Insurers and brokers increasingly ask how MSPs control remote PowerShell, who approved a change, and whether execution history can be exported. Those questions are about artifacts, not about Trustholm (or any vendor) “getting you approved.†This guide maps questionnaire themes to files you can produce in a Govern trial. It does not claim that any carrier, binder, or wholesaler has certified Trustholm.
What you can attach
Start with objects you can regenerate on demand:
- Security Center screenshot following the screenshot guide in the lead pack.
- Audit export JSON/CSV from the operator portal (tenant-scoped).
- Assessor Package ZIP with honest trust-artifacts.json (no Type II claim).
- SIG Lite / questionnaire pre-fill as a draft, with Gap rows left as Gap.
Do not attach invented pentest PDFs, bridge letters, or SOC 2 reports. Trustholm does not hold SOC 2 Type I or Type II and does not claim an observation period.
What insurers usually mean by “script controlâ€
Most forms collapse several controls into one cell: signing, approval, least privilege, logging, and tenant isolation. Split them in your response:
- Signing: customer-held keys; the agent verifies locally. Trustholm is not the sole holder of mutate authority on the recommended path.
- Approval: tenant policy before enqueue. Dual custody where you configured it.
- Logging: security audit plane plus execution stdout/exit codes, not only RMM job history.
- Isolation: schema-per-tenant, not a marketing slogan. Reproduce a 403 on JWT/tenant mismatch in trial.
If the form asks “is the RMM your only remote access tool,†answer with coexistence: the incumbent RMM stays; Trustholm gates privileged scripts beside it.
What never to write
Do not write “Trustholm is insurance approved,†“meets cyber insurer controls,†or “reduces premiums.†Premiums, endorsements, and binding are the carrier’s decision. Trustholm supplies technical evidence for your program.
Do not paste LabVerified language for Entra SSO, Stripe, or SMTP until the capability verification registry says LabVerified. CodeComplete is not live-signed-off.
Trial reproduction (sixty minutes)
- Provision or sign in to a Govern trial.
- Publish a signed script (or duplicate a platform example) and run it on one agent.
- Export audit for that window; confirm tenant identifiers only.
- Download Assessor Package; open trust-artifacts.json and the limitations appendix.
- Capture Security Center fields listed in the screenshot guide.
- Store the ZIP and screenshots in your GRC binder with a dated folder name.
Customer-operated remainder
Endpoint hardening (GPO/Intune AllSigned), patch cadence, EDR, backups, and insurance application narrative remain yours. Trustholm does not replace those programs.
Workshop notes for brokers
Bring the starter pack index (public) and the gated questionnaire files (work email). Walk the broker through one denied unsigned dispatch if RequireSigned is on. That demonstration is stronger than a slide claiming coverage.
Maintenance
Re-run the trial export after major platform upgrades. Questionnaire crosswalks drift. Treat this page as a map, not a living certificate.
Field notes (insurer questionnaires)
For brokers, attach only regenerable artifacts: Security Center screenshot, audit export, Assessor ZIP, and SIG Lite with Gap rows intact. Never write insurance approved, premium reduction, or carrier endorsement. If the form asks whether the RMM is the only remote access tool, answer coexistence: incumbent RMM plus Trustholm for privileged signed scripts.
Date the diligence folder YYYY-MM-DD and record the portal product version. Re-export after upgrades. Do not reuse last week's grant token. Public starter PDFs copy without email. Gated files need a live grant. If the Platform API is down, HubSpot may still capture the lead with no download buttons. Say that out loud so GRC does not think the trial is broken.
Walk one denied unsigned dispatch when RequireSigned is on. Capture a 403 from a mismatched tenant header. Export audit for one window and confirm no foreign tenant codes. Open the Assessor ZIP trust-artifacts.json and read the limitations appendix. Leave Gap rows as Gap. Do not paste LabVerified for Entra, Okta, Stripe, or SMTP until the capability verification registry says LabVerified.
Keep the incumbent RMM. Trustholm does not replace OS patching, remote takeover, or a NOC hero pitch. Probe and observe features are operator tools, not the reason a council or insurer should buy. Named design-partner logos stay off marketing pages until attestation exists.
Store ZIP files with access control. They hold tenant metadata even when secrets are stripped. Email security@trustholm.com only for Manual DPA or pentest summary. Do not invent those PDFs on www.
If someone asks to select all agents in a dropdown, stop and show catalog pagination. If someone asks for a second region or a single global edge FQDN, say Phase 1 Australia edge is current and global discovery is deferred.
Copy the trust hub sentence into the packet: we do not hold SOC 2 Type I or Type II and do not claim an observation period. Trustholm supplies technical artifacts for the customer's program. It does not automate customer SOC 2 Trust Services Criteria like a GRC product.
Assign an owner to refresh this packet quarterly or after a Shipped/Gap change. Workshops go stale. Prefer live reproduction over architecture slides. Prefer export files over screenshots alone, then keep both.
For brokers, attach only regenerable artifacts: Security Center screenshot, audit export, Assessor ZIP, and SIG Lite with Gap rows intact. Never write insurance approved, premium reduction, or carrier endorsement. If the form asks whether the RMM is the only remote access tool, answer coexistence: incumbent RMM plus Trustholm for privileged signed scripts.