Trustholm is the policy and evidence engine for MSP privileged automation. The control plane governs who may author, who must approve, and what runs on customer endpoints, with exportable audit designed for assessor review.
Agentic gate (shipped REST v1): External automation and AI tools (Rewst, Neo, ConnectWise zofiQ, MCP clients) request privileged PowerShell through POST /api/Governance/execution-intent. Trustholm evaluates signing + approval policy, queues the agent dispatch, and writes attestation into the security audit plane (AgenticExecution).
Trustholm is the gate, not an L1 ticket chatbot. MCP transport remains on the roadmap; the REST contract is the integration standard today.
See /govern/agentic-governance for the partner pilot path.
What ships today: - Signed PowerShell lifecycle from IDE to execution queue - Tenant signing policy and approval workflows - Assessor Package ZIP (Govern 30-day / 10k-row caps; Evidence 365-day / 100k-row caps via retention SKUs) - Agentic execution-intent API + tenant integration keys + attestation audit - Rules-first script risk scoring and Operations Intelligence priority queue (beta SKU) - Module packaging: Govern (scripts + agents), Evidence (+ compliance), optional Observe (monitoring/NOC)
What we do not claim: Full RMM replacement, lowest per-agent pricing, LogicMonitor parity, or vendor SOC 2 Type II attestation. Compare pages document when NinjaOne, Automate, or PDQ remain the better primary platform. SOC 2 Type II observation is in progress. See the trust hub.
Evaluation path: Start Govern instant trial, run one signed script, download an Assessor Package, then decide whether Evidence tier fits regulated customers. Stack-fit and platform pages describe complement positioning for procurement.