pay shelfware on every seat.
Jump to feature depth, tenancy evidence, or stack-fit guidance.

Lightweight Windows agents with polling credentials and fleet-scale catalog APIs.

IDE, signing policy, platform catalog, and execution queue.

Policy and evidence control plane - Govern to Evidence to Observe.

Gate Rewst/Neo execution-intent with attestation auditors accept.

Packaged monitoring/NOC upsell when entitled - not the hero GTM.

Shipped/Gap evidence, access controls, and audit export.

Where script governance belongs in your environment.
Core modules: - Agent Management - lightweight Windows agent, polling credentials, fleet catalog APIs, ad-hoc and bulk push/pull file operations - PowerShell IDE - editor, approval workflows, push/pull file pipeline in script runs, platform script catalog, execution queue - Software (winget) - browse the full public winget catalog, tenant-approved packages, scheduled deployment policies, inventory compliance, and break-glass push (apps Intune's storefront may not list) - Monitoring (optional) - probe SNMP ingest, NOC dashboards, module gates
Push installers and configs. Run signed automation. Pull logs and evidence - without Win32 repackaging for every change. When the install is conditional PowerShell, not a silent MSI, Trustholm stages files, runs parameterized scripts on demand or on a schedule, and records full output for auditors.
Each MSP tenant keeps its own customers, scripts, agents, and audit history. Privileged actions land in a security audit table with JSON/CSV export - separate from HTTP request logs.
Trustholm fits when script signing, file orchestration, and audit export are the buying trigger - not when you need a different product category entirely. See Microsoft Intune comparison for coexistence guidance.
Yes. Packaged modules (Agent Management, Monitoring, PowerShell IDE) are gated globally and per-tenant via SKU entitlements. Navigation and API routes respect module enablement.
Yes. Push files from your tenant library before a script runs, pull artifacts back afterward - ad-hoc, in bulk from the agent catalog, or as part of a published script pipeline in the PowerShell IDE. Every transfer ties to execution and audit records.
Use Intune Win32 for silent MSI-style apps. Use Trustholm when the install is conditional PowerShell, requires staged files, needs run-as context, or must produce exportable execution evidence. Many MSPs keep both layers.
Each MSP tenant is isolated by design-your customers, scripts, agents, and audit history stay scoped to your organization. Enterprise buyers can request dedicated database profiles; assessors who need implementation detail will find architecture evidence on the trust hub.
OIDC and SAML SSO with MFA flows. Entra ID, Google Workspace, and Okta-style providers are common configurations. Customer IdP lifecycle remains your responsibility.
Yes. Agent, script, and catalog endpoints use cursor/keyset pagination and indexed filters-designed for fleets of 100k+ agents per tenant, not unbounded dropdowns.