The governed-AI operating layer for MSPs

AI is exposing the security gaps that were always there.

So turn the AI risk you find into a governed service your clients actually value.

TrueRock finds the AI risk across every client, governs every AI they use, and proves it with evidence — all on the Microsoft 365 they already own.

TrueRock.AI is a multi-tenant Microsoft 365 security and AI-governance platform for Managed Service Providers (MSPs), built by TrueRock AI LLC in Redmond, Washington.

Every Microsoft 365 planMulti-tenantGrounded & cited

Read the narration
  1. Before AI is safe in a client's tenant, there are four jobs. Assess. Secure. Label. Govern.
  2. Here is one Northwind client, Prism Healthcare. 250 users, assessed end to end.
  3. Conditional Access has 2 gaps, and 22 of 84 devices are out of compliance.
  4. First, who can already reach the data. 7 SharePoint sites are open to everyone.
  5. Only 12.9 percent of files carry a label. And a label is what the AI reads before it answers.
  6. 19 agents run in this tenant. 10 hold tenant-wide write access, and 3 have no enabled owner.
  7. At the top, EHR Files Sync. Its only owner is disabled, and it can write every file in the tenant.
  8. TrueRock writes the runbook to fix it. A dry run first, and then a technician approves it.
  9. Their people still get the AI they want, grounded in their own files, with sensitive details removed first.
  10. When Claude or ChatGPT connects, every call goes through the gateway, recorded, and blocked when policy says no.
  11. And every call is metered, per client, against a quota the MSP sets.
  12. The risk you find becomes the service you run. 250 users to govern here, 675 across the book.
What it is

Not a readiness check. A governed-AI operating layer.

Two products, one engine. TrueRock OutCrop is what your team uses to find and prove the risk across every client. TrueRock Managed AI is what your clients' people use — governed AI you switch on per client, and meter.

Why “OutCrop”

In geology, an outcrop is where the bedrock breaks the surface — the one place you can see what the ground is really made of. TrueRock OutCrop does that for every client you manage. It brings what's hidden inside each Microsoft 365 tenant to the surface — overshared files, shadow AI, over-privileged agents, missing Conditional Access, configuration drift — ranked across your whole book, with the evidence behind every finding and the runbook to fix it.

OutCrop · msp.truerock.ai

TrueRock OutCrop

// every client's risk, brought to the surface

  • Portfolio ranked by risk, every client
  • Shadow AI + agents, scored by blast radius
  • Data protection on any M365 tier
  • Compliance mapped to the frameworks, cited
Managed AI · chat.truerock.ai

The governed assistant

// grounded, cited, redacted

  • Reasons over the client's own OneDrive & SharePoint
  • Every claim cited to the file
  • Secrets redacted before the model sees them
  • Right-cost model picked per question
Managed AI · gateway & meter

The gateway and meter

// governed AI calls, metered per client

  • Priced per client — every employee covered
  • Copilot, Claude and OpenAI calls through TrueRock metered
  • Per-client quota, metered on real usage
  • Governs the agents clients built themselves
OutCrop finds and proves the risk. Managed AI puts governed AI in your clients' hands — priced per client, every employee covered, and metered. How pricing works →
Why it matters

Govern every AI. Meter it. Prove it.

What it means for you — and for the clients you protect.

For the MSP
The trust you earned just became a product.

AI is the newest workload on the estate you already run. TrueRock governs it under your existing practice and turns it into a recurring service — metered to real usage, priced for the governance you provide — across your whole book, on the tier clients own, with evidence they sign off on.

For clients
Use AI without giving away the store.

The AI your team already reaches for — Copilot, Claude, agents — stays governed, not blocked. Your sensitive data stays yours: protected on the plan you already have, never fed to a model that shouldn't see it. And you get proof — a cited record you can hand your own board or auditor. Your trusted partner delivers it, not a black box.

See it work

Every capability, with the demo that proves it.

Pick a product; watch the film — every demo cited to what it shows.

Featured
Daily driver
Know what changed — and ask anything, with every answer cited.
Skills
Build your own grounded report generators.
Portfolio
Every client, one cockpit — that reasons.
Reports
Client-ready reports that reason — not just tabulate.
Onboarding
Connect your book in minutes.
Why TrueRock

Insights down to bedrock, not a checkbox-tick.

A one-time readiness check is a snapshot — stale the day it ships. TrueRock is built to reason deeper, prove every finding, and keep measuring across your whole book.

01

Depth, not a snapshot

Reasons over a client's real environment — the connections and exposures a flat checklist never sees.

02

Grounded, not guessed

Every finding traces to its evidence. "The model said so" doesn't survive a client review. Provenance does.

03

Continuous, not one-time

The same intelligence never stops — the first assessment through every day you manage the tenant.

04

Built in, not bolted on

The AI reasoning is native to every surface and every client — not a chatbot bolted onto a legacy dashboard. Multi-tenant from day one, so it spans your whole book with clean, GDAP-secured isolation.

On the Microsoft 365 they already own.

Help every client get the most out of the Microsoft 365 they own. On Business Basic through E3, TrueRock adds data classification, AI prompt protection, shadow-AI discovery and compliance evidence across your whole book. Where a client has E5, Copilot or Agent 365, TrueRock amplifies those richer signals into governance you can act on across every client.

✓ Business Basic
✓ Business Standard
✓ Business Premium
✓ E3 — and richer where signals exist
✓ E5, plus Copilot and Agent 365: amplified

Every capability answers twice — Without TrueRock, With TrueRock, on any SKU.

See the capabilities in detail 23 capabilities

Your Microsoft 365 plan = what the client’s plan provides today, including what E5 adds on a single tenant · Plus TrueRock = what TrueRock adds on every plan, across every client.

OutCrop 16 See and score every AI, agent and exposure touching the tenant, close the gaps, and evidence it against the frameworks — cross-tenant and cited. Where a client has E5, TrueRock builds on it; on every plan, it brings these capabilities across your whole book.
Capability Your Microsoft 365 planthe Microsoft SKU, natively Plus TrueRockon any SKU · cross-tenant
Shadow AI + agent governance Find and risk-score every AI app, browser extension and autonomous agent touching the tenant — including the Copilot Studio and Power Automate agents clients build themselves. Basic–E3: not part of Microsoft 365 today. E5 adds Defender for Cloud Apps discovery — but single-tenant, and it doesn’t see the agents built inside Power Platform. Basic → E5Enumerates and risk-scores every AI app and agent across your whole book, on any SKU. Where a client has E5, it folds Defender’s discovery in — and rolls it all into one cross-tenant AI Watch report.
AI Watch — Governed AI Safety Report One per-client report of every AI touching the tenant — the governed lane in full, Microsoft Copilot via the audit log, and shadow-AI traffic on every managed device — with the right label applied so the AIs you can’t watch still can’t read what they shouldn’t. Not part of Microsoft 365 today below E5. E5 gives a Copilot / Purview audit trail — one tenant, one product, not a safety report. Basic → E5Unifies the governed lane, Copilot and shadow AI into one Safety Report per client. Where E5’s Copilot/Purview audit exists, it folds that signal into the same cross-tenant report — honest about what’s off-device.
Find sensitive data (classification) Automatically read the content of files and mail and classify what’s sensitive — PHI, PII, financials, contracts — without anyone labeling it first. Basic–E3: no automatic classification at all (manual labels only). E5 adds auto-label policies + trainable classifiers — deeper, but single-tenant. Basic → E5Reads the content itself and classifies it on any SKU, cross-tenant — the “gold” nobody labeled, surfaced on Business Premium. Where E5’s labels exist, it reads them into the portfolio and the AI-readiness score.
Data exposure + blast radius Map who — and what — can reach classified data: the people, apps and agents that can read, write or exfiltrate it, and the reach an attacker inherits. Basic–E3: not part of Microsoft 365 today. E5 / SharePoint-Advanced adds access-governance reports — single-tenant, and blind to third-party app scopes. Basic → E5Shows who and what can reach classified data across every tenant, then reasons across scope, owner and sensitivity to name the single highest-risk key to revoke first. Unifies E5’s access-governance signals cross-tenant.
Remediate exposure Close the leak: revoke risky external shares, apply the exact protecting label, and stand up DLP on the data types actually found. Manual share-revoke on any tier. E5 adds auto-labeling policies + inline DLP — single-tenant, and only once someone configures it. Basic → E5Detect and one-click revoke on any SKU; name the exact Purview label the item needs and ship it as a runbook you approve, from Business Premium up. Drives E5’s DLP + auto-label across every tenant from one console.
Conditional Access enforcement Verify the sign-in policies that keep accounts safe — MFA, device trust, blocking legacy auth — actually cover every user. Only from Business Premium up (Entra P1); Basic/Standard can’t enforce it at all. E5 adds risk-based CA (Entra P2). Business Premium → E5Coverage-gap analysis per tenant, license-aware — names the failing baselines and the users a lesser SKU leaves excluded, and honestly flags the gap on the tiers that can’t enforce it. Reads P2 risk signals into cross-tenant coverage.
Device compliance (Intune / Defender) Confirm every managed device is encrypted, patched and antivirus-healthy — with a ranked queue of what to fix first. Only from Business Premium up (Intune); not part of Microsoft 365 today on Basic/Standard. E5 adds Defender for Endpoint EDR — deeper, single-tenant. Business Premium → E5Cross-tenant compliance across Defender + Intune, plus a remediation queue ranked by how many endpoints each fix clears. Reads Defender EDR signals into that view.
Compliance mapping + client-ready reports Map a client’s real configuration to the controls that matter across CIS for Microsoft 365, HIPAA, NIST CSF, ISO 27001 and Essential Eight, and produce the branded, cited evidence pack. Compliance splits into what a machine can prove and what people must attest — this is the first part, delivered whole: every control counted against the framework’s total and traceable to the signal behind it. Basic/Std: not part of Microsoft 365 today. Business Premium+: a Compliance Manager score for one tenant. E5: fuller controls — still single-tenant. Basic → E5Turns real config into framework mappings and MSP-branded, cited DOCX + PDF per client — every claim traceable to a control, and every control still needing human attestation named as scoped work rather than quietly scored. Pulls E5’s compliance signals into that report across the book.
Assess — AI readiness + threat intel Score whether each tenant can safely turn AI on — six dimensions from labeling to oversharing to DLP-for-AI — and surface the CVEs that actually threaten each client, ranked by real exploitability. Basic–E3: not part of Microsoft 365 today. E5 adds Defender vulnerability management on the threat side — deeper, single-tenant, and it doesn’t score AI-readiness. Basic → E5An AI-readiness score per tenant plus per-client CVE ranking — KEV and vendor-surface, not raw CVSS — across the whole book. Reads Defender’s vuln signals into that ranking and the readiness score.
AI-governance maturity + next best step Place each client on the journey from ad-hoc AI use to a governed AI estate — Land, Ground, Automate, Connect — and name the one thing to fix next to move up a level. Basic/Std: not part of Microsoft 365 today. Business Premium+: a Compliance Manager score for controls on one tenant — not a staged AI-governance journey, and no next best step. E5: fuller controls, same single tenant. Basic → E5A gated four-stage maturity level per tenant, computed from that tenant’s own posture — a later stage never counts until the foundation clears — plus the next best areas to improve, each with the real number and the concrete fix, as a client-ready report.
Licensing advisor + daily change tracking Read every tenant’s licensing to reclaim waste, close security gaps, right-size seats and drive adoption — and track what changed each day — as advice, not an upsell. A raw license list on every tier, and nothing more — no advice, no daily diff. No Microsoft SKU ships this, E5 included. Basic → E5Reclaim / secure / right-size / drive-usage per tenant, costed against compliance, plus daily change tracking across the whole book — the license as a lever to protect the client, not a blanket upsell.TrueRock is the ceiling — no SKU ships this
Automate — Skills Author a cited report once and run it the same way on every client — the MSP writes the generator, every technician runs it identically. Nothing — no MSP-authored, RBAC-aware report automation exists in any Microsoft SKU. Basic → E5Author once, run everywhere: cited, RBAC-aware report generators that any technician can run, fork and edit as templates — the same report, the same way, on every client.TrueRock is the ceiling — no SKU ships this
Onboard the whole book in one consent One GDAP-native admin consent registers every client you manage, you pick a pilot tenant, and a plan quota caps spend before the first scan runs. GDAP is Microsoft’s own and you already have it — we add nothing to the mechanism. What no SKU gives is one consent that turns your delegated access into a working cross-client console, with a spend cap on it. Basic → E5One admin consent covers the whole book, not one tenant at a time. Pick a pilot client, run it, and a plan quota bounds the cost before it starts — honest about what is scanned and what is not.
First-Look assessment for a prospect Run a read-only assessment of a prospect’s Microsoft 365 under the access they grant, and hand them a result that says what was examined, what was not, and why — with no overall score invented from partial evidence. No Microsoft 365 SKU produces a prospect-facing assessment: the admin center scores a tenant you already administer, for its own owner. There is nothing to hand someone who is not yet a client. Basic → E5A read-only first look that names every surface it read AND every surface it could not, with the reason — a license it lacks, an API that does not expose it, or a permission not granted. Findings carry the object and the endpoint they came from, and where the evidence runs out it says so instead of scoring anyway.TrueRock is the ceiling — no SKU ships this
Findings into your PSA, as tickets Turn findings into tickets in the PSA your service desk already lives in — ConnectWise, Autotask or HaloPSA — routed to the right board by severity and control, without anyone re-typing them. Nothing. No Microsoft 365 SKU writes a ticket into an MSP’s PSA — the admin center is where a finding stops. Basic → E5Routing rules you author (severity plus control) pick the board and queue, and the same finding is never dispatched twice. A failure is recorded and retried rather than dropped. The dispatch path is proven end to end on our side against a test adapter; pointing it at your live ConnectWise, Autotask or HaloPSA takes your own PSA credentials.TrueRock is the ceiling — no SKU ships this
Portfolio cockpit — every client, ranked The whole book on one screen: every tenant ranked worst-first by risk, and every metric opening onto the client most affecting it and the root cause they share. Every tier gives an admin centre and a score for one tenant at a time. No Microsoft 365 SKU ranks your clients against each other, and none explains why a number moved. Basic → E5Every tenant ranked by risk in one view, filterable by risk band and security domain, each metric drilling to the finding and the tenant behind it — and a synthesis of the correlation and the shared root cause, not just the number.
Governed assistant 4 A governed lane over Copilot, Claude and OpenAI — grounded in the tenant’s own documents, cited to the file, and contained. On every Microsoft 365 plan your clients run.
Capability Your Microsoft 365 planthe Microsoft SKU, natively Plus TrueRockon any SKU · cross-tenant
Governed Managed AI A sanctioned workspace over Copilot, Claude and OpenAI: every prompt scrubbed of secrets, quota-checked and metered, each question routed to the right-cost model, with a content gate that redacts sensitive data before it ever reaches a model. A governed multi-AI lane is not part of Microsoft 365 today, on any SKU. Copilot governs Copilot only. Basic → E5TrueRock’s governed lane over Copilot, Claude and OpenAI — sanctioned, metered and cost-controlled per client, and delivered as a governed managed service you’re paid to run, on any Microsoft 365 tier a client already runs. A persistent protective label on the source file, so the protection travels with it, needs Business Premium.TrueRock is the ceiling — no SKU ships this
Content gate on every prompt Classify what a prompt and its grounding documents carry on the way in, and block or redact unlabeled PHI, PII and card data before it ever reaches a model — then name the label that would protect the source file. On Basic–E3, prompt inspection is not part of Microsoft 365 today. E5’s Purview controls reach Microsoft Copilot on that one tenant — and only Copilot; the other assistants a team actually uses sit outside them. Basic → E5Inspects every prompt and grounding document before any model sees it — Copilot, Claude, OpenAI or an agent your client built — and blocks or redacts on your policy: one MSP baseline, per-tenant overrides, across the book. A protective label on the source file itself needs Business Premium.
Their own AI client, your policy Let a technician work in the assistant they already use — proven today with Claude, and open to any client that can authenticate to the connector — reaching one client’s data through a connector you sanction, with your policy applied on the way in and on the way out, and every call in an audit trail. Copilot’s controls cover Copilot on each tenant; the other assistants a team uses need their own governance, and an MSP needs one policy across clients. Basic → E5One connector you sanction, governed by a policy you author: an MSP baseline with per-tenant overrides, a floor the tenant cannot weaken, and a refusal that names the rule it applied. Every decision recorded — including the ones it could not make.TrueRock is the ceiling — no SKU ships this
Per-person answers, not a shared index Two people ask the governed assistant the same question about the same client and get different answers, because each person’s retrieval runs on their own delegated access — auditable one user at a time. Microsoft 365 Copilot already honors each user’s permissions on the tenant it runs in — that is its design, and we do not claim otherwise. What no SKU gives is the same guarantee on the OTHER assistants a team uses, or one place to prove it across your whole book. Basic → E5Retrieval built with each person’s own delegated token, so a document they cannot open is never read, never summarized and never indexed for them — not filtered out after the fact. On the Microsoft 365 the client already pays for.
Gateway & meter 3 Meter every AI call, route each question to the right-cost model, and account for every client’s own usage — cost control a flat per-seat license cannot give.
Capability Your Microsoft 365 planthe Microsoft SKU, natively Plus TrueRockon any SKU · cross-tenant
AI cost control — right model per question Send simple questions to a lighter model and hard reasoning to the powerful one — control AI cost per client without giving up quality, and show the credits saved. No Microsoft 365 SKU routes by complexity or shows AI savings — Copilot is a flat per-seat license, one price whatever you ask. Basic → E5Picks the right-cost model per tenant, re-runs a low-confidence answer on the powerful one, and shows the credits saved per client — cost control a flat license can’t give, on any Microsoft 365 tier a client already runs.TrueRock is the ceiling — no SKU ships this
Ask TrueRock — grounded, cited answers A security-analyst chat across every client’s real Microsoft 365 that reasons across clients — every claim cited to the record it came from. Not part of Microsoft 365 today, on any SKU — Copilot is per-tenant and per-seat, not a multi-tenant analyst. Basic → E5Cited answers across every client’s real Microsoft 365 at once — it connects records across two or more clients to surface the systemic pattern, not just answer for one tenant.TrueRock is the ceiling — no SKU ships this
AI spend limits + client chargeback Cap what each client can spend on AI before they spend it, meter every token back to the tenant that caused it, and account for it per client, priced to the usage you actually meter. No Microsoft 365 SKU meters AI per client for an MSP — Copilot is a flat per-seat license billed to the tenant, with no limit to set and no margin line. Basic → E5Per-tenant token limits with soft-warn and hard-block thresholds and a reset cadence you choose, plus a monthly statement per client — raw cost, your margin, the line the client sees — so AI is a managed service you can price, not an open tab.TrueRock is the ceiling — no SKU ships this

See how TrueRock is priced →

Start with one client

Your clients are adopting AI. Make governing it your next service.

It starts with a single tenant. Connect one client and TrueRock returns a board-ready, fully cited map of their AI risk — the shadow AI, the exposed data, the readiness gaps — every finding traced to where it lives, and honest about what it hasn't yet seen. That first read is the conversation that becomes a priced engagement.

Rather ask a question first? .