Governance & agentic control plane

Policy and evidence for privileged automation - signed scripts, approval gates, audit export, and an execution-intent API that gates external AI agents beside your RMM.

Governance wedge in one session

Signed script, approval gate, Assessor Package - beside your RMM.

Developer workspace with code on screen for PowerShell orchestration

Pilot target

First signed script plus Assessor Package

Govern instant trial provisions script governance entitlements. Run one approved script and download an Assessor Package for your assessor window.

  • Tenant signing policy before dispatch
  • Execution attribution per agent
  • Assessor Package ZIP for GRC tools
<30mguided time to first Assessor Package
Start Govern trial

Trustholm is the policy and evidence engine for MSP privileged automation. The control plane governs who may author, who must approve, and what runs on customer endpoints - with exportable audit designed for assessor review.

Agentic gate (shipped REST v1): External automation and AI tools (Rewst, Neo, ConnectWise zofiQ, MCP clients) request privileged PowerShell through POST /api/Governance/execution-intent. Trustholm evaluates signing + approval policy, queues the agent dispatch, and writes attestation into the security audit plane (AgenticExecution).

Trustholm is the gate, not an L1 ticket chatbot. MCP transport remains on the roadmap; the REST contract is the integration standard today.

See /platform/agentic-governance for the partner pilot path.

What ships today: - Signed PowerShell lifecycle from IDE to execution queue - Tenant signing policy and approval workflows - Assessor Package ZIP (Govern 30-day / 10k-row caps; Evidence 365-day / 100k-row caps via retention SKUs) - Agentic execution-intent API + tenant integration keys + attestation audit - Rules-first script risk scoring and Operations Intelligence priority queue (beta SKU) - Module packaging: Govern (scripts + agents), Evidence (+ compliance), optional Observe (monitoring/NOC)

What we do not claim: Full RMM replacement, lowest per-agent pricing, LogicMonitor parity, or vendor SOC 2 Type II attestation. Compare pages document when NinjaOne, Automate, or PDQ remain the better primary platform. SOC 2 Type II observation is in progress - see the trust hub.

Evaluation path: Start Govern instant trial, run one signed script, download an Assessor Package, then decide whether Evidence tier fits regulated customers. Stack-fit and platform pages describe complement positioning for procurement.

Frequently asked questions

Is this an AI agent product?

No - we do not compete with Neo, Robin, or zofiQ for autonomous L1 ticket resolution. We gate their privileged execution: external agents submit execution-intent through Trustholm policy and get assessor-ready attestation of what ran.

How does this relate to my RMM?

Keep patch and remote control in your incumbent RMM. Use Trustholm for signed orchestration, Assessor Package export, and agentic attestation beside it.

Which tier should I trial?

Govern is instant when enabled - script governance and agent seats with a 30-day Assessor Package window. Evidence adds compliance modules and extended export caps (365 days / 100k rows) for regulated MSPs.