Trustholm is the policy and evidence engine for MSP privileged automation. The control plane governs who may author, who must approve, and what runs on customer endpoints - with exportable audit designed for assessor review.
Agentic gate (shipped REST v1): External automation and AI tools (Rewst, Neo, ConnectWise zofiQ, MCP clients) request privileged PowerShell through POST /api/Governance/execution-intent. Trustholm evaluates signing + approval policy, queues the agent dispatch, and writes attestation into the security audit plane (AgenticExecution).
Trustholm is the gate, not an L1 ticket chatbot. MCP transport remains on the roadmap; the REST contract is the integration standard today.
See /platform/agentic-governance for the partner pilot path.
What ships today: - Signed PowerShell lifecycle from IDE to execution queue - Tenant signing policy and approval workflows - Assessor Package ZIP (Govern 30-day / 10k-row caps; Evidence 365-day / 100k-row caps via retention SKUs) - Agentic execution-intent API + tenant integration keys + attestation audit - Rules-first script risk scoring and Operations Intelligence priority queue (beta SKU) - Module packaging: Govern (scripts + agents), Evidence (+ compliance), optional Observe (monitoring/NOC)
What we do not claim: Full RMM replacement, lowest per-agent pricing, LogicMonitor parity, or vendor SOC 2 Type II attestation. Compare pages document when NinjaOne, Automate, or PDQ remain the better primary platform. SOC 2 Type II observation is in progress - see the trust hub.
Evaluation path: Start Govern instant trial, run one signed script, download an Assessor Package, then decide whether Evidence tier fits regulated customers. Stack-fit and platform pages describe complement positioning for procurement.