Agentic MSP Platform

AI L1 that does the fix — not just the triage.

Gated ticket-resolution agents for Halo-based service desks. They run in your cloud, act in your clients' own tenants, and re-check authorisation inside every action — which means you can prove what they are allowed to do.

Talk to us about a pilot
In build — live demos on real systems

Every competitor triages. This one acts — and can show its working.

Three claims, and each one is something we can demonstrate on demand rather than assert on a slide.

It acts

The agents execute real fixes in Microsoft 365 and Entra, and write the audit trail back to the same ticket — deterministically, in platform code, never dependent on the model remembering to log.

It runs in your cloud

Agents, tools and data paths live in your own AWS account and your clients' own tenants. No multi-tenant vendor SaaS holding delegated admin over everyone's Microsoft tenants.

The gate is provable

Authorisation is re-checked inside every action at execution time — verified caller, PSA contact, same client, that client's tenant only — and the deny paths are covered by tests that run on every change.

What actually happens

01

A ticket lands in Halo

From any channel — email, portal, phone, chat. Nothing about how it arrived has to change.

02

An agent diagnoses it against the real systems

Not against a knowledge base. Against live Microsoft 365 and Entra data for that client's own tenant.

03

It executes the gated fix, or escalates with a diagnosis

Either way the ticket carries the full audit trail, written by platform code rather than by the model.

Write actions ship disabled and in dry-run. Turning one on takes an explicit confirmation that states its blast radius — nothing changes state because a model decided it should.

Proof, not promises

Each of these is something that happened, against real systems, on a dated run.

to onboard a client

~1m51s

One command from one config file: tenant, consent, users, PSA join key, verified agent access. Re-runs are idempotent.

to stand up the stack

~75s

Gateway, gated action tools, container runtime, event trigger, claim table and roles — deployed into an AWS account from one config file.

of refusal, demonstrated

Two layers

Asked to look up a colleague's account the agent refused from the tool contract alone; called directly with the same spoofed request, the action independently denied it.

on teardown

Zero residue

A sandbox client was removed completely — cloud resources, PSA records, tenant — and the removal was verified, not assumed.

Where this honestly is

In build, with live demos on real systems. We do not have customers in production — a first design partner would be the first, which is the whole point of a design partnership and is reflected in what it costs. There is no uptime figure, no SLA and no accuracy percentage on this page, because we do not have the operating history to support one and an invented number is worse than none.

Built and delivered personally by Dale Grant — AWS Certified Solutions Architect Professional, SC cleared. The reference delivery is an AI service desk for a UK MSP on HaloPSA.

Looking for a first design partner

A UK MSP running HaloPSA, willing to point real tickets at it. The pilot starts read-only — you audit the diagnoses and watch it refuse things before anything is allowed to change state.

dale@grantedison.com