Agentic IT governance

Gate Rewst, Neo, and other AI automation through signed-script policy with attestation auditors accept - beside your RMM.

Gate AI agents without becoming one

Execution-intent API + attestation - beside Rewst, Neo, and your RMM.

Cybersecurity professional analyzing threat and script governance posture

Design partner

One partner, one attested run

Enable the agentic integration key, submit execution-intent from Rewst or Neo sandbox, and export attestation in an Assessor Package.

  • Same signing + approval policy as humans
  • Attestation in AgenticExecution audit category
  • MCP transport on roadmap; REST ships today
1partner pilot before broad MCP
Read partner pilot guide

MSPs are adding AI agents to ticket and automation workflows. The risk is not the chatbot - it is unsigned PowerShell running on customer endpoints without attributable proof.

Trustholm's answer is an agentic control plane: external tools request execution only through policy, and every intent gets an attestation in the security audit plane.

What ships today (REST v1)

  1. Tenant enables Settings → Integrations → Agentic and rotates an integration API key.
  2. External actor calls POST /api/Governance/execution-intent with script identity, targets, and X-External-Actor-Id.
  3. Trustholm evaluates signing + approval policy (same gates as human technicians).
  4. Approved intents queue to Windows agents; completion writes agentic.execution.attestation audit events.
  5. Operators export Assessor Packages that include the audit slice for questionnaires.

API reference for engineers: documented in the Trustholm product docs under Agentic governance API. Partner operators: agentic partner pilot runbook.

Design partner pilot (Rewst or Neo)

  1. Pick one published, signed platform or tenant script.
  2. Configure the agentic integration key in a non-production tenant.
  3. Submit one execution-intent from the partner sandbox.
  4. Approve if required; confirm agent run and attestation in Security Centre / audit export.
  5. Attach the Assessor Package ZIP to your internal business case.

Honest scope

  • Shipped: REST execution-intent, attestation audit, portal settings, rules-first Operations Intelligence bridge (operations_intelligence actor).
  • Roadmap: Native MCP transport, outbound webhook callbacks on attestation, broader marketplace connectors.
  • Out of scope: Generative auto-execution, Datadog-class RCA chatbots, replacing your RMM.

Bundles

  • Govern - script governance + agents + Assessor Package (Govern caps)
  • Evidence - extended export window/row caps + compliance modules
  • Observe - optional monitoring/NOC upsell - not the hero GTM

Frequently asked questions

Do you replace Neo or Rewst?

No. Those tools own L1 / orchestration UX. Trustholm gates privileged PowerShell they request and proves what ran.

Is MCP required?

Not for v1. The REST execution-intent contract is the integration standard. MCP is a transport roadmap item over the same policy engine.

Can Operations Intelligence submit intents?

Yes. Approving a rules-first suggestion can submit an execution-intent with actor operations_intelligence, then attest like any other agentic run.