Managed service provider (MSP)
An IT services company that operates endpoints and infrastructure for many end customers. On Trustholm, each MSP is a tenant with isolated data and policies.
Shared vocabulary for MSP security and procurement
Plain-language definitions for Trustholm and MSP platform concepts. Use this page when security reviewers, procurement, or search engines need consistent entity names tied to shipped product behavior.
Plain-language definitions for Trustholm and MSP platform concepts. Use this page when security reviewers, procurement, or search engines need consistent entity names tied to shipped product behavior.
An IT services company that operates endpoints and infrastructure for many end customers. On Trustholm, each MSP is a tenant with isolated data and policies.
Your MSP organization on the platform. Users, scripts, agents, audit logs, and configuration stay scoped to your tenant-customers should expect this separation by default.
An end-customer business managed by the MSP inside a tenant. Customers and groups scope agents, policies, and reporting within the MSP tenant.
The team running the Trustholm SaaS: uptime, billing, base infrastructure, and cross-tenant platform controls. Distinct from MSP tenant administrators.
Recommended evaluation pattern: prove signed script governance and audit export on one customer group before mandating portfolio-wide adoption.
Optional product capability (for example Monitoring or PowerShell IDE) registered in the platform module catalog and enabled per deployment by operators.
Opt-in, time-boxed elevation for tenant technicians: request with business justification, Tenant Admin approval, optional MFA or passkey activate, then automatic expiry. Audited as PrivilegeElevation. Distinct from vendor support access and from script dual-custody. Default off.
Industry term (e.g. Microsoft Entra PIM) for eligible admin roles that activate for a limited time. Trustholm implements management-plane just-in-time privilege elevation for portal technicians - not Azure resource role activation.
Technical architecture term you may see in trust pack materials. Trustholm scopes each MSP tenant data separately; assessors can review implementation evidence on the trust hub. Buyers should treat separation as baseline platform behavior, not an optional add-on.
Resolved tenant identity on every API request and background job before any tenant data is read or written. Mismatched JWT tenant claims and selected tenant codes are rejected.
Stable alphanumeric identifier for a tenant used in agent configuration, API headers, and support workflows. Agents bind to exactly one tenant code at install time.
Tenant library of PowerShell and automation content with versioning, approval states, and execution history. Platform catalog scripts can be duplicated into a tenant library.
Cross-tenant register of published system scripts maintained by platform operators. Tenants browse read-only examples and duplicate into their own libraries to customize.
Cryptographic approval step before scripts run at scale. Signing ties execution to an approved artifact and signer identity for audit and change control.
Separation of duties for script publish: the user who submits a script for approval cannot approve it. Trustholm enforces this per tenant by default in Script Management and records denied self-approve attempts in security audit.
Work queue that schedules script runs against selected agents with attribution: who queued the job, which signed script version ran, and the outcome per machine.
Immutable-leaning record of security-relevant actions: sign-ins, script approvals, executions, configuration changes, and exports. Used for SOC 2-style evidence and insurance questionnaires.
Downloadable bundle of audit events and metadata for assessors. Trial tenants can reproduce exports to validate claims in trust documentation.
Collection of security architecture notes, subprocessors, and downloadable artifacts for vendor due diligence. Framed as evidence enablers, not product certification.
Third-party service provider that processes data on behalf of Trustholm (for example hosting or email). Listed with purpose and region on the subprocessors page.
Lightweight Windows software installed on managed machines. Agents poll the API for work, execute approved scripts, and report telemetry without inbound firewall holes.
Optional on-prem or network component that ingests SNMP and similar monitoring signals where cloud agents cannot reach devices directly.
Server-issued secret hashed on the agent and verified on anonymous agent API routes. Prevents unauthenticated command pickup when enforcement is enabled.
Per-route and per-tenant traffic caps on agent and portal APIs. Returns HTTP 429 with Retry-After so fleets back off safely under load or abuse.
Artifacts and control mappings MSPs use in their own SOC 2 program. Trustholm documents shipped controls and gaps; it does not claim SOC 2 certification for the product.
Australian Cyber Security Centre mitigation strategies. Trustholm pages map remote access and application control themes to MSP responsibilities, not vendor certification.
When an MSP uses Trustholm to process personal data, Trustholm typically acts as a processor and the MSP remains controller. DPA and subprocessors support procurement review.
Honest evidence table format on trust and compliance pages: what is implemented today, what is partial, and what remains the MSP or platform roadmap responsibility.
Procurement and security reviewers need consistent vocabulary. A public glossary helps humans and search systems align terms like tenant, agent, and audit export with Trustholm shipped behavior.
Each MSP organization operates in its own tenant boundary-customers, scripts, agents, and audit history stay scoped to your organization. Assessors who need implementation detail can review architecture evidence on the trust hub.
No. Compliance entries describe how MSPs can use Trustholm in their programs. Trust pages use Shipped/Gap rows instead of certification claims.
Start a trial tenant, run a signed script, and export audit evidence. Trust downloads and resource guides link reproduction steps from many glossary entries.