These are anonymized composite stories aligned to Epic 5 design-partner templates. They are not named customer logos until legal approval lands.
A strongly attributed internal write-up of story #1 lives under product compliance docs (DOCS/07-Compliance/case-studies/). Use them for internal business cases, questionnaire framing, and sales enablement while SOC 2 Type II observation continues - Trustholm is not Type II certified.
Trustholm sells Path B outcomes: governed privileged automation with proof, beside the incumbent RMM, gating external AI agents. These stories map to that claim without inventing certification slogans. Trustholm supplies assessor artifacts; it does not automate customer SOC 2 Trust Services Criteria like a GRC product.
How to use these stories
Security reviewers want evidence, not adjectives. Attach an Assessor Package sample, the Shipped/Gap trust pack, and SIG Lite answers alongside these narratives. Finance owners want a clear budget line: Govern for script governance and agents; Evidence when retention and compliance modules matter; Observe only when monitoring is entitled and wanted.
Do not present these composites as signed customer case studies. Mark them as anonymized evaluation material until legal clears named quotes.
1. Govern wedge - first Assessor Package in one session
Persona: MSP security lead evaluating script governance beside an incumbent RMM.
Buying trigger: Customer questionnaires asked who ran privileged scripts, under which approval, with exportable evidence. Screenshots from the RMM console were rejected as insufficient.
Pilot path: Instant Govern trial when enabled. Install one Windows agent. Duplicate a platform governance starter script. Enforce signing policy for the pilot group. Run one approved script. Open Security Centre and generate an Assessor Package for a 30-day window.
Outcome: Trial POC completed. Assessor Package ZIP delivered to a customer CISO for a questionnaire cycle. Signing policy remained enabled after the trial because technicians already had a working path.
What mattered technically: Signing policy before dispatch, execution attribution per agent, Assessor Package under Govern tier caps (30 days / 10k rows), honest Shipped/Gap trust artifacts linked from the ZIP.
Procurement language: "We can show who ran what, where, and under which policy - without replacing our RMM."
Commercial note: Govern closes the wedge. Evidence becomes the upsell when the same buyer asks for longer retention or compliance module evidence in the same package.
2. Evidence tier - retention-aligned export
Persona: Compliance-focused MSP with COMPLIANCE_RETENTION_90D (or longer) entitlement on the Evidence marketing bundle.
Buying trigger: An assessor asked for a year-scale audit window and a clear statement of export caps. Silent truncation of audit rows was unacceptable for their evidence folder.
Pilot path: Upgrade from Govern to Evidence. Confirm active retention SKUs. Call Assessor Package limits API to display Evidence tier caps in Security Centre. Generate a package for a 90-day window. Attempt an oversized window intentionally to verify a clear 403 rather than a partial ZIP.
Outcome: Assessor Package at Evidence-tier caps (365-day window / 100k rows) with integrity summary included. Operators understood when to narrow dates versus when to keep Evidence entitlements.
What mattered technically: Export limits resolved through IEntitlementResolver.GetAssessorPackageExportLimitsAsync. Evidence unlock SKUs include COMPLIANCE_RETENTION_90D, COMPLIANCE_RETENTION_1Y, COMPLIANCE_RETENTION_7Y, and COMPLIANCE_REPORT_PACK. Window and matching row-cap violations return 403 with upgrade guidance.
Procurement language: "Export caps are enforced server-side by entitlement. We do not silently drop rows out of the assessor ZIP."
Commercial note: Evidence attach rate is a Path B ARR lever. Position it as questionnaire and retention value, not as monitoring seats.
3. Script risk gate - blocked dangerous publish
Persona: Script manager approving technician automation imported from a legacy RMM library.
Buying trigger: A technician imported a helper script that used an Invoke-Expression download cradle. The MSP wanted rules-first prevention before publish, not a chatbot that invents new scripts.
Pilot path: Enable rules-first script risk scoring on publish. Attempt to publish the dangerous script and observe the block. Rewrite to remove the cradle. Re-score and approve through the normal workflow. Optionally enable Operations Intelligence beta so related suggestions appear in a priority queue and can submit execution-intent after human approval.
Outcome: Rules-first risk score blocked the cradle before publish. Approval workflow recorded the remediated rewrite. When remediation ran later through an approved suggestion, attestation linked to the agentic gate.
What mattered technically: Invisible intelligence embedded in publish and operations surfaces - not a chat sidebar. Recommendations stay inside approved script catalogs. Agentic bridge uses operations_intelligence as the external actor id when suggestions submit intents.
Procurement language: "We block known-dangerous patterns at publish and keep AI agents behind the same signing policy as humans."
Commercial note: This story supports Epic 4 and Epic 4.5 together: gate external AI, score scripts, prioritize follow-up, attest what ran.
Publication status and trust discipline
Named quotes and logos require customer legal approval. Track stubs in product compliance docs (DOCS/07-Compliance/case-studies/README.md). SIG Lite JSON includes agentic attestation and operations intelligence rows for sales questionnaires.
SOC 2 Type II remains observation in progress, not certified. See /trust for honest positioning. Assessor Packages include trust artifact links and claim-integrity annexes (Essential Eight honesty CSV; Entra MFA coverage JSON when synced) - never certification claims.
When you are ready to publish named stories, replace placeholders with approved quotes, keep metrics factual, and link each story to Govern, Evidence, or agentic outcomes so buyers know which SKU funded the result.