
procurement
MSP audit workshop checklist (about 90 minutes)
A procurement and GRC agenda to reproduce script-governance evidence in trial without inventing certifications.
- Reproduce steps in trial
- Export audit evidence
- Attach to GRC binder
Updated 2026-08-26
A procurement and GRC agenda to reproduce script-governance evidence in trial without inventing certifications.
Visual anchor before the full guide below.

procurement
A procurement and GRC agenda to reproduce script-governance evidence in trial without inventing certifications.
Use this workshop when security, sales, and GRC need a shared packet before an enterprise or government-adjacent renewal. Time-box to about ninety minutes. Output is a dated diligence folder, not a slide that claims SOC 2.
0-10 min: Honesty charter. Read the trust hub wording. State out loud: not Type I or Type II certified; no observation period claimed; no Essential Eight product certification; not insurance approved.
10-25 min: Isolation demo. Two tenant contexts or header mismatch 403. Schema-per-tenant diagram plus one failed cross-tenant call.
25-45 min: Signed dispatch. RequireSigned on. Unsigned attempt denied. Signed script runs on one agent. Capture stdout/exit in the queue.
45-65 min: Export. Audit JSON/CSV. Assessor ZIP. Screenshot Security Center fields. Do not invent missing annexes.
65-80 min: Questionnaire mapping. Open SIG Lite / pre-fill. Leave Gap rows as Gap. Mark vendor SSO/billing/SMTP deferred unless LabVerified.
80-90 min: Owners. Who stores the ZIP, who updates the binder quarterly, who emails security@ for Manual DPA/pentest.
Starter pack index (public PDF), gated grant downloads if a lead was captured, trial exports, this agenda with attendees, and a one-page “what we do not claim†sheet copied from the trust hub.
Do not screenshot a competitor’s badge. Do not paste LabVerified for sandboxes you do not have. Do not promise named case studies if legal has not cleared them (WO-001 partner attestation may still be blocked).
Re-export if the trial was reset. Confirm grant tokens expired (they should). File Manual requests only if the customer’s paper actually requires DPA or pentest summary.
Repeat when Shipped/Gap tables change or when you onboard a new regulated client. Workshops go stale faster than product releases.
If someone asks to “select all 100k agents†in a dropdown, stop the demo and show catalog pagination. That failure mode is how diligence dies in production.
Roles: facilitator keeps claims honest, security engineer drives the portal, GRC writes the limitations appendix, account lead maps the packet to the incumbent RMM. Five-day follow-up: re-export if the trial reset, confirm grant tokens expired, file Manual DPA only if the paper actually requires it.
Date the diligence folder YYYY-MM-DD and record the portal product version. Re-export after upgrades. Do not reuse last week's grant token. Public starter PDFs copy without email. Gated files need a live grant. If the Platform API is down, HubSpot may still capture the lead with no download buttons. Say that out loud so GRC does not think the trial is broken.
Walk one denied unsigned dispatch when RequireSigned is on. Capture a 403 from a mismatched tenant header. Export audit for one window and confirm no foreign tenant codes. Open the Assessor ZIP trust-artifacts.json and read the limitations appendix. Leave Gap rows as Gap. Do not paste LabVerified for Entra, Okta, Stripe, or SMTP until the capability verification registry says LabVerified.
Keep the incumbent RMM. Trustholm does not replace OS patching, remote takeover, or a NOC hero pitch. Probe and observe features are operator tools, not the reason a council or insurer should buy. Named design-partner logos stay off marketing pages until attestation exists.
Store ZIP files with access control. They hold tenant metadata even when secrets are stripped. Email security@trustholm.com only for Manual DPA or pentest summary. Do not invent those PDFs on www.
If someone asks to select all agents in a dropdown, stop and show catalog pagination. If someone asks for a second region or a single global edge FQDN, say Phase 1 Australia edge is current and global discovery is deferred.
Copy the trust hub sentence into the packet: we do not hold SOC 2 Type I or Type II and do not claim an observation period. Trustholm supplies technical artifacts for the customer's program. It does not automate customer SOC 2 Trust Services Criteria like a GRC product.
Assign an owner to refresh this packet quarterly or after a Shipped/Gap change. Workshops go stale. Prefer live reproduction over architecture slides. Prefer export files over screenshots alone, then keep both.
Roles: facilitator keeps claims honest, security engineer drives the portal, GRC writes the limitations appendix, account lead maps the packet to the incumbent RMM. Five-day follow-up: re-export if the trial reset, confirm grant tokens expired, file Manual DPA only if the paper actually requires it.
This workshop does not produce a SOC 2 report. It produces reproducible trial evidence for your program.
Security engineering, GRC, and the account owner. Brokers optional. Keep marketing claims out of the room.
Only if RequireSigned is off, which weakens the story. Prefer a live deny.
No. Composite stories exist; named partners may still be blocked. Do not invent logos.
Use waitlist/presales. Do not fake a tenant. The workshop can still review public trust pages.