ECZ-ID for MSPs & MSSPs
Know which AI can act for which customer.
Prove the authority behind it.
Map machine actors across your client estate, bind them to customer authority, preserve the evidence, and give every client a current state they can independently re-check.
AI is moving beyond assistance. Agents are beginning to interact with service desks, RMM and PSA platforms, security systems, cloud infrastructure, APIs and customer data — and increasingly they can take action. For an MSP, that creates an accountability question no single system in your stack was built to answer on its own:
- Which machines can act?
- For which customers?
- Who operates them?
- Under what authority?
- Through which MCP or API surface?
- What evidence can be independently re-checked?
ECZ-ID adds independently resolvable identity, operator, authority and evidence around managed machine operations.
Free · 3 minutes · No signup required
Designed to work alongside your RMM, PSA, IAM, OAuth and security controls — not replace them.
The multi-tenant problem
One operator. Many customer environments. One accountability chain.
A single MSP identity now stands behind actions taken in dozens — sometimes hundreds — of customer environments. When a machine acts, the accountability chain has to survive three questions at once: which machine, for which customer, under whose authority.
The managed-machine accountability chain. Highlighted links are the records ECZ-ID makes first-class. In many environments, those relationships are distributed across identity, ticketing, contracts, platform permissions and audit systems rather than represented as one independently resolvable trust relationship.
Why now
The authority model behind managed services is changing.
Established model
The customer authorises the MSP. The MSP assigns a named technician. The ticket trail carries the accountability.
Emerging model
The customer still authorises the MSP — but the acting party is now a machine, operating through MCP servers and APIs, often across more than one customer environment, at machine speed. None of this says AI agents are bad for managed services. It says the accountability model has to be rebuilt around them — deliberately, before an incident forces the question.
Complementary by design
Your current stack answers part of the question. ECZ-ID answers the rest.
Those systems remain essential sources of operational truth. What they may not provide on their own is a neutral, independently resolvable view of the complete machine/operator/customer-authority relationship for an external relying party — your customer, their auditor, their insurer. ECZ-ID's contribution is that independent layer: identity, authority and evidence that can be resolved and re-checked from outside your own tooling.
The core distinction
Permission is not proof.
Your IAM proves a credential was allowed to do something. Your logs record that something happened. Neither, on its own, proves the thing your customer actually needs to know: that a specific, identified machine acted for them, under an authority they granted, which is still in force.
Permission
The credential was valid at the time.
Proof
The machine is identified; its operator is accountable; the customer’s authority is recorded; the MCP/API surface is identified; the evidence exists; and the current state — active, suspended, revoked or superseded — can be independently re-checked today.
Free · Self-serve · 3 minutes
Where does machine accountability stand in your operation today?
Seventeen questions, three minutes, no signup. You get structured findings — not a marketing score. Each finding states what was detected, why it matters in a multi-tenant operation, and what to check next. Where the £395 Readiness Audit is genuinely the right next step, we say so. Where it isn't, we say that too.
Runs entirely in your browser — your answers are not transmitted.
Fixed fee · Fixed scope · Asynchronous
The £395 Client-Estate Machine Trust Audit
The fastest way into a real machine trust estate: a structured, evidence-based audit of the machine surface you run for customers — mapped, recorded and delivered as a written report you can put in front of management, customers and insurers.
What the MSP scope examines
- Topology — your MSP entity, customer environments and operating model.
- Agent inventory — the AI agents and consequential automation in scope.
- MCP & API inventory — the surfaces machines use to act.
- Consequential action map — what can be done, per actor, per customer, classified READ / WRITE / HIGH-IMPACT–ADMIN.
- Identity, authority, evidence and revocation findings — where records exist, where assumptions stand in for them.
- Prioritised recommendations — sequenced, vendor-neutral, actionable without any further ECZ-ID purchase.
What it is not
Not a compliance certification. Not a penetration test. Not a sales document disguised as an audit — the recommendations are implementable without any further ECZ-ID purchase, and the report is yours either way.
Checkout runs on the live MCP Readiness Audit engagement (£395, fixed fee — the name you will see at order review). Purchase starts your engagement and written intake; the client-estate machine-trust scope above is agreed with you at intake and populates your machine trust estate as the audit is delivered. Entirely asynchronous: written delivery plus written follow-up Q&A, with other channels available on request. Not a compliance certification.
Beyond the audit
An audit is a snapshot. Machine trust is a state.
Agents change. Models are swapped. Customers are onboarded and offboarded. Authority is granted, narrowed and revoked. Persistent machine trust keeps identity, authority, evidence and freshness as live records — so “which AI can act for which customer, under what authority?” stays a lookup, not a project. When consequential actions occur, bind the native evidence to the relationship — without replacing your RMM, PSA, IAM or security stack — and proving which AI acted becomes answerable exactly where that evidence exists.
The strongest position an MSP can hold in the AI era: our customers can check our machine operations for themselves. With ECZ-ID, each customer can be given an evidence view of their own slice of the machine estate — the actors authorised for them, the authority state, the evidence available and its freshness — scoped to the relationship, independently re-checkable, with no internal telemetry and no other customers’ data exposed.
Every capability on this page is one your customers will eventually need themselves. MSPs that build machine accountability into their own operation first will be positioned to sell it as a recurring service. Talk to us about Managed AI Trust
Built for MSPs operating at the sharp end of managed AI.
MSSP / MDR operators
Machines acting inside customer security stacks — where attribution and authority are least optional.
AI-forward MSPs
Already deploying copilots and agents for customers, and ahead of the accountability question.
RMM-heavy MSPs
Deep automation across many tenants through one console — one credential surface, many customers.
Microsoft & Copilot practices
Copilot, Entra and Azure estates where agentic features are arriving tenant-by-tenant.
Cloud MSPs
Operating customer infrastructure through APIs — where machine action is already the norm.
Regulated-sector MSPs
Serving finance, health, legal and public-sector customers who will ask for proof first.
Action classes
Not all machine actions carry the same weight.
ECZ-ID classifies machine capability into three action classes. The class determines how much identity, authority and evidence the action deserves.
READ
Access to customer systems and data without modification. Ticket queries, monitoring reads, report generation. The baseline class — attribution still matters, because access is still access.
WRITE
Creation or modification of records, configurations and communications. Ticket updates, user changes, configuration edits. The class where “which machine did this, for which customer?” becomes an operational necessity.
HIGH-IMPACT / ADMIN
Administrative, destructive or security-relevant capability. Privilege changes, deletions, security-control modification, financial actions. The class that should never exist without recorded identity, current authority and independently re-checkable evidence.
Questions MSP operators actually ask.
Does ECZ-ID replace our RMM, PSA or IAM?
No. Your RMM, PSA, IAM and security tooling remain the systems of operation, access and telemetry. ECZ-ID adds a layer they don't provide: independently resolvable machine identity, customer authority and evidence. It is designed to work alongside your stack, not replace any of it.
Is this an MCP gateway or an execution control?
No. ECZ-ID does not sit in the execution path and does not allow or block actions. Gateways and policy engines control what happens next; ECZ-ID makes what happened — and who had authority — provable afterwards. The two are complementary.
We already log everything. Why isn't that enough?
Internal logs are necessary and valuable — nothing here says otherwise. They remain essential sources of operational truth. What they may not provide on their own is a neutral, independently resolvable view an external relying party — a customer, insurer or auditor — can re-check without depending on your tooling. That independent layer is what ECZ-ID adds.
We don't run AI agents yet. Is this relevant?
If you run RMM automation, scripts or API integrations across customer environments, you already operate machine actors — agents change the scale, not the category. The Trust Check takes three minutes and will tell you honestly whether this matters for you yet.
What exactly do we get for £395?
A fixed-scope audit: inventory of the machine surface in scope, consequential action mapping, identity/authority/evidence/revocation findings, prioritised recommendations, and a written report with asynchronous follow-up Q&A. Scope is agreed at written intake — state your MSP context there. It is not a compliance certification, and it is yours whether or not you use ECZ-ID afterwards.
Is ECZ-ID a compliance requirement?
No, and we won't pretend it is. No regulation names ECZ-ID, and buying it does not make you compliant with anything. What it does is give you the identity, authority and evidence records that make compliance conversations — and customer and insurer questions — answerable.
How does the customer-facing evidence work?
You choose to give a customer a view of their own slice of the machine estate: the actors authorised for them, the authority state, the evidence available and its freshness. It is scoped to the relationship — no internal telemetry, no other customers' data.
What happens after the audit?
You keep the report and can act on it entirely without us. Where it makes sense, the natural next step is standing machine trust: identity, authority and evidence maintained as live records rather than annual snapshots.
Start with the question your customers will ask anyway.
Which AI can act, for which customer, under whose authority — and can the authority be proved? Three minutes tells you where you stand.
Designed to work alongside your RMM, PSA, IAM, OAuth and security controls — not replace them.