Agentic governance for partners: public overview

Updated 2026-08-26

How Rewst, Neo, and similar tools request privileged PowerShell through Trustholm without a public OpenAPI dump or repo doc links as the UX.

Agentic governance for partners: public overview

Visual anchor before the full guide below.

Leadership team in collaborative workshop planning script governance rollout

agentic

Agentic governance for partners: public overview

How Rewst, Neo, and similar tools request privileged PowerShell through Trustholm without a public OpenAPI dump or repo doc links as the UX.

  • Reproduce steps in trial
  • Export audit evidence
  • Attach to GRC binder
1session reproduction target
Start free trial

Published 2026-08-26 · Pillar: agentic

MSPs are connecting automation platforms and AI agents to privileged scripts. ” The risk is unsigned PowerShell on customer endpoints without attributable proof.

Trustholm’s public partner story is simple: we are the gate. Partners submit an execution intent.

Policy (signing, approval, tenant scope) decides. The agent runs only what passed.

Attestation lands in the security audit plane.

This page is a sanitized overview. It is not a full OpenAPI site, not a Docusaurus portal, and not a substitute for the partner runbook your SE shares under NDA.

What partners should implement

  1. Authenticate as a tenant-scoped principal (or documented partner credential).
  2. POST an execution intent that names the script or runbook, targets, and optional PSA ticket fields.
  3. Wait for policy: deny is a first-class outcome.
  4. Poll or webhook for completion according to the partner guide you were given.
  5. Never cache a “god token” that bypasses signing.

MCP transport exists as a sidecar preview for some operators. REST execution-intent remains the integration standard to talk about in public.

What Trustholm will not be

We will not be your L1 ticket resolution bot versus Neo, Robin, or ConnectWise zofiQ. We will not auto-execute model-drafted scripts without the same gates. We will not claim a live design-partner logo until that attestation exists.

Evidence the assessor wants

AgenticExecution (or equivalent) audit rows, Assessor agentic annex files when present, and a denied intent example. If GOV-4 live partner volume is still open, say so. Do not invent production telemetry.

Customer responsibilities

Partners still need least-privilege in their own tools. Trustholm cannot stop a partner from storing tenant API keys badly. Rotate credentials. Prefer customer-held signing keys so a compromised SaaS control plane cannot mint new mutate authority on the recommended path.

How to start

Public narrative: /govern/agentic-governance. Trial: run one intent against a lab agent. Sales: do not promise OpenAPI-complete docs on www. Operator help in the product covers the fields that matter.

Honesty on availability

If a capability is CodeComplete but not LabVerified (SSO, billing webhooks), do not tell a partner it is live-signed-off. Point at the capability verification registry internally.

Out of scope on this page

Repo paths under DOCS/, raw Swagger, and internal ADRs are not the primary UX. If you need those, you are past marketing and into an engaged SE thread.

Field notes (partner gate overview)

Public talk track: we are the gate, not the L1 bot. REST execution-intent is the standard. MCP is optional sidecar. Deny is first-class. Never cache a god token. Do not promise OpenAPI-complete docs on www. Do not name a design partner until attestation exists.

Date the diligence folder YYYY-MM-DD and record the portal product version. Re-export after upgrades. Do not reuse last week's grant token. Public starter PDFs copy without email. Gated files need a live grant. If the Platform API is down, HubSpot may still capture the lead with no download buttons. Say that out loud so GRC does not think the trial is broken.

Walk one denied unsigned dispatch when RequireSigned is on. Capture a 403 from a mismatched tenant header. Export audit for one window and confirm no foreign tenant codes. Open the Assessor ZIP trust-artifacts.json and read the limitations appendix. Leave Gap rows as Gap. Do not paste LabVerified for Entra, Okta, Stripe, or SMTP until the capability verification registry says LabVerified.

Keep the incumbent RMM. Trustholm does not replace OS patching, remote takeover, or a NOC hero pitch. Probe and observe features are operator tools, not the reason a council or insurer should buy. Named design-partner logos stay off marketing pages until attestation exists.

Store ZIP files with access control. They hold tenant metadata even when secrets are stripped. Email security@trustholm.com only for Manual DPA or pentest summary. Do not invent those PDFs on www.

If someone asks to select all agents in a dropdown, stop and show catalog pagination. If someone asks for a second region or a single global edge FQDN, say Phase 1 Australia edge is current and global discovery is deferred.

Copy the trust hub sentence into the packet: we do not hold SOC 2 Type I or Type II and do not claim an observation period. Trustholm supplies technical artifacts for the customer's program. It does not automate customer SOC 2 Trust Services Criteria like a GRC product.

Assign an owner to refresh this packet quarterly or after a Shipped/Gap change. Workshops go stale. Prefer live reproduction over architecture slides. Prefer export files over screenshots alone, then keep both.

Public talk track: we are the gate, not the L1 bot. REST execution-intent is the standard. MCP is optional sidecar. Deny is first-class. Never cache a god token. Do not promise OpenAPI-complete docs on www. Do not name a design partner until attestation exists.

Frequently asked questions

Is this a public OpenAPI for Rewst?

No. This is a narrative overview. Partners get a runbook and the REST contract through a guided engagement.

Does Trustholm replace Neo or Robin?

No. Those tools may request work. Trustholm gates privileged script execution.

Can a compromised Trustholm cloud sign new scripts?

On the recommended path, customer-held keys mean the agent still verifies locally. That is the product claim to keep honest.

Is MCP required?

No. REST execution-intent is the public standard. MCP is an optional sidecar for some operators.

When can we name a design partner?

When live attestation exists. Until then, do not invent logos or production volume.