European Union MSPs adopting agentic automation (Neo, Rewst, ConnectWise zofiQ, MCP clients) face buyer questions about human oversight, logging, and risk management under the EU AI Act and broader ICT governance programs. Trustholm is not an EU AI foundation model vendor.
We are the policy and evidence engine that gates privileged execution: external tools request runs through POST /api/Governance/execution-intent; signing and approval policy apply; attestations record what ran. This resource helps DPOs, vCISOs, and procurement teams frame Trustholm as a human-in-the-loop control plane beside US RMM and agentic tools.
The governance gap agentic tools create
Agentic platforms can propose and trigger remediation faster than manual script queues. Regulated EU buyers ask: who authorized execution, under which policy, with what audit trail, and can we prove human oversight?
Running agentic actions only through a US RMM script channel may not provide separable governance evidence or European-addressable control planes. Trustholm adds a neutral gate with exportable security audit-not autonomous L1 ticket resolution.
We do not claim EU AI Act conformity assessment, CE marking for AI systems, or that Trustholm itself is a high-risk AI system in every deployment. Classification depends on use case, automation scope, and legal counsel.
Execution-intent API: request, policy, attestation
Shipped REST flow (see product agentic governance API documentation):
- External integration submits execution intent with script reference and context
- Trustholm evaluates signing policy and approval requirements
- Approved runs dispatch through the standard agent queue
- Attestation and security audit rows record intent, decision, and outcome
Tenant integration keys scope agentic callers. No generative auto-execution: recommendations reference approved catalog scripts only.
Human oversight narrative for procurement
Map Trustholm controls to buyer questions:
| Buyer question | Trustholm response | |----------------|-------------------| | Can agents run unsigned code? | Signing policy blocks when configured | | Who approved this run?
| Audit export shows approver and publisher | | Can we gate third-party AI tools? | Execution-intent API with tenant keys | | Is there a chatbot executing scripts?
| No-chatbot-first AI rejected; gate only | | Where is evidence stored? | Tenant-scoped security audit plane |
Pair with customer AI governance policies and DPIAs for agentic tool vendors separately.
EU digital sovereignty angle
European buyers may prefer a European-led governance vendor gating US agentic tools while retaining US RMM for patch breadth. Document stack boundaries: agentic vendor proposes, Trustholm enforces policy and records proof, RMM may still handle unrelated monitoring. See /resources/digital-sovereignty-eu-msp-saas for residency.
Relationship to GDPR, NIS2, and DORA
Agentic metadata (operator identities, intent records, audit rows) may contain personal data-process under GDPR processor framing (/compliance/eu/gdpr-processor-framing). Financial sector clients add DORA ICT register entries. NIS2 supply-chain reviews ask for subprocessors transparency when agentic automation touches essential entities.
What we do not ship (honest gaps)
- MCP transport for execution-intent (roadmap; REST v1 shipped)
- Broad autonomous remediation or generative script authoring
- EU AI Act conformity certificates or model cards for Trustholm as AI system
- Native SIEM streaming of attestations (export JSON/CSV today)
Document gaps in vendor files and compensating controls your security team accepts.
MSP pilot checklist for agentic governance
- Enable tenant agentic integration settings and rotate API key
- Connect one external tool to execution-intent in sandbox tenant
- Run denied unsigned intent-expect policy block with audit row
- Run approved intent-export attestation slice from audit API
- Attach export to customer AI governance file
- Document US agentic vendor + EU governance gate architecture in DPIA
Trust hub cross-reference
See /platform/governance for product narrative and /compliance/eu for regulatory spokes. AI Act certification is not claimed.
Appendix: evidence reproduction steps
In trial tenant: submit execution intent via API, capture policy decision in audit export, screenshot integration settings, store with timestamps in GRC folder. Re-run when signing policy or Shipped/Gap rows change. Document denied intents and approval paths for assessor walkthroughs. Pair with customer AI governance policy version numbers in footnotes.