Platform overview

Multi-tenant MSP script orchestration

Trustholm proves which signed scripts ran on which client machines, so MSPs can hand auditors and cyber insurers clean evidence instead of digging through RMM logs.

Three modules, one platform

Agents, signed PowerShell, and optional monitoring - buy what your SKU includes.

3core modules

Modular packaging

Agent Management, script workflows, and optional Monitoring ship as separate entitlements.

Stack-fit guide · View bundles

Core platform capabilities

Visual overview of what ships today-links to deep feature pages below.

Technician walking through a datacenter server aisle

Built for MSPs

Multi-tenant by design

Each MSP organization operates in its own boundary. Customers, scripts, agents, and audit history stay scoped to your tenant-separation buyers should expect as baseline.

  • Role-based access scoped to your organization
  • Agent credentials bound to your tenant
  • Dedicated database option for enterprise
1tenant boundary per MSP
Review security evidence
Leadership team in boardroom discussing MSP platform strategy

Modular packaging

Buy orchestration first, depth when entitled

Agent Management, script orchestration, and optional Monitoring ship as packaged modules so owners do not pay shelfware on every seat.

  • Module gates on API routes
  • Trial bundles map SKUs to entitlements
  • Fits alongside your existing workflows
3core platform modules
Stack fit guide

Core modules: - Agent Management - lightweight Windows agent, polling credentials, fleet catalog APIs, ad-hoc and bulk push/pull file operations - PowerShell IDE - editor, approval workflows, push/pull file pipeline in script runs, platform script catalog, execution queue - Software (winget) - browse the full public winget catalog, tenant-approved packages, scheduled deployment policies, inventory compliance, and break-glass push (apps Intune's storefront may not list) - Monitoring (optional) - probe SNMP ingest, NOC dashboards, module gates

Push installers and configs. Run signed automation. Pull logs and evidence - without Win32 repackaging for every change. When the install is conditional PowerShell, not a silent MSI, Trustholm stages files, runs parameterized scripts on demand or on a schedule, and records full output for auditors.

Each MSP tenant keeps its own customers, scripts, agents, and audit history. Privileged actions land in a security audit table with JSON/CSV export - separate from HTTP request logs.

Trustholm fits when script signing, file orchestration, and audit export are the buying trigger - not when you need a different product category entirely. See Microsoft Intune comparison for coexistence guidance.

Frequently asked questions

Can I enable only some modules?

Yes. Packaged modules (Agent Management, Monitoring, PowerShell IDE) are gated globally and per-tenant via SKU entitlements. Navigation and API routes respect module enablement.

Does Trustholm push and pull files on endpoints?

Yes. Push files from your tenant library before a script runs, pull artifacts back afterward - ad-hoc, in bulk from the agent catalog, or as part of a published script pipeline in the PowerShell IDE. Every transfer ties to execution and audit records.

When should we use Trustholm instead of Intune Win32?

Use Intune Win32 for silent MSI-style apps. Use Trustholm when the install is conditional PowerShell, requires staged files, needs run-as context, or must produce exportable execution evidence. Many MSPs keep both layers.

How is my data separated from other MSPs?

Each MSP tenant is isolated by design-your customers, scripts, agents, and audit history stay scoped to your organization. Enterprise buyers can request dedicated database profiles; assessors who need implementation detail will find architecture evidence on the trust hub.

What identity providers are supported?

OIDC and SAML SSO with MFA flows. Entra ID, Google Workspace, and Okta-style providers are common configurations. Customer IdP lifecycle remains your responsibility.

Is there an API for large fleets?

Yes. Agent, script, and catalog endpoints use cursor/keyset pagination and indexed filters-designed for fleets of 100k+ agents per tenant, not unbounded dropdowns.