Agentic IT governance

Gate Rewst, Neo, and other AI automation through signed-script policy with attestation auditors accept, beside your RMM.

Gate AI agents without becoming one

Execution-intent API + attestation, beside Rewst, Neo, and your RMM.

Cybersecurity professional analyzing threat and script governance posture

Design partner

One partner, one attested run

Enable the agentic integration key, submit execution-intent from Rewst or Neo sandbox, and export attestation in an Assessor Package.

  • Same signing + approval policy as humans
  • Attestation in AgenticExecution audit category
  • MCP transport on roadmap; REST ships today
1partner pilot before broad MCP
Read partner pilot guide

MSPs are adding AI agents to ticket and automation workflows. The risk is not the chatbot. It is unsigned PowerShell running on customer endpoints without attributable proof.

Trustholm's answer is an agentic control plane: external tools request execution only through policy, and every intent gets an attestation in the security audit plane.

What ships today (REST v1)

  1. Tenant enables Settings → Integrations → Agentic and rotates an integration API key.
  2. External actor calls POST /api/Governance/execution-intent with script identity, targets, and X-External-Actor-Id.
  3. Trustholm evaluates signing + approval policy (same gates as human technicians).
  4. Approved intents queue to Windows agents; completion writes agentic.execution.attestation audit events.
  5. Operators export Assessor Packages that include the audit slice for questionnaires.

API reference for engineers: documented in the Trustholm product docs under Agentic governance API. Partner operators: agentic partner pilot runbook.

Design partner pilot (Rewst or Neo)

  1. Pick one published, signed platform or tenant script.
  2. Configure the agentic integration key in a non-production tenant.
  3. Submit one execution-intent from the partner sandbox.
  4. Approve if required; confirm agent run and attestation in Security Centre / audit export.
  5. Attach the Assessor Package ZIP to your internal business case.

Honest scope

  • Shipped: REST execution-intent, attestation audit, portal settings, rules-first Operations Intelligence bridge (operations_intelligence actor).
  • Roadmap: Native MCP transport, outbound webhook callbacks on attestation, broader marketplace connectors.
  • Out of scope: Generative auto-execution, Datadog-class RCA chatbots, replacing your RMM.

Bundles

  • Govern: script governance + agents + Assessor Package (Govern caps)
  • Evidence: extended export window/row caps + compliance modules
  • Observe: optional monitoring/NOC upsell, not the hero GTM

Frequently asked questions

Do you replace Neo or Rewst?

No. Those tools own L1 / orchestration UX. Trustholm gates privileged PowerShell they request and proves what ran.

Is MCP required?

Not for v1. The REST execution-intent contract is the integration standard. MCP is a transport roadmap item over the same policy engine.

Can Operations Intelligence submit intents?

Yes. Approving a rules-first suggestion can submit an execution-intent with actor operations_intelligence, then attest like any other agentic run.