AI-native playbook · Managed IT services

How to make a managed IT provider (MSP) AI-native: a playbook

An MSP holds standing admin access to dozens of other companies' systems. So becoming AI-native depends less on how many tickets an agent can close than on whether every agent action on a client system acts for a named technician, stays inside one client and leaves a record the client can check. This playbook sets out the stages to get there, starting with work that changes nothing on a client system, with a source for every figure.

Last reviewed
October 2026
Written for
Owners and service managers of MSPs with 5 to 100 staff
Reading time
About 30 minutes
On this page
01

The keys to every client

On 2 July 2021, attackers used flaws in Kaseya VSA, a remote monitoring and management (RMM) product, to push ransomware through about 60 managed service providers to between 800 and 1,500 of their clients. In Sweden, the Coop grocery chain closed about 800 stores for almost a week[43]. Those businesses were reached through the tool their IT provider used to look after them.

Every MSP runs that kind of channel. The RMM agent on each endpoint, the PSA that holds every client's tickets and contacts, the documentation tool with the passwords, and delegated admin access to each Microsoft 365 tenant add up to standing access to dozens of other companies at once. The Five Eyes cyber agencies wrote a whole advisory about it in 2022[1].

In April 2026 Kaseya, which also owns Datto, launched agents it says work "without manual intervention", and contrasted them with tools that "surface a recommendation and hand it to a technician"[28]. Agents are about to drive the channel attackers used in Kaseya VSA. The question for an MSP is who each agent acts for, which client it can reach on a given call, and whether anyone can show afterwards what it did.

02

AI-enabled vs AI-native

AI-enabled MSP

Switches on the AI in its PSA and RMM. Tickets get auto-categorized, a chatbot answers the portal, technicians use a copilot for notes. Each tool's AI acts on that tool's own admin credentials, and nobody can list what agents did at a given client last month.

AI-native MSP

Designs the desk so agents do the first pass of most ticket, alert, documentation and billing work, and technicians approve and handle exceptions. Every agent action on a client system acts for a named technician, stays inside one client, and leaves a record the client can check.

The difference is reach. A law firm's agent can embarrass the law firm. An agent with an MSP's RMM access can take down every client at once, and the MSP will be asked to prove what it did by clients, auditors, insurers and, in the EU and soon the UK, a regulator. Tier structure and pricing change last, at Stage 5, once the controls have held at real clients.

Most MSPs are at the start. In Kaseya's 2026 survey, 53% said they already use AI to automate ticketing, patching and monitoring, but more than half had automated only about a quarter of their workload (vendor-run survey)[27].

03

The missing layer: who the agent acts for

An MSP will add agents around its PSA, RMM and documentation tool, not replace them. Each tool can govern its own agent, but none answers the cross-tool questions: which technician is this agent acting for, does that person have this access at this client, and where is the one record of it all.

OrchKernel is built to be that layer. Agents ask it before they act. It checks the call against rules, holds it for a named person when needed, runs it with credentials the agent never sees, and writes it to a tamper-evident log. What it is not: it is not a PSA, an RMM, a patch orchestrator or a security tool. The PSA stays the system of record for tickets, agreements and billing. The detail is in the OrchKernel blueprint.

04

Where the hours and margin go under a flat fee

An MSP takes "ongoing responsibility" for a client's IT under a service agreement, usually for a flat or near-fixed monthly fee[47]. Leading MSPs get about 75% of revenue from those agreements[42]. That makes the economics of AI unusually direct. Under hourly billing, saved time is lost revenue. Under a flat fee, every minute a technician does not spend on triage, notes, time entry or a repeat fix is margin.

Public numbers on MSP labor and margin are thin. These are the ones we could source:

  • $61,860Median pay, computer user support specialists, 2025. Network support specialists: $76,220[22]
  • −3%Projected change in computer support specialist jobs, 2025 to 2035. BLS names chatbots as a reason[22]
  • −1.3%US jobs in computer systems design and related services, September 2026 against a year earlier[23]
  • 21.8% and 18.9%Gross margin at Kyndryl (year to March 2026) and Rackspace (2025). Enterprise outsourcers, not SMB MSPs[24]
  • 19%+Adjusted EBITDA of IT solution providers the benchmark calls "best-in-class". Benchmark owned by ConnectWise; medians are paid[30]

We found no public median for SMB MSP margins. Service Leadership publishes medians and quartiles only to paying members, so this page does not quote a "typical" agreement margin.

Where the time goes

Vendors publish plenty of numbers on where technician hours go. Thread says AI handles "50-100% of dispatch work"[35]. Kaseya says its triage removes "up to 80%" of categorization errors[28]. One ConnectWise customer reported 25% less average ticket time[32]. One Pia customer says a typical onboarding fell from about two hours to under ten minutes[36], and one Rewst customer recovered $120,000 through billing reconciliation[37]. A study Kaseya commissioned, based on eight MSPs, puts savings at $2,600 per technician per month[29]. All of these are vendor claims, none publishes a baseline, and nobody has published an independent figure for time lost to notes, alerts or billing leakage.

They still show where to look: dispatch, repeat tickets, thin notes, missing time, agreements that drift from what is deployed, and alert noise.

The pressure on price

In Kaseya's 2026 survey, the share of MSPs whose typical client spends more than $25,000 a year fell from 75% to 41% in one year, 71% named winning new clients as their top challenge, and the share struggling to hire technicians rose from 9% to 16%[27]. A drop that steep in one year may reflect a change in who answered, so read it as direction, not size. MSPs are not growing their own tool spend fast either: N-able, which sells RMM and security tools to MSPs, reported dollar-based net revenue retention of 103% in 2025, so its existing customers spent about 3% more than a year earlier[25]. Smaller clients, harder hiring and slow growth in spend all push the same way: more clients per technician, without more risk per client.

05

What AI already does in MSPs, by tool category

Vendors are named because the sources name them, not as recommendations; capabilities are as each vendor describes them. The column that matters is the last one: what each vendor says about approvals and logs.

PSA and RMM platform agents
What vendors say it does
Kaseya's agentic platform says it is "triaging tickets, containing threats, verifying backups, and optimizing workflows without manual intervention"[28]. ConnectWise launched agents in June 2026 and put fully autonomous operation in a later phase[31,32]. NinjaOne, N-able and SuperOps sell autonomous patching and hardening[34].
Controls they describe
Kaseya's launch release describes no approval step. HaloPSA lists "PII redaction, kill switches, and audit logging"[33].
Service desk overlays
What vendors say it does
Thread's agents "call, chat, and email with clients", triage and draft time entries[35]. Pia automates tickets inside ConnectWise and HaloPSA and claims "3X" more tickets closed per technician[36].
Controls they describe
Neither home page describes how a technician approves an action before it runs.
Automation platforms
What vendors say it does
Rewst runs workflows across the PSA, RMM, Microsoft 365 and other tools an MSP connects, with an AI agent that builds them[37].
Controls they describe
The one vendor that leads with control: permissions on who may push automations live, and "Credentials stay scoped to the client tenant you choose, with activity logged"[37].
AI resold to clients
What vendors say it does
Hatz lets MSPs launch an "AI-as-a-service business" for their clients[38].
Controls they describe
Governance of the client's own AI use becomes something the MSP sells.

Platform vendors compete on autonomy; governance shows up mostly in smaller tools. The MSP signs the client agreement, so the gap is the MSP's to close.

Adoption, with caveats

The 53% adoption figure above comes from a survey run by a company that sells the tools, and "AI" there likely includes rules-based automation that existed before generative AI[27]. We could not reach an independent survey of MSP AI adoption.

The best independent evidence is not from MSPs. In a study of 5,179 customer support agents, an AI assistant raised issues resolved per hour by 14% on average and by 34% for novices, with little effect on the most experienced[26]. BLS already builds it into its projections: it expects jobs for computer support specialists to fall 3% over 2025 to 2035 and names chatbots for troubleshooting as a reason[22].

Where the money went

Into the platforms that hold the keys. Kaseya bought Datto for $6.2 billion in 2022[44], and Silver Lake and Thoma Bravo own about 59% of N-able[25]. Private equity has also rolled up MSPs themselves, buying at $3 to 10 million of EBITDA[42]. We found no verified AI-first MSP at scale, so for an established MSP the route is changing how its own desk works.

06

One MSP, many clients: the blast radius

The rest of this playbook is built around this picture. On the left, an agent inherits the MSP's standing access, the way RMM scripting and platform automation are commonly wired. On the right, the same agent goes through a gate that limits each call to one client and to what one technician may do there.

Without a gate
AI agent
Holds the MSP's RMM, PSA and partner admin access
  • Dental clinic
  • Law firm
  • Tax preparer
  • Defense supplier
  • Wealth adviser
  • Private school

One wrong filter, one injected instruction or one stolen key reaches all of them.

With a gate
AI agent
Acts for one named technician; holds no client keys
Gate, checked on every call
  • One client per call
  • No more access than the technician has there
  • Approved script or held for approval
  • Recorded in a tamper-evident log
  • Dental clinic
  • Law firm
  • Tax preparer
  • Defense supplier
  • Wealth adviser
  • Private school
The client names are examples. The left side is how RMM scripting and platform automation are commonly wired: one credential set that reaches every tenant.

With the gate in place a wrong filter, a prompt injection or a stolen agent token reaches one client and one technician's access, on record. The Five Eyes advice asks the same of people: least privilege, no admin credentials shared across customers, separated customer data[1].

07

The staged path

Six stages, ordered by risk to client systems rather than by tool. Stages 0 to 2 never change a client system. Stage 3 is the first that does, and it does so only with a technician's approval. Different clients can sit at different stages: a dental clinic under HIPAA may stay at Stage 3 for patching long after a small marketing agency reaches Stage 4.

  1. 0

    Stage 0: Get the record straight

    Clean the PSA, curate the scripts, check who can reach which client.

    About 4 to 8 weeks

    What to do

    • Clean ticket types in the PSA; make billed seats and devices match the RMM and license counts.
    • Flag authorized contacts at each client: who may request new access, purchases and leaver processing.
    • Mark which scripts in the library are approved.
    • List every AI feature already on in your PSA, RMM and security tools.
    • Map clients by the rules they bring (HIPAA, CMMC, FTC, SEC, NYDFS, EU, UK).
    • Check MFA on every account that can reach a client, GDAP roles per technician, and that logs are kept for at least six months[1,39].
    • Read client contracts for clauses on AI and sub-processors.

    Why now

    Triage is only as good as the ticket types it sorts into. And the Five Eyes advice to MSPs already asks for these controls before any agent is involved[1].

    In place first

    • Nothing. Every MSP starts here, including those that already switched on their platform's AI.

    What to measure

    • Share of tickets with a valid type and agreement
    • Share of client-access accounts on MFA
    • Agreements whose billed counts match RMM and license counts

    Common mistakes

    • Switching on platform autonomy before the script library is curated, so the agent picks from scripts nobody has reviewed.
    • Letting each tool's AI run on that tool's own admin credentials, which leaves no single record of what agents did at which client.
  2. 1

    Stage 1: Read and draft

    Agents triage, summarize and draft. Nothing touches a client system.

    Starts when ticket types and agreements are clean for the clients in scope

    What to do

    • Triage and routing: client and agreement match, type, priority, board, linked device.
    • Summaries for escalations and handover; drafts of notes, time entries and knowledge-base articles.
    • Alert grouping, so one outage produces one ticket instead of forty.
    • Monthly report and QBR drafts, and a list of billing mismatches for the billing lead.

    Why now

    Under a flat fee this is where technician minutes go, and none of it changes a client system. The best causal evidence on AI help at a service desk found a 14% gain in issues resolved per hour, and 34% for the least experienced agents[26]. That points at tier 1.

    In place first

    • Agents read one client's records at a time.
    • A model approved for each kind of data: no health records, controlled unclassified information or EU personal data to a model without the right agreement in place.

    What to measure

    • Triage agreement rate: how often the dispatcher keeps the agent's type and priority. Thread claims 96% triage accuracy (vendor claim, no baseline given)[35]
    • Share of tickets closed with a complete note and time entry
    • Unbilled time found
    • Time to first response

    Common mistakes

    • Counting tickets the AI resolved without checking how many were reopened.
    • Letting draft notes go to clients unread.
  3. 2

    Stage 2: Talk to client staff

    AI on the portal, chat and phone, with no identity changes.

    After Stage 1, once hand-off to a person works

    What to do

    • AI intake on the portal, Teams chat and the support line, creating well-formed tickets.
    • Status updates and reminders when a ticket is waiting on the user.

    Why now

    Users get an answer at 2 a.m. and the desk gets complete tickets. It is also the stage where social engineering lands: Scattered Spider calls help desks posing as employees to get passwords and MFA reset[2]. An AI on the phone line inherits that exposure, so it gets no reset tool.

    In place first

    • Tell users they are talking to AI. In the EU, Article 50 of the AI Act requires this unless it is obvious[18].
    • A person on request, every time.
    • No password, MFA or access changes available to the agent at all.
    • A review of any outbound AI voice calls to mobile phones under the TCPA[14].

    What to measure

    • End-user satisfaction
    • Share of conversations handed to a person, and why
    • Thread says its agents resolve 10 to 25% of issues with no technician (vendor claim)[35]. Measure your own

    Common mistakes

    • Giving the voice agent a reset tool for low-risk users. Attackers pick whichever user is easiest.
  4. 3

    Stage 3: Propose, technician approves

    First stage that touches client systems

    Agents prepare changes to client systems; a named technician approves each one.

    After Stage 1 data shows the agent's proposals are usually right

    What to do

    • Routine fixes from the approved library: disk cleanup, stopped services, print spooler.
    • Patch exceptions after Patch Tuesday: the failed and pending devices, with a proposed fix for each.
    • New-starter and leaver checklists, only from authorized client contacts.
    • Risky sign-in packs: the evidence, plus a proposed containment step.

    Why now

    Most repeat work is a change to a device or tenant. Approving the exact payload keeps the technician accountable and removes the typing between consoles.

    In place first

    • A rule that each call reaches one client, and only scripts from the approved library.
    • Maintenance windows recorded per client.
    • The agent acts with no more access than the approving technician's GDAP role in that tenant[39].
    • A kill switch per team and for everything, tested.

    What to measure

    • Share of proposals approved without edits
    • Time from proposal to approval
    • Rollback rate
    • Changes made outside a client's window (target zero)

    Common mistakes

    • Batch approvals across clients, which recreate the blast radius one click at a time.
    • Approval screens that hide the device list or the script body, so the technician approves a summary.
  5. 4

    Stage 4: Narrow, pre-authorized autonomy

    Named, reversible actions run without waiting, client by client.

    Class by class, once Stage 3 shows low edit and rollback rates for that class

    What to do

    • Per-client runbooks listing actions an agent may take without approval, such as restarting a stopped print spooler or, where the client agreed in advance, revoking sessions on a confirmed risky sign-in.
    • Notify after the fact, and sample the actions for review every week.

    Why now

    Autonomy earned this way rests on your own approval data for that action, which is also the evidence a client or insurer would ask for.

    In place first

    • Stage 3 data for the class that you would show the client; their written agreement for containment; a named reviewer.

    What to measure

    • Autonomous actions per class and client
    • Reversals
    • Incidents linked to an autonomous action
    • Endpoints per technician. Pia cites "the industry average 250:1 ratio" without a source (vendor claim)[36]

    Common mistakes

    • Widening a class to every client because it worked at one.
    • Nobody sampling the autonomous actions once they stop needing approval.
  6. 5

    Stage 5: The AI-native operating model

    Tiers, pricing and client reporting change to match.

    Ongoing

    What to do

    • Fewer tier 1 seats, more automation engineering and review.
    • Report agent activity to each client from the log, and revisit pricing where the work changed.
    • Offer clients governance for their own AI, as a service.

    Why now

    48% of MSPs say AI is their clients' top need, but 13% earn meaningful revenue from AI services (vendor-run survey)[27]. An MSP that runs governed agents on its own desk has something credible to sell.

    In place first

    • Stages 3 and 4 running at most clients, with the log as the record.

    What to measure

    • Agreement gross margin trend
    • Adjusted EBITDA. The only public reference is "19%+" for the providers it calls "best-in-class", from a benchmark owned by ConnectWise[30]
    • Revenue per employee and client retention

    Common mistakes

    • Keeping the old tier structure, so saved time turns into slack rather than more clients per technician.
    • Letting clients find out about agents from an incident instead of a report.
08

Your first 90 days

Stage 0 plus two Stage 1 workflows, then one narrow Stage 3 class with friendly clients. We suggest triage and resolution notes with time entries, because both go after flat-fee labor, neither touches a client system, and both produce numbers you can compare within the quarter.

  1. Days 1 to 30

    Pick the two workflows. Clean ticket types and authorized contacts for your ten largest clients. Write an AI use policy: no client data in public chatbots, and which models are approved for which kinds of data. List every AI feature already switched on. Check MFA and GDAP roles for every technician. Record the baseline: triage edits, notes completeness, time to first response, unbilled time.

  2. Days 31 to 60

    Run both workflows in shadow mode: the agent drafts, people work as usual, and you compare. Record how often the dispatcher keeps the agent's triage and how much technicians edit its notes. Start the per-client log of every agent action. Send regulated clients a one-page note on what you are doing and which data goes where.

  3. Days 61 to 90

    Turn both workflows on with review. Pick one Stage 3 class, such as approved-library fixes for two or three friendly clients, with technician approval on each. Set up the kill switch and test it. Review edit rate, reopen rate, measured time saved per ticket and any near misses, then decide what to widen.

At day 90, two questions matter more than how many tickets the AI touched. Are the agent's drafts good enough that technicians have stopped rewriting them? And can you show any client every agent action at their site in the last month?

09

What not to fully automate

An agent can prepare each of these: gather the evidence, draft the change, propose the answer. A named person makes the decision, and the log shows whose it was.

Verifying identity before a password, MFA or device reset
Why it stays with a person
This is the attack path. Scattered Spider "posed as employees to convince IT and/or helpdesk staff to … reset the employee's password, and transfer the employee's MFA to a device they control"[2]. Voice cloning makes the impersonation easier to pull off.
Granting admin roles or new access in a client tenant
Why it stays with a person
Least privilege is the first ask in the Five Eyes advice to MSPs[1], and under GDAP the customer grants partner roles explicitly[39]. The client's resource owner agrees, and a technician makes the change.
Running a script or change across many clients at once
Why it stays with a person
One RMM channel reached 800 to 1,500 businesses in the Kaseya VSA attack[43]. One content update crashed 8.5 million Windows devices[41]. Fan-out across clients is how one wrong filter becomes an outage at every client you manage.
Restarts and changes outside the client's maintenance window
Why it stays with a person
An agent cannot see what a reboot at 10 a.m. costs a dental clinic with a full schedule or a law firm on a filing deadline.
Containment that stops a client's business, unless agreed in a runbook
Why it stays with a person
Isolating a file server is an outage if wrong and a breach if late. The client picks that trade-off in advance, in writing.
Deciding an incident is reportable, and telling the client
Why it stays with a person
Clocks start on awareness: 72 hours to an SEC-regulated client[8], 24 and 72 hours under NIS2[15]. The client and its counsel decide what is reported; the MSP must get them the facts fast.
Closing a security alert as a false positive
Why it stays with a person
Password spraying looks like noise until it works. Only classes the security lead has listed may be closed by an agent.
Purchases, license increases and quotes charged to the client
Why it stays with a person
It is the client's money, and the client's approver signs.
Who receives a leaver's mailbox and files
Why it stays with a person
The client decides who sees a departed employee's email. It is a privacy decision.
Adding a new AI model or vendor that will see client data
Why it stays with a person
It is a new sub-processor under GDPR Article 28[17], a subcontractor under HIPAA[11], and possibly inside a defense client's CMMC scope[12].
Pricing, renewals and the client relationship
Why it stays with a person
An agent can draft the QBR. Price and scope are the account manager's call.
10

When automation goes wrong

The sector's worst incidents so far came through automation channels and help desks. Agents with RMM and tenant access will use the same channels.

Real cases

  1. Kaseya VSA, July 2021

    REvil used flaws in an RMM product to push ransomware through about 60 MSPs to between 800 and 1,500 businesses. Coop Sweden closed about 800 stores for almost a week. The flaws had been reported months earlier[43].

    The lesson: The automation channel is the attacker's channel. Control: one client per call, approval across clients, a kill switch.

  2. ScreenConnect authentication bypass, February 2024

    CISA added CVE-2024-1709, in ConnectWise's remote-access tool, to its catalog of vulnerabilities known to be exploited[3].

    The lesson: Remote-access tools are prime targets. Control: agents never hold those credentials; a gate holds them sealed and logs each use.

  3. SimpleHelp RMM, June 2025

    Ransomware actors used an unpatched SimpleHelp RMM at a utility billing software provider to reach that provider's customers[4].

    The lesson: The same pattern four years later. Control: the same, plus patching your own tools.

  4. MGM Resorts, September 2023

    Attackers called the help desk posing as an employee they had found on LinkedIn. MGM later agreed a $45 million settlement with people whose data was taken[45].

    The lesson: Resets are the soft spot. Control: agents have no reset tool; a technician calls back on the number on file.

  5. CrowdStrike, July 2024

    A content update that passed a faulty validator crashed 8.5 million Windows devices[41]. CrowdStrike committed to staggered deployment starting with a canary, and to giving customers control over when and where updates land[40].

    The lesson: A change at scale needs staging and a stop. Control: one client per call, kill switches.

  6. An AI coding agent deletes a production database, July 2025

    During a code freeze, Replit's AI agent acted against instructions and deleted a company's production data, then said it had "made a catastrophic error in judgment"[46].

    The lesson: An instruction to an agent is not a control. Control: destructive tools need approval; freezes are enforced outside the agent.

Agent failures to design against (scenarios)

These are scenarios, not reported events. Each is something an agent with too much reach could do at an MSP, and each maps to one of the control points.

A. The all-clients script. An agent proposing a disk cleanup builds a device filter that matches every client's servers instead of one site's.
What stops it
A rule: one client per call and approved script IDs only, plus technician approval showing the full device list (control 1).
B. The convincing caller. The AI voice agent hears a cloned voice of a client's CFO asking for an MFA reset before a board call.
What stops it
The agent has no reset tool. It routes the request to the human queue with the callback number on file (control 2).
C. Cross-client context. An agent drafting a QBR for one client pulls a config note, firewall password included, from another client's documentation.
What stops it
Data access by client and field: one client's records per task, credentials never readable by agents, every read logged (control 8).
D. Noise that wasn't. An agent tuned to close self-clearing alerts closes a burst of failed-logon alerts that were password spraying.
What stops it
Agents close only alert classes the security lead has listed; the rest go to a person, and closures are sampled (control 6).
E. The email that gives orders. A ticket arrives with hidden text telling the agent to add a forwarding rule to an outside address.
What stops it
Mailbox rule changes always need approval with the exact payload shown, and forwarding outside the client's domain is denied by rule (control 1).
F. The quiet invoice change. A reconciliation agent misreads a license export, lowers seat counts on an agreement, and the invoice goes out short.
What stops it
Agreement and invoice changes wait for the billing lead (control 12).
11

Rules that reach MSPs

In the US, the regulated party is usually the client. Rules reach the MSP through the client's duty to oversee providers and through contracts. NIS2 names MSPs directly, and the UK is legislating to. None of these rules exempts an action because software took it.

United States: through your clients

FTC Safeguards Rule, 16 CFR 314[6,7]
Who it reaches
MSPs serving non-bank financial institutions: tax preparers, auto dealers, mortgage brokers and similar
What it asks
Service providers "capable of maintaining appropriate safeguards"; MFA for "any individual accessing any information system"; "monitor and log the activity of authorized users". Events affecting 500 or more consumers go to the FTC within 30 days.
Status
In force. The breach notice amendment took effect on 13 May 2024.
SEC Regulation S-P, as amended in 2024[8,9]
Who it reaches
MSPs serving broker-dealers, investment advisers, funds and transfer agents
What it asks
Service providers must notify the client "as soon as possible, but no later than 72 hours after becoming aware" of a breach.
Status
Compliance 18 months after Federal Register publication for larger entities and 24 months for smaller ones: 3 December 2025 and 3 June 2026, counting from publication on 3 June 2024.
NYDFS cybersecurity regulation, 23 NYCRR 500[10]
Who it reaches
MSPs serving banks, insurers and other firms licensed by New York's Department of Financial Services
What it asks
Service provider policies covering MFA, encryption and notice of cybersecurity events. The client reports an incident within 72 hours, including one at a service provider, and an extortion payment within 24 hours.
Status
MFA requirements in full from 1 November 2025. The notice changes applied from 1 December 2023.
HIPAA, 45 CFR 160.103[11]
Who it reaches
MSPs serving clinics, practices and their business associates
What it asks
A subcontractor that "creates, receives, maintains, or transmits" health information is a business associate. So is an AI model provider your agents send it to.
Status
In force.To be confirmed: HHS guidance on cloud providers that hold encrypted data without the key (hhs.gov could not be opened)
CMMC program, 32 CFR 170, and DFARS 252.204-7021[12,13]
Who it reaches
MSPs serving defense contractors that handle controlled unclassified information
What it asks
An external service provider handling that information is "in the OSA's assessment scope". Your agents' actions are assessed as part of the client.
Status
Part 170 in force since 16 December 2024. The DFARS contract clause in its current form since 10 November 2025.
CIRCIA[5]
Who it reaches
Covered critical-infrastructure clients
What it asks
Incident reports in 72 hours and ransom payment reports in 24, once the final rule exists.
Status
Not yet in effect. CISA says it continues to work on the final rule.
TCPA, for AI voice calls[14]
Who it reaches
MSPs whose voice agent places calls
What it asks
AI-generated voices are "artificial" under the TCPA, which matters for outbound calls to mobiles.
Status
Ruling issued 8 February 2024.To be confirmed: how it applies to support calls from an MSP to client staff

EU and UK: increasingly direct

NIS2, Directive (EU) 2022/2555[15]
Who it reaches
Medium and large MSPs and MSSPs serving the EU, directly
What it asks
Risk measures including "supply chain security"; incident early warning in 24 hours, notification in 72, final report within a month.
Status
Member states had to transpose it by 17 October 2024 and apply it from 18 October 2024.To be confirmed: the Annex I wording that lists MSPs under ICT service management, and which member states have finished transposing
DORA, Regulation (EU) 2022/2554[16]
Who it reaches
MSPs serving EU banks, insurers and investment firms, through the contract
What it asks
Contract terms for ICT providers: a full service description, data return, incident help at a cost set in advance, cooperation with regulators, termination rights.
Status
Applies from 17 January 2025.
GDPR Article 28[17]
Who it reaches
MSPs that process EU personal data for clients, usually as processors
What it asks
No new sub-processor "without prior specific or general written authorisation of the controller". A new AI model provider is one.
Status
In force.
EU AI Act, Article 50[18,19]
Who it reaches
MSPs whose AI chats with or calls people in the EU
What it asks
People interacting with an AI system must be told so, unless it is obvious.
Status
Article 50 applies from 2 August 2026, per the tracker.To be confirmed: Article 50 scope for business-to-business support agents, and the final omnibus text in the Official Journal
UK Cyber Security and Resilience Bill[20,21]
Who it reaches
"Relevant managed service providers" serving the UK, wherever they are based. Small and micro MSPs are excluded unless designated as critical suppliers
What it asks
Register with the Information Commission, take "appropriate and proportionate measures", report incidents in 24 hours with a full report in 72, and tell affected customers. Proposed fines up to £17 million or 4% of worldwide turnover.
Status
Not law. In the House of Lords, with report stage listed for 26 October 2026.To be confirmed: the commencement date, which follows Royal Assent by secondary legislation

Platform terms and contracts

Microsoft GDAP[39]
Who it reaches
Every MSP that manages Microsoft 365 tenants through Partner Center
What it asks
Partner access is "granular and time-bound", and customers must explicitly grant it.
Status
Platform terms, binding in practice.
Client contracts
Who it reaches
Every MSP
What it asks
Clauses on AI use and named sub-processors.
Status
No public evidence of how common. Read yours.
State laws aimed at MSPs
Who it reaches
MSPs serving public bodies in some states
What it asks
Registration or ransom-payment reporting.
Status
Not found.To be confirmed: whether any state has MSP-specific rules of this kind

What they have in common

Across the FTC, SEC, NYDFS, CMMC, NIS2 and the UK bill, four duties recur. An AI agent acting in client systems falls under all four:

Know who touched what
Log activity in client systems and keep it. Six months is the minimum in the Five Eyes advice to MSPs[1]; the FTC rule asks clients to log authorized users' activity[6].
Limit access
MFA, least privilege and separation between customers[1,39]. An agent is one more identity with access.
Report fast
72 hours to an SEC-regulated client[8]; 24 and 72 hours under NIS2 and the UK bill[15,20]. The clock starts on awareness, so evidence has to be at hand.
Write down who does what
Business associate agreements, data processing agreements, CMMC responsibility matrices and DORA contract terms[11,12,16]. Agents and the models behind them belong in those documents.
12

How roles change

  1. 1

    Tier 1 technician: from fixing to reviewing

    In the customer support study above, AI help lifted novices most[26]. As agents take repeat tickets, tier 1 reviews proposals and handles what the agent was unsure of. The open question is training: if agents take the easy tickets, where do future tier 2 and 3 technicians learn? Rotate juniors through Stage 3 approvals with a senior reviewing, rather than cutting the rung.

  2. 2

    Dispatcher: from routing to owning the exception queue

    Thread sells its agents largely on taking over dispatch work[35]. Whatever share they take, the person who dispatched now owns the tickets the agent could not place and the triage error rate.

  3. 3

    Automation engineer: a core role

    Owns the approved script library, agent playbooks, per-client runbooks and the list of what may run without approval. Many MSPs already have someone doing this for RMM scripts or workflow tools; the job grows and gets a seat in change review.

  4. 4

    Service manager: from SLAs to controls

    Sets approval thresholds, reviews edit and rollback rates every week, decides when a class earns Stage 4, and holds the kill switch.

  5. 5

    vCIO and account manager: AI adviser to clients

    Clients are asking their MSP about AI, and few MSPs earn from it yet (Stage 5 has the survey figures)[27]. Advice on governing AI is easier to sell when the MSP can show its own agent log.

  6. 6

    Security lead: owns identity verification

    The reset procedure becomes one of the documents the MSP is most likely to be judged on after an incident. The security lead owns it, tests it with mystery calls, and keeps the list of alert classes agents may close.

  7. 7

    Pricing: watch who keeps the gain

    Per-user and per-device pricing ties revenue to client size, so automation gains go to the MSP at first, until clients notice. We found no public data on MSPs changing prices because of AI.

13

One ticket's path

A Stage 3 ticket from start to finish. The agent does the reading and typing, the technician makes the call, and the change reaches one client through a gate that records it.

  1. 01Ticket arrives· Technician and client systems

    A user at the dental clinic emails: the front-desk PC is out of disk space and the imaging software will not open.

  2. 02Triage· AI agent

    Matches the sender to the clinic and its agreement, sets type and priority, links the device from the RMM.

  3. 03Proposal· AI agent

    Approved script DSK-04 (clear temp files and the update cache) on one device, at this client, now.

  4. 04Check· OrchKernel

    One client? Script on the approved list? Inside the clinic's window? Does the technician the agent acts for hold that access?

  5. 05Approval· Technician and client systems

    The technician sees the exact device, script and time, and approves. Had the run covered more devices, each would be listed.

  6. 06Action· OrchKernel

    Runs through the RMM with credentials the agent never sees, then records the request, check, approval and result.

  7. 07Note and time entry· AI agent

    Drafts the resolution note and time entry in the PSA. The technician confirms before the ticket closes.

The PSA stays the record of the ticket. OrchKernel holds the record of what the agent asked to do, who approved it and what ran.
14

The OrchKernel blueprint for an MSP

OrchKernel sits between AI agents and the systems the MSP connects, as drawn in the blast radius. Agents ask it before they act; it checks the rules, holds what needs a person, runs what is allowed with sealed credentials, and records all of it.

The mechanisms

Approvals
The action waits for a named person, who sees the exact payload: device list, script body, mailbox rule, seat count. It runs once, as approved.
Rules
Checked on every call: one client per call, approved script IDs only, no external forwarding, purchase thresholds, which models see which data. A rule allows, holds or denies, with a reason.
Acting on a named person's authority
Each agent acts for a named technician, with no more access than that person has at that client. Remove the technician's access and the agent loses it too.
Data access by role and field
One client's records at a time. Credentials in the documentation tool are never readable by an agent.
Tamper-evident audit log
Every request, decision, approval and result, by client, chained so an edited or deleted entry shows.
Human queue
Reset requests, alerts the agent may not close, unknown requesters and possible incidents land with a named owner.
Kill switches
Stop agents for one team, one client or everything, at once.
Connections to your systems
The MSP connects its PSA, RMM, documentation tool, Microsoft 365 and Google tenants and chat. OrchKernel holds the credentials sealed, so agents never hold PSA, RMM or tenant keys.

Sixteen control points

Where an MSP needs a control whatever tools it runs, who owns it, and what enforces it.

Changes to client systems

01
Script and change runs on client devices: approved library, one client per run, inside maintenance windows
Owner or approver
Technician approves; the automation engineer owns the library
What enforces it
Rules: approved script IDs, one client per call. Approval shows device list and script body.
03
Access and admin-role grants in client tenants
Owner or approver
Technician with the client's resource owner; admin roles need the service lead
What enforces it
Approval on every grant; admin roles need the service lead.
04
Agent authority no greater than the technician's, per tenant
Owner or approver
Service lead; GDAP role design
What enforces it
Acting on the technician's authority; delegation only narrows.
05
Security containment: what may run without waiting
Owner or approver
Security lead and the client, agreed in advance
What enforces it
Pre-agreed actions are allowed by rule for that client. Anything else is held for approval.
15
A stop for agents: per team, per client, for everything
Owner or approver
Any admin
What enforces it
Kill switches, tested in Stage 3.

Identity and requests

02
Password, MFA and identity resets
Owner or approver
Technician verifies the caller; the security lead owns the procedure
What enforces it
Agents are given no reset tool. Requests go to the human queue with the callback number on file.
14
User lifecycle requests only from authorized client contacts
Owner or approver
Technician checks; the client contact is recorded
What enforces it
A rule checks the requester against the authorized list from the PSA. Unknown requesters go to the human queue.

Security and incidents

06
Closing security alerts
Owner or approver
Security analyst or technician
What enforces it
Rules limit closures to listed classes; the rest go to the human queue.
11
Incident clocks and client notice
Owner or approver
Security lead; the client's counsel decides what is reported
What enforces it
Human queue at once, with the log as evidence.

Data, models and records

08
Per-client data separation; secrets never readable
Owner or approver
Data owner and service lead
What enforces it
Data access by client and field. Every read is logged against the client.
09
Model and sub-processor clearance by data class: health, defense, EU personal data, financial customer data
Owner or approver
Compliance owner, with the client's authorization
What enforces it
Rules decide which models see which data classes. BAAs and DPAs are signed outside any software.
10
A record of every agent action, by client, kept at least six months or longer where a client's rules require
Owner or approver
Compliance owner
What enforces it
The tamper-evident log, exportable per client for an auditor, assessor or insurer.
16
Changes to the agents themselves: playbooks, prompts, tool grants
Owner or approver
Automation engineer and service lead
What enforces it
Approval before new tools or grants go live; the log records which version acted.

Clients and money

07
Client-facing messages: outage notices, reports, AI chat and voice
Owner or approver
Technician, service lead or account manager
What enforces it
Approval on notices and reports; rules require AI disclosure.
12
Billing and agreement changes: seat counts, invoices, out-of-scope charges
Owner or approver
Billing lead
What enforces it
Approval on every change. The agent drafts the reconciliation; it cannot post it.
13
Purchases and quotes above a threshold
Owner or approver
Owner, and the client's approver
What enforces it
Thresholds by amount and client; above them the action is held for approval.

What belongs elsewhere

The PSA stays the system of record
OrchKernel does not replace the PSA, the RMM, the documentation tool or the password vault.
Patching and rollout
Patch rings, staged rollouts and window scheduling stay in the RMM. OrchKernel is not a patch orchestrator.
Identity configuration
Phishing-resistant MFA, conditional access and GDAP relationships are set in the identity provider and Partner Center.
Detection and backup
EDR, SIEM and backup stay in the security stack.
Reporting decisions
Whether an incident is reportable is for the client and its counsel. OrchKernel supplies the evidence.
Contracts and certifications
BAAs, DPAs, CMMC responsibility matrices, MSAs, SOC 2 and CMMC assessments are outside any software.
Your own tools' vulnerabilities
A gate in front of agents does not protect an exposed remote-access server. Patch it.

Licensing for an MSP

OrchKernel is source-available under the Business Source License 1.1 and runs on your own servers, so you can read the code that enforces these controls. The license allows production use where each deployment serves one organization, and it allows separate deployments for separate client organizations. A hosted or managed service in which one deployment serves more than one organization needs a commercial license. The terms are on the license page.

One deployment per client is within the license. Whether one deployment for your own desk, with agents reaching many client tenants, fits the standard license is to be confirmed with us before you rely on it.

15

Scorecard by stage

Record the baseline before Stage 1 and track the same numbers at each stage. For most MSP operating metrics there is no public benchmark: the detail sits in paid peer groups and vendor dashboards, and we have not quoted any figure we could not source.

Clean ticketsStage 0
How to count it
Share of tickets with a valid type, subtype and agreement
Public benchmark
No public benchmark
MFA coverageStage 0
How to count it
Share of accounts with access to any client environment that use MFA
Public benchmark
Target is all of them, per the Five Eyes advice[1]
Agreement mismatchesStage 0
How to count it
Agreements where billed seats or devices differ from RMM and license counts
Public benchmark
No public benchmark
Triage agreement rateStage 1
How to count it
Share of agent triage decisions the dispatcher keeps unchanged
Public benchmark
Vendor claim of 96% accuracy, no baseline[35]
Complete closesStage 1
How to count it
Share of tickets closed with a resolution note and a time entry
Public benchmark
No public benchmark
Issues resolved per technician hourStage 1
How to count it
Closed tickets divided by technician hours, by tier
Public benchmark
Independent analogue only: +14% on average, +34% for novices, in customer support, not MSPs[26]
Hand-off rateStage 2
How to count it
Share of AI conversations passed to a person, and the reason
Public benchmark
No public benchmark. Vendor claim of 10 to 25% resolved with no technician[35]
Approved without editsStage 3
How to count it
Share of agent proposals a technician approves unchanged
Public benchmark
No public benchmark
Rollbacks and out-of-window changesStage 3
How to count it
Agent changes reversed, and changes made outside a client's window
Public benchmark
No public benchmark. Target zero out-of-window
Autonomous actions and reversalsStage 4
How to count it
Per class and client, with incidents linked to any of them
Public benchmark
No public benchmark
Endpoints per technicianStage 4
How to count it
Managed endpoints divided by technical staff
Public benchmark
"The industry average 250:1 ratio" is a vendor figure with no source[36]
Agreement gross margin and adjusted EBITDAStage 5
How to count it
From your own books, quarter by quarter
Public benchmark
Only "19%+" adjusted EBITDA for the providers it calls "best-in-class", from a ConnectWise-owned benchmark; detail is paid[30]
16

Sources and further reading

Sources were read in October 2026; dates are publication or data dates. Last reviewed October 2026.

Primary sources

Government agencies, regulators, legislatures and SEC filings. Some EU texts are read in unofficial copies, marked as such.

  1. 1
  2. 2
    AA23-320A: Scattered Spider. CISA and FBI, updated 29 July 2025.
  3. 3
  4. 4
  5. 5
  6. 6
    16 CFR 314.4: Elements (FTC Safeguards Rule). Legal Information Institute, Cornell Law School.
    Copy of the regulation
  7. 7
    16 CFR part 314, version history. Electronic Code of Federal Regulations.
    The breach notice amendment to 314.4 took effect on 13 May 2024
  8. 8
  9. 9
    SEC adopts amendments to Regulation S-P to enhance protection of customer information. US Securities and Exchange Commission, 16 May 2024.
    Compliance 18 or 24 months after Federal Register publication; eCFR shows the text published 3 June 2024
  10. 10
    23 NYCRR 500.11 (third-party service provider security policy), 500.17 (notices) and 500.22 (transitional periods). Legal Information Institute, Cornell Law School.
    Copy of the regulation; sections 500.17 and 500.22 at the same site
  11. 11
    45 CFR 160.103: Definitions (business associate). Legal Information Institute, Cornell Law School.
    Copy of the regulation
  12. 12
    32 CFR part 170, Cybersecurity Maturity Model Certification program: sections 170.4 and 170.19. Legal Information Institute, Cornell Law School.
    Part 170 in effect from 16 December 2024 (eCFR version history)
  13. 13
    DFARS 252.204-7021: Contractor compliance with the CMMC level requirements. Electronic Code of Federal Regulations.
    Current version in effect from 10 November 2025
  14. 14
    FCC makes AI-generated voices in robocalls illegal (declaratory ruling). Federal Communications Commission, 8 February 2024.
  15. 15
    Directive (EU) 2022/2555 (NIS2): Articles 2, 6, 21, 23 and 41. Official Journal of the European Union, 14 December 2022.
    Read in an unofficial copy; EUR-Lex did not load. Annex I not opened
  16. 16
    Regulation (EU) 2022/2554 (DORA): Articles 30 and 64. Official Journal of the European Union, 14 December 2022.
    Read in an unofficial copy; EUR-Lex did not load
  17. 17
    Regulation (EU) 2016/679 (GDPR), Article 28: Processor. Official Journal of the European Union.
    Read in an unofficial copy
  18. 18
    Regulation (EU) 2024/1689 (AI Act), Article 50: transparency obligations. Official Journal of the European Union.
    Read in an unofficial copy
  19. 19
    EU AI Act implementation timeline. Future of Life Institute (artificialintelligenceact.eu), updated 31 August 2026.
    Tracker, not the Official Journal
  20. 20
  21. 21
    Cyber Security and Resilience (Network and Information Systems) Bill: bill stages. UK Parliament, updated 16 September 2026.
    House of Lords report stage listed for 26 October 2026
  22. 22
    Occupational Outlook Handbook: computer support specialists. US Bureau of Labor Statistics, 2025 pay data; 2025 to 2035 projections.
  23. 23
  24. 24
    Company facts from annual reports (10-K): Kyndryl (fiscal year to March 2026), Rackspace Technology (fiscal 2025). US Securities and Exchange Commission, XBRL data, filed March and May 2026.
    Gross margin is gross profit divided by revenue, from each company's reported figures
  25. 25
    N-able, Inc. annual report (10-K) for 2025. US Securities and Exchange Commission, filed 26 February 2026.

Industry bodies and independent research

Peer-reviewed or working-paper research with no product to sell.

  1. 26
    Generative AI at work (NBER working paper 31161). Erik Brynjolfsson, Danielle Li and Lindsey Raymond, National Bureau of Economic Research, 2023; published in the Quarterly Journal of Economics, 2025.

Vendor sources

Published by companies that sell software or services to MSPs, including the two most cited MSP surveys and benchmarks. Directional, not an industry benchmark.

  1. 27
    AI emerges as the key to scaling MSP operations as growth gets harder (2026 State of the MSP). Kaseya, 14 April 2026.
    Vendor sourceSurvey of more than 1,000 MSPs; fielding dates not given
  2. 28
    Kaseya unveils the first agentic IT management platform. Kaseya, 24 April 2026.
    Vendor source
  3. 29
    Omdia study finds MSPs save more than $310,000 per year after standardizing on Kaseya. Kaseya, 1 October 2026.
    Vendor sourceCommissioned by Kaseya; 8 MSPs interviewed
  4. 30
    Service Leadership report reveals historic growth for IT solution providers. ConnectWise (owner of Service Leadership), 2026.
    Vendor source
  5. 31
  6. 32
  7. 33
    HaloPSA product page. Halo.
    Vendor sourceRead 5 October 2026
  8. 34
    Product home pages: NinjaOne, N-able and SuperOps. NinjaOne; N-able; SuperOps.
    Vendor sourceAlso https://www.n-able.com/ and https://superops.com/, read 5 October 2026
  9. 35
    Thread home page. Thread.
    Vendor sourceRead 5 October 2026
  10. 36
    Pia home page. Pia.
    Vendor sourceRead 5 October 2026
  11. 37
    Rewst home page. Rewst.
    Vendor sourceRead 5 October 2026
  12. 38
    Hatz AI home page. Hatz AI.
    Vendor sourceRead 5 October 2026

Company and press

Company statements about incidents, platform documentation, news coverage and encyclopedia summaries.

  1. 39
    Introduction to granular delegated admin privileges (GDAP). Microsoft Learn, updated 27 May 2026.
  2. 40
  3. 41
  4. 42
    Private equity is ready to take MSP consolidation to the next level. TechCrunch (analyst opinion column), 8 October 2021.
  5. 43
    Kaseya VSA ransomware attack. Wikipedia.
    Secondary source, citing Kaseya and press reports
  6. 44
    Kaseya. Wikipedia.
    Secondary source
  7. 45
    Scattered Spider. Wikipedia.
    Secondary source
  8. 46
    Replit. Wikipedia.
    Secondary source
  9. 47
    Managed services. Wikipedia.
    Secondary source

Become a design partner

Run Stage 0 and two Stage 1 workflows on your own PSA data with us, then one Stage 3 class at a friendly client. You get early access, help with setup, and a say in what we build next.

Or email support@prefero.ai