Prove every signedscript run

Govern PowerShell with signing policy and exportable audit, so MSPs can answer assessors and insurers without RMM log archaeology.

Install one agent, run one signed script, and export the audit file. Most teams do it in under thirty minutes.

<30m
Pilot to first audit export
1
Govern for signed scripts
15MB
Lightweight agent target

No credit card · Select product interestPilot access within two business days · Enterprise reviewed manually

Night view of connected regions representing multi-tenant MSP fleet operations

Try it before you buy

Most teams export their first audit file in under thirty minutes.

<30min to first export

One pilot session

Install one agent, run one signed script, export the audit file. That is usually enough to answer the buy-or-not question.

Govern modules that close the audit gap

Signed scripts, agents, trust evidence, and optional monitoring, beside your RMM.

Developer workspace with code on screen for PowerShell orchestration

Scripts

Sign, approve, and run PowerShell

Block unsigned scripts when policy requires it. Every run is recorded with who ran what on which machine.

  • PowerShell IDE with approval workflows
  • Push/pull file pipeline in script runs
  • Platform catalog duplication into tenant libraries
  • Execution queue with a clear audit record
  • Complex install pipelines when Win32 is the wrong tool
<30 mintypical first signed script + export
Explore script governance
Endpoint laptop on desk representing managed Windows fleet deployments

Agents

Lightweight Windows agents

Deploy a small agent that polls outbound. Search and target machines with catalog APIs built for large fleets.

  • ~15MB single-file deployment target
  • Outbound polling, no inbound firewall holes
  • Catalog APIs for 100k+ agents per tenant
15MBagent footprint target
Explore agent management
Procurement reviewer signing vendor security questionnaire documents

Trust

Evidence for security reviewers

Download what is built vs. not. Export audit rows from trial and attach them to your questionnaire.

  • Shipped and Gap tables on the trust hub
  • Downloadable trust pack
  • Architecture notes for procurement
1trial session to export audit rows
Download trust materials
NOC-style analytics display for monitoring module evaluations

Monitoring

Optional probes and NOC views

Add SNMP ingest and NOC dashboards when your SKU includes the Monitoring module.

  • Packaged Monitoring module gates
  • Probe ingest with rollup retention controls
  • Lazy policy trees for fleet-scale operators
Optionalmodule, buy when entitled
Explore monitoring module

What you get from a Govern pilot

Three distinct outcomes: pilot fit, audit export, and fleet scale.

Test on one customer first

1pilot tenant before portfolio rollout

Run a pilot group before you mandate Govern fleet-wide.

Compare options

Hand auditors a file

JSON/CSVexportable script run history

Export who ran which signed script on which machine, without digging through RMM logs.

Review security evidence

Grow the fleet safely

100k+agents per tenant via catalog APIs

Server-backed search and pagination, not full-fleet dropdowns.

See Govern architecture

What early evaluators report

Design-partner MSPs and security reviewers validating script governance fit-not certification marketing.

“We reproduced a signed script run and CSV audit export in one pilot session-that export slice is what our cyber insurer actually asked for.”

MSP operations leadAustralian MSP · 120-endpoint pilot · Q2 2026 evaluation
40+MSP evaluations in progress
<30mMedian time to first audit export in trial
Shipped/GapHonest evidence tables published
69%MSP leaders reporting 2+ breaches in 12 months

Privileged script runs need governance proof

Signing, four-eyes approval, and exportable audit-verify in a trial tenant. No SOC 2 badge claims; honest Shipped/Gap evidence for assessors.

Govern pricing

Public bundles from your operator catalog-or contact us for enterprise

Enterprise
Contact sales
Invoice/PO, dedicated isolation, custom entitlements

Core modules: - Agent Management: lightweight Windows agent, polling credentials, fleet catalog APIs, ad-hoc and bulk push/pull file operations - PowerShell IDE: editor, approval workflows, push/pull file pipeline in script runs, platform script catalog, execution queue - Software (winget): browse the full public winget catalog, tenant-approved packages, scheduled deployment policies, inventory compliance, and break-glass push (apps Intune's storefront may not list) - Monitoring (optional): probe SNMP ingest, NOC dashboards, module gates

Push installers and configs. Run signed automation. Pull logs and evidence without Win32 repackaging for every change. When the install is conditional PowerShell, not a silent MSI, Govern stages files, runs parameterized scripts on demand or on a schedule, and records full output for auditors.

Each MSP tenant keeps its own customers, scripts, agents, and audit history. Privileged actions land in a security audit table with JSON/CSV export, separate from HTTP request logs.

Govern fits when script signing, file orchestration, and audit export are the buying trigger, not when you need a different Trustholm product. See the product family and Microsoft Intune comparison for coexistence guidance.

Govern questions

Can I enable only some modules?

Yes. Packaged modules (Agent Management, Monitoring, PowerShell IDE) are gated globally and per-tenant via SKU entitlements. Navigation and API routes respect module enablement.

Does Govern push and pull files on endpoints?

Yes. Push files from your tenant library before a script runs, pull artifacts back afterward, ad-hoc, in bulk from the agent catalog, or as part of a published script pipeline in the PowerShell IDE. Every transfer ties to execution and audit records.

When should we use Govern instead of Intune Win32?

Use Intune Win32 for silent MSI-style apps. Use Govern when the install is conditional PowerShell, requires staged files, needs run-as context, or must produce exportable execution evidence. Many MSPs keep both layers.

How is my data separated from other MSPs?

Each MSP tenant is isolated by design. Your customers, scripts, agents, and audit history stay scoped to your organization. Enterprise buyers can request dedicated database profiles; assessors who need implementation detail will find architecture evidence on the trust hub.

What identity providers are supported?

OIDC and SAML SSO with MFA flows. Entra ID, Google Workspace, and Okta-style providers are common configurations. Customer IdP lifecycle remains your responsibility.

Is there an API for large fleets?

Yes. Agent, script, and catalog endpoints use cursor/keyset pagination and indexed filters, designed for fleets of 100k+ agents per tenant, not unbounded dropdowns.