# Home

The MSP Knowledge Base (MSPKB)

## **What It Is:**

The MSPKB is a comprehensive resource designed to provide a clear understanding of MSPs and their businesses. It offers detailed information about MSP roles, services, tools, partnerships, culture, hiring practices, and how they operate. Whether you’re working alongside MSPs, engaging with their ecosystem, or looking to deepen your understanding, the MSPKB breaks it all down in a concise and accessible way.

***

## **Who It's For:**

1. **Businesses Supporting MSPs:**
   * Understand the operational realities, priorities, and goals of MSPs to better align your services and partnerships.
2. **Newcomers to the MSP Ecosystem:**
   * If you’re stepping into a role involving MSPs or are curious about their business models and challenges, this resource provides the foundational knowledge you need.
3. **MSP Community Contributors:**
   * Those involved in real-time chats, forums, user groups, or industry events can use and contribute to the MSPKB to ensure the most accurate and detailed picture of MSPs is available.

***

#### **How It Works:**

The MSPKB functions as a growing lexicon of information about MSPs, shaped by real-world input from the MSP ecosystem. It is not a static archive but a living resource that evolves as MSPs and their businesses grow and change.

**Core Features:**

* **Clarity:** Information is presented in clear, simple terms that avoid jargon and overly technical language.
* **Context:** Each entry connects to the broader ecosystem, showing how MSPs’ services, tools, and practices fit into the industry landscape.
* **Collaboration:** Contributions from those working with or within the MSP space ensure that the information remains accurate, up-to-date, and useful.

**How to Contribute:**

* Click the **"Edit on GitHub"** button on any page to suggest updates, refine details, or expand sections.
* Add knowledge based on your experience, whether that’s about MSP tools, workflows, hiring practices, or historical context.

***

#### **Why It Matters:**

The MSPKB is not a resource for solving MSPs’ problems—it’s a resource for understanding MSPs. It captures the nuances of their businesses, the tools they use, and how they interact within their ecosystem. This knowledge is valuable for anyone working with MSPs or exploring their world.


# Introduction to Managed Service Providers (MSPs)

Start here: what a Managed Service Provider is, which businesses rely on one, and how the MSP model compares to running IT in-house.

New to the MSP model? This section lays the groundwork — defining what Managed Service Providers do, who turns to them and why, and how outsourcing to an MSP differs from building an in-house IT team.

### In this section

{% content-ref url="/pages/I2CT6nZE34x17gjqDmBq" %}
[What are MSPs?](/msp-foundations/introduction-to-managed-service-providers-msps/what-are-msps)
{% endcontent-ref %}

{% content-ref url="/pages/1LrUbIYFIPziAKT7aDJU" %}
[Who Needs MSPs?](/msp-foundations/introduction-to-managed-service-providers-msps/who-needs-msps)
{% endcontent-ref %}

{% content-ref url="/pages/j5WTMmkNUyPEjLWMLbpI" %}
[MSPs vs. In-House IT](/msp-foundations/introduction-to-managed-service-providers-msps/msps-vs.-in-house-it)
{% endcontent-ref %}


# What are MSPs?

MSPs are companies that remotely manage a customer's IT infrastructure and/or end-user systems, typically on a subscription basis. They offer a range of IT services, including network management, security management, IT support, and more, allowing their clients to focus on their core business operations.

#### MSPs typically offer a variety of IT services to cater to their clients' diverse needs. Some common services include:

* **Network Management**: Monitoring, maintaining, and optimizing clients' networks to ensure seamless connectivity and performance.
* **Security Management**: Protecting clients' IT systems and data from security threats through proactive monitoring, threat detection, and incident response.
* **IT Support**: Providing end-user support and troubleshooting for hardware, software, and network issues.
* **Backup and Disaster Recovery**: Implementing data backup and recovery solutions to protect clients' critical information from loss or damage.
* **Cloud Services**: Helping clients manage and optimize their cloud infrastructure, applications, and services.

In addition to the common services mentioned above, MSPs may also offer strategic planning services that can be valuable for small to medium-sized businesses that may not have the resources to hire full-time executives for these roles. Some of these include:

* **vCIO Services**: External IT consultants offering strategic guidance, technology roadmaps, budgeting, vendor management, and compliance/risk management.
* **vCISO Services**: Overseeing information security programs, developing strategies, creating policies, incident response planning, security training, and conducting assessments/audits.

For an overview of the history of the MSP market and more information about MSPs you can view Dave Sobels' video below


# Who Needs MSPs?

## Who Needs MSPs?

Managed Service Providers (MSPs) cater to a diverse range of customers across different industries and organization sizes. Understanding the target market and customer profiles for MSPs is crucial for developing tailored solutions and strategies to meet these needs effectively. This section outlines the target market for MSPs and the next page provides typical customer profiles to help you understand their unique needs.

#### Target Market for MSPs

* Small and medium-sized businesses (SMBs)
* Large enterprises
* Government organizations
* Non-profit organizations
* Education institutions
* Healthcare providers

## Typical Customer Profiles

#### SMBs with limited in-house IT resources:

These businesses often lack the expertise or resources to manage their IT infrastructure and services effectively. MSPs provide them with cost-effective, scalable solutions that enable them to focus on their core business functions.

#### Large enterprises seeking to outsource specific IT functions

For large organizations, MSPs offer the opportunity to outsource specialized IT tasks or departments, allowing the company to allocate resources more efficiently and maintain better control over their IT environment.

#### Organizations with strict compliance requirements

Industries like finance, healthcare, and government organizations face stringent compliance regulations. MSPs can help these organizations navigate complex compliance requirements by providing managed security services and ensuring that IT infrastructure is up-to-date and secure.

#### Businesses undergoing digital transformation or cloud migration

As companies embrace digital transformation and move to the cloud, they often require expert guidance and support. MSPs can offer strategic planning, implementation, and ongoing management services, enabling a smooth transition and ensuring the organization's digital initiatives are successful.


# MSPs vs. In-House IT

There are several reasons why businesses choose to work with MSPs rather than managing their IT solely in-house

**Cost-effectiveness:** Hiring and maintaining a full-time, in-house IT team can be expensive, especially for small and medium-sized businesses. By working with an MSP, businesses can access expert IT services at a lower cost, as MSPs typically charge a predictable, flat-rate fee for their services. This makes it easier for companies to budget and control IT expenses.

**Access to expertise:** MSPs have skilled IT professionals with experience and expertise in various areas, such as network management, cybersecurity, and cloud services. By partnering with an MSP, businesses can access this expertise without the need to hire specialists in-house.

**Scalability:** As businesses grow and their IT needs evolve, MSPs can easily scale their services to accommodate changing requirements. This allows companies to prioritize their business goals while the MSP handles their IT infrastructure.

**24/7 support:** A large portion of MSPs offer round-the-clock monitoring, support, and maintenance of IT systems, ensuring that issues are detected and resolved promptly. This level of support is often difficult to achieve with an in-house team, which may be limited by working hours and staffing constraints.

**Proactive approach:** MSPs proactively monitor and maintain IT systems to prevent issues from occurring in the first place. This approach helps businesses avoid costly downtime and improve overall system performance.

**Access to the latest technology:** MSPs stay up-to-date with the latest technology trends and best practices, ensuring that their clients benefit from the most advanced and secure IT solutions available.

**Compliance and security:** MSPs have experience in managing IT environments that adhere to industry-specific regulations and compliance requirements. They can help businesses maintain compliance and protect sensitive data with robust security measures.

**Focus on core business:** By outsourcing IT management to an MSP, businesses can free up time and resources to focus on their core competencies, enabling them to grow and succeed in their industry.


# Operational Maturity Levels (OMLs) in MSPs

How MSPs measure operational maturity: the five Operational Maturity Levels (OMLs), how maturity relates to size, and what drives growth.

Operational Maturity Levels (OMLs) describe how well-run an MSP is, independent of its size. This section explains the five-level framework, why maturity and headcount are not the same thing, and the practices that move an MSP up the scale.

### In this section

{% content-ref url="/pages/dfO0pAMUZAfXdaL9paCe" %}
[What are OMLs?](/msp-foundations/operational-maturity-levels-omls-in-msps/what-are-omls)
{% endcontent-ref %}

{% content-ref url="/pages/OUAQkvkLu8zwE4RUaRjk" %}
[Size vs. Maturity Level](/msp-foundations/operational-maturity-levels-omls-in-msps/size-vs.-maturity-level)
{% endcontent-ref %}

{% content-ref url="/pages/U3Q20u9XJhpQKGjT0CZi" %}
[Boosting Growth: Best Practices & Tools](/msp-foundations/operational-maturity-levels-omls-in-msps/boosting-growth-best-practices-and-tools)
{% endcontent-ref %}

{% content-ref url="/pages/Ix71PIxa49ulVpK7Ff1b" %}
[Beyond OMLs: Holistic Success Factors for MSPs](/msp-foundations/operational-maturity-levels-omls-in-msps/beyond-omls-holistic-success-factors-for-msps)
{% endcontent-ref %}


# What are OMLs?

The Service Leadership Operational Maturity Framework was designed to help MSPs evaluate and improve their operational efficiency, profitability, and client satisfaction. This framework consists of five levels of operational maturity, each tailored to the specific needs and challenges faced by MSPs at different stages of growth and development. By understanding and implementing the framework, MSPs can optimize their operations and achieve long-term success in the industry.

<details>

<summary><strong>Level 1: Beginning</strong></summary>

At Level 1, MSPs are characterized by low to negative financial performance and inconsistent service quality. Traits that support improvement at this level include:

* Implementing basic time tracking and project management systems
* Developing a basic understanding of pricing strategies and profit levers
* Establishing a foundational level of service delivery and customer support
* Creating a basic process for hiring, onboarding, and terminating employees

</details>

<details>

<summary><strong>Level 2: Emerging</strong></summary>

MSPs at Level 2 exhibit low to negative financial performance and inconsistent service quality but have started to understand the basics of profit levers. Traits that support improvement at this level include:

* Implementing basic controls and operational processes
* Improving pricing strategies and understanding their impact on profitability
* Establishing forward planning and budgeting processes
* Aligning incentive compensation with operational goals

</details>

<details>

<summary><strong>Level 3: Scaling</strong></summary>

Level 3 MSPs typically deliver median financial performance and service quality. Traits that support improvement at this level include:

* Implementing more advanced controls and operational processes
* Refining budget planning and attainment tracking processes
* Ensuring that incentive compensation is directly tied to operational goals
* Streamlining service delivery and enhancing customer support

</details>

<details>

<summary>Level 4: Optimizing</summary>

At Level 4, MSPs demonstrate high financial and service quality performance. Traits that support improvement at this level include:

* Focusing on continuous improvement of operational processes and controls
* Utilizing advanced budgeting and forecasting techniques
* Leveraging incentive compensation plans tied to budget attainment
* Implementing advanced service delivery methods and technologies

</details>

<details>

<summary><strong>Level 5: Innovating</strong></summary>

Level 5 MSPs are the highest performers in terms of financial performance and service quality. Traits that support improvement at this level include:

* Continuously innovating and expanding service offerings
* Developing strategic partnerships with vendors and other industry players
* Fostering a culture of innovation and growth within the organization
* Utilizing advanced data analytics and business intelligence to drive decision-making

</details>


# Size vs. Maturity Level

It is a common misconception that larger MSPs have higher operational maturity levels. However, operational maturity has more to do with efficiency and effectiveness rather than company size. Both small and large MSPs can be found at various operational maturity levels, emphasizing the importance of focusing on operational improvement rather than simply growing the company.

By understanding the traits associated with each operational maturity level, MSPs can develop a roadmap for increasing their operational maturity and improving their overall performance in the industry.


# Boosting Growth: Best Practices & Tools

Smaller MSPs and those with varying operational maturity levels can benefit from adopting industry best practices and leveraging the right tools for their specific needs. Understanding how these practices and tools can organically help MSPs scale their business growth and development without the need for heavy reliance on human resources:

* **Process-driven improvements**: When MSPs adopt best practices and tools that are tailored to their needs, they can naturally improve their operational efficiency and effectiveness, leading to higher OMLs without necessarily following a strict, formalized approach.
* **Tailored tool adoption**: By choosing tools that align with their specific requirements and integrating them effectively, MSPs can streamline their processes and better manage their IT environments, which can contribute to higher OMLs.


# Beyond OMLs: Holistic Success Factors for MSPs

OMLs offer a vital framework for MSPs to measure their financial and operational efficiency, but it is important to acknowledge there's other contributors to a successful MSP business. By also focusing on these additional factors, MSPs create a well-rounded, thriving business that achieves long-term success beyond the financials.

**Collaborative Networking**

* Engaging with industry peers through forums and online peer groups.
* Participating in real-time chat communities to share insights and experiences.
* Building strategic partnerships within the MSP ecosystem to drive mutual growth.

**Digital Presence and Branding**

* Establishing a strong online presence through social media platforms and professional networks, such as LinkedIn.
* Building brand recognition and trust through thought leadership and relevant content.
* Leveraging targeted marketing strategies to reach potential clients and showcase the MSP’s expertise.

**Commitment to Learning and Innovation**

* Staying informed on the latest industry trends, tools, and technologies.
* Investing in employee development through certifications, training, and workshops.
* Encouraging a culture of innovation, embracing change, and continuous improvement


# MSP Business Models & Revenue Generation

The common ways MSPs package and price their services, and the revenue streams that keep the business running.

How does an MSP actually make money? This section breaks down the business models MSPs commonly adopt and the recurring and one-off revenue streams that underpin them.

### In this section

{% content-ref url="/pages/0gbjnT0hcWtviFZOfv0j" %}
[Common Business Models](/msp-foundations/msp-business-models-and-revenue-generation/common-business-models)
{% endcontent-ref %}

{% content-ref url="/pages/eDL6KDGP0NiKzqgUxAxQ" %}
[Revenue Streams](/msp-foundations/msp-business-models-and-revenue-generation/revenue-streams)
{% endcontent-ref %}


# Common Business Models

MSPs typically adopt one or more of the following business models

* **Break/Fix Model:** MSPs provide IT services on an as-needed basis, charging clients for individual services or incidents. This model is less predictable and offers limited recurring revenue. While companies who are living exclusively in this model wouldn’t be classified as a “Managed” Service Provider, many MSPs do still have an element of Break/Fix incorporated into their offering, especially if they are of a lower maturity
* **Subscription Model:** MSPs offer a range of IT services for a fixed monthly fee. This model provides a predictable revenue stream and encourages long-term client relationships.
* **Tiered Service Model:** MSPs offer different levels of service (e.g., basic, premium, enterprise) at varying price points. Clients can choose the level that best meets their needs and budget.
* **Value-based Model:** MSPs charge clients based on the value delivered or the outcomes achieved, rather than the specific services provided. This model aligns the MSP's interests with the client's and encourages long-term collaboration.


# Revenue Streams

A successful MSP business leverages a mix of recurring, one-time, and complementary revenue streams to ensure financial stability and growth. By diversifying their income sources, they can adapt to market changes and capitalize on new opportunities. This section outlines various revenue streams that MSPs incorporate into their business models. For most MSPs, the recurring revenue is their preferred model.

**Recurring Revenue**

* Monthly or annual fees from clients for ongoing IT services, such as network management, security management, and IT support.
* Subscription-based pricing for cloud services, software, and infrastructure management
* Service level agreements (SLAs) that outline the scope of services and associated fees

**One-time Revenue**

* Fees for one-time projects, such as system installations, migrations, or custom software development
* Revenue from consulting services, including IT assessments, strategy development, and technology roadmaps.
* Commissions or referral fees from hardware and software vendors when selling products to clients

**Complementary Revenue Streams**

* Value-added reselling (VAR) opportunities, where MSPs bundle their services with third-party products to offer clients a more comprehensive solution.
* Professional services, such as IT strategy consulting, project management, or business continuity planning
* Managed security services, including vulnerability assessments, penetration testing, and incident response.
* Training and educational services, such as workshops, webinars, or certification courses for clients’ staff


# MSP Tools: Functions & Use

The core software an MSP runs on — RMM and PSA platforms, the wider tool categories, and how to choose the right stack.

MSPs run on software. This section covers the two platforms at the centre of most stacks — RMM and PSA — the broader categories of tooling around them, and how to evaluate what your business actually needs.

### In this section

{% content-ref url="/pages/fv5wHvqbsBQex6apqdw0" %}
[RMMs & PSAs](/msp-operations/msp-tools-and-their-functions/rmms-and-psas)
{% endcontent-ref %}

{% content-ref url="/pages/peGHwRcYKphzTRyRF5tm" %}
[Categories of tools](/msp-operations/msp-tools-and-their-functions/categories-of-tools)
{% endcontent-ref %}

{% content-ref url="/pages/qVwLZ6mS78dPpUbgryS7" %}
[Choosing the right tools](/msp-operations/msp-tools-and-their-functions/choosing-the-right-tools)
{% endcontent-ref %}


# RMMs & PSAs

Remote Monitoring and Management (RMM) and Professional Services Automation (PSA) are two distinct categories of software tools used by Managed Service Providers (MSPs) to manage their IT services and business operations. While both are crucial to the success of an MSP, they serve different purposes and have unique features. Here's a closer look at the differences between RMM and PSA tools and factors that may influence the choice of one tool over another.

### **Remote Monitoring and Management (RMM)**

**Purpose:** RMM tools are designed to help MSPs monitor, manage, and maintain their clients' IT infrastructure remotely. They enable MSPs to detect, diagnose, and resolve IT issues proactively without the need for on-site visits.

**Features:**

* Remote device monitoring (servers, workstations, network devices, etc.)
* Automated alerts and notifications for detected issues.
* Patch management and software updates
* Remote access and control of client devices
* Asset and inventory management

**Benefits:**

* Proactive problem detection and resolution
* Improved operational efficiency.
* Reduced downtime and disruptions for clients.
* Streamlined and automated IT maintenance processes

### **Professional Services Automation (PSA)**

**Purpose:** PSA tools are designed to help MSPs manage their business operations, including service delivery, resource management, and billing. They provide a centralized platform to automate and streamline various processes, improving efficiency and reducing manual effort.

**Features:**

* Ticketing and helpdesk management
* Project management and resource allocation
* Time tracking and billing.
* Customer relationship management (CRM)
* Reporting and analytics

**Benefits:**

* Streamlined business processes.
* Improved resource utilization and productivity
* Enhanced customer service and satisfaction
* Better visibility into business performance


# Categories of tools

The main categories of tools MSPs rely on — PSA, RMM, documentation, security, backup, network monitoring, and security awareness — and how they fit together.

MSPs rely on a wide range of tools to deliver efficient and reliable IT services to their clients. These tools help MSPs manage their clients' IT infrastructure, automate routine tasks, monitor performance, and ensure security. By understanding the roles and functions of different MSP tools, MSPs can better leverage their capabilities to streamline operations and maximize value for their clients.

| Category                                   | Examples                                  | Job to be done                                                                                                                                                                                                                                         |
| ------------------------------------------ | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **PSA** (Professional Services Automation) | ConnectWise, Datto Autotask, HaloPSA      | Streamline and automate business processes, including ticketing, project management, time tracking, billing, and reporting. PSAs serve as the central hub for managing MSP operations and provide a single source of truth for client data.            |
| **RMM** (Remote Monitoring and Management) | ConnectWise Automate, Datto RMM, NinjaOne | Monitor, manage, and maintain client IT infrastructure remotely. RMM tools enable MSPs to proactively identify and resolve issues, automate routine tasks, and provide remote support to clients.                                                      |
| **Documentation management**               | IT Glue, Hudu                             | Store, organize, and manage documentation related to clients, devices, networks, and processes. Effective documentation management ensures MSPs have quick access to accurate, up-to-date information, enabling faster and more efficient service.     |
| **Security tools**                         | Huntress, Blackpoint, SentinelOne         | Protect client IT infrastructure from threats such as malware, ransomware, and data breaches. Security tools help MSPs implement and maintain robust security measures, monitor for potential threats, and respond to incidents effectively.           |
| **Backup and disaster recovery**           | Datto BCDR, Veeam, Acronis                | Ensure data protection and business continuity for clients by backing up critical data and systems. These tools enable MSPs to quickly restore client data and services in the event of hardware failures, data loss, or other disasters.              |
| **Network Monitoring and Management**      | Auvik, LogicMonitor, Domotz               | Monitor, manage, and optimize clients' network infrastructure. These tools help MSPs proactively detect and resolve network issues, ensure optimal performance, and provide insights into network usage and trends.                                    |
| **Security Awareness Training**            | KnowBe4, Phin Security, BullPhish         | Educate employees on cybersecurity best practices, recognizing and avoiding threats, and maintaining secure behavior. These tools help build a strong security culture, reduce the risk of breaches, and support compliance with industry regulations. |

## How these tools work together to streamline operations

MSPs often integrate their tools to create a cohesive and efficient workflow. For example, PSA tools can integrate with RMM solutions and Network Monitoring and Management tools to automatically generate tickets when issues are detected. Documentation management tools can be connected to both PSA, RMM, and Network Monitoring platforms to provide relevant information within tickets or device management consoles. Security tools can send alerts to the RMM or PSA, triggering automated remediation or escalation procedures. Backup and disaster recovery solutions can also be integrated into the MSP's toolset, ensuring seamless data protection and recovery processes.

While all these tools play a crucial role in MSP operations, their relative importance may vary based on the specific needs and priorities of each MSP. Typically, PSA and RMM tools serve as the core of an MSP's toolset, as they directly impact service delivery and operational efficiency, so lets dig into them a bit deeper.


# Choosing the right tools

MSPs will generally use both an RMM and a PSA tools in their operations, in addition to other 3rd party solutions, as they all serve different purposes and complement each other. The choice of a specific tool within each category depends on factors such as:

* **Integration:** MSPs often prefer tools that can seamlessly integrate with other software they use. For instance, some RMM tools have built-in integrations with specific PSA tools, making it easier for MSPs to manage their IT services and business operations in a cohesive manner.
* **Features and functionality:** MSPs need to consider the specific features they require and how well a particular tool meets those requirements. For example, an MSP with a heavy focus on network management may prioritize an RMM tool with advanced network monitoring capabilities, or adopt a 3rd party networking solution.
* **Scalability:** As MSPs grow, their software tools must be able to scale with them. It's essential to choose tools that can accommodate an expanding client base and handle an increasing volume of work.
* **Ease of use and customization:** MSPs should consider how easy it is to learn and use a specific tool and how much customization it allows to adapt to their unique workflows and processes.
* **Cost:** Pricing models and total cost of ownership can vary between different tools. MSPs must carefully evaluate their budget constraints and ensure that the chosen tool provides the best value for their investment.


# Common Industry Challenges & Solutions

The recurring challenges MSPs face as the industry evolves, and practical strategies for addressing them.

Every MSP runs into a familiar set of obstacles as it grows and the market shifts. This section looks at how the industry's requirements are evolving, the challenges that follow, and the strategies MSPs use to meet them.

### In this section

{% content-ref url="/pages/AnFWvGvgCYcMajmwgJHA" %}
[Industry Evolution & Requirements](/msp-operations/common-challenges-and-solutions/industry-evolution-and-requirements)
{% endcontent-ref %}

{% content-ref url="/pages/OZrKWQskKfkZIMw67O77" %}
[Challenges Faced by MSPs](/msp-operations/common-challenges-and-solutions/challenges-faced-by-msps)
{% endcontent-ref %}

{% content-ref url="/pages/r5hwV8TjEFlLsotN3VC3" %}
[Strategies for Addressing Challenges](/msp-operations/common-challenges-and-solutions/strategies-for-addressing-challenges)
{% endcontent-ref %}


# Industry Evolution & Requirements

The MSP industry has evolved significantly over time, with enterprise tools not always being the right fit for MSPs. Understanding the reasons behind this and learning about the industry's history can provide valuable insights for both industry veterans and newcomers to the space.

* **Unique MSP requirements:** MSPs have specific needs that are not always met by traditional enterprise tools, such as multi-tenancy, tooling integrations, and automation capabilities tailored for their business model.
* **Market evolution:** As the IT landscape has evolved, MSPs have adapted to new technologies and market demands, requiring them to stay agile and informed about the latest trends and best practices.
* **Vendor relationships:** MSPs often rely on strong relationships with their vendors to access the best tools and solutions for their business, which can influence the way they operate and interact within the channel industry.


# Challenges Faced by MSPs

MSPs play a vital role in optimizing IT infrastructure and maintaining high levels of security for businesses. In their pursuit of delivering top-notch IT services, they face a unique set of challenges that can impact their operations. This section explores some of the prevalent concerns MSPs face, grouped into five main areas:

<details>

<summary>Financial and Operational Factors</summary>

* Balancing competitive pricing and profitability
* Streamlining processes and leveraging automation to reduce labor costs
* Managing expenses related to new technologies and staff training

</details>

<details>

<summary>Technological Adaptability</summary>

* Navigating the ever-changing landscape of tools, platforms, and best practices
* Adapting to emerging trends, such as cloud computing, remote work, and cybersecurity threats
* Ensuring staff possess the necessary training and certifications for relevant technologies

</details>

<details>

<summary>Customer Relationship Management</summary>

* Meeting and managing customer expectations while providing high-quality services
* Addressing customer demands for round-the-clock support and prompt issue resolution
* Fostering long-term client relationships by demonstrating value and expertise

</details>

<details>

<summary>Cybersecurity Considerations</summary>

* Protecting both the MSP's and clients' IT infrastructure from evolving cyber threats
* Implementing robust security measures and staying informed about the latest vulnerabilities and attacks
* Maintaining compliance with industry regulations and standards, such as GDPR and HIPAA

</details>

<details>

<summary>Business Scalability</summary>

* Expanding the client base without sacrificing service quality
* Handling the complexities of onboarding new clients and integrating their systems into the MSP's workflow
* Crafting a growth strategy that balances organic expansion with strategic partnerships and acquisitions

</details>

<details>

<summary>Staffing and Workload Challenges</summary>

* Managing staff workload to prevent burnout, maintain high service quality, and promote a healthy work-life balance
* Addressing the challenge of recruiting and retaining skilled IT professionals in a competitive job market while balancing specialized expertise with cross-training employees for greater flexibility
* Implementing efficient resource allocation, workload management practices, and support structures to optimize team performance and assist employees facing high-pressure situations

</details>


# Strategies for Addressing Challenges

As MSPs navigate the unique challenges they face in delivering top-tier IT services, it's crucial to have a strategic approach to overcome these hurdles. In this section, we explore various strategies for addressing the key challenges previously discussed. By implementing these strategies, MSPs can not only tackle their immediate concerns but also lay the groundwork for long-term success and growth in the industry.

<details>

<summary>Financial and Operational Factors</summary>

* Implementing a value-based pricing model that reflects the quality and expertise of the MSP's services
* Utilizing automation and process optimization to reduce manual labor and improve efficiency
* Continuously monitoring expenses and adjusting budget allocations to optimize resource utilization

</details>

<details>

<summary>Technological Adaptability</summary>

* Establishing a dedicated team responsible for tracking and evaluating new tools and technologies
* Creating a culture of continuous learning and offering ongoing training opportunities for employees
* Forming strategic partnerships with technology vendors to stay ahead of industry trends and developments

</details>

<details>

<summary>Customer Relationship Management</summary>

* Developing clear communication channels and setting realistic expectations with clients from the outset
* Investing in customer support tools and training to provide responsive, 24/7 support
* Regularly soliciting customer feedback and making data-driven improvements to service offerings

</details>

<details>

<summary>Cybersecurity Considerations</summary>

* Implementing a multi-layered security approach to protect both the MSP and its clients
* Actively participating in industry forums and networks to stay informed about emerging threats and vulnerabilities
* Conducting regular security audits and reviews to ensure compliance with industry standards and regulations

</details>

<details>

<summary>Business Scalability</summary>

* Establishing a standardized onboarding process for new clients to streamline integration and minimize disruptions
* Developing a clear growth strategy that outlines the MSP's expansion plans, including potential partnerships and acquisitions
* Investing in scalable infrastructure and technologies that can adapt as the business grows

</details>

<details>

<summary>Staffing and Workload Challenges</summary>

* Establishing a well-defined recruitment strategy to attract and retain top talent in the IT industry
* Implementing workload management tools and processes to ensure balanced work distribution among team members
* Fostering a supportive work environment that prioritizes employee well-being and encourages open communication

</details>


# MSP Departments and Business Units

How an MSP is organised — service desk, professional services, sales and account management — and the roles that fill each unit.

As MSPs scale, work splits into distinct departments. This section walks through the main business units — the service desk, professional services, and sales and account management — and the industry roles that staff them.

### In this section

{% content-ref url="/pages/aJ1jc5ANQ7ft20ZDiGFh" %}
[MSP Service Desk Styles and Operational Maturity Levels](/msp-operations/msp-departments-and-business-units/msp-service-desk-styles-and-operational-maturity-levels)
{% endcontent-ref %}

{% content-ref url="/pages/DeuPyz9z7BujIB3YZTy1" %}
[Professional Services Department: Technical Expertise and Collaboration with the Service Desk](/msp-operations/msp-departments-and-business-units/professional-services-department-technical-expertise-and-collaboration-with-the-service-desk)
{% endcontent-ref %}

{% content-ref url="/pages/yxphJfTpWI94yUN3AOVz" %}
[Sales, Account Management, and Marketing: Driving MSP Growth and Client Satisfaction](/msp-operations/msp-departments-and-business-units/sales-account-management-and-marketing-driving-msp-growth-and-client-satisfaction)
{% endcontent-ref %}

{% content-ref url="/pages/shaSkKWI3jxGmy7sLHo2" %}
[Industry Roles & Responsibilities](/msp-operations/msp-departments-and-business-units/roles)
{% endcontent-ref %}


# MSP Service Desk Styles and Operational Maturity Levels

MSP service desks play a critical role in delivering efficient and reliable support to clients. There are various styles of service desks, each with its unique approach to handling service requests and managing resources. This section explores different service desk styles and their corresponding levels of operational maturity.

This document contains a general overview of different styles MSPs can adopt. While there are variations and combinations of these styles, the most common MSP service desk types can be broadly categorized as follows:

1. **Tiered Service Desk**: In a tiered service desk model, support is divided into different levels, with each level responsible for handling specific types of issues. Typically, Level 1 support handles basic troubleshooting and issue resolution, while more complex problems are escalated to higher levels. This model allows for efficient allocation of resources and ensures that technicians with the appropriate expertise are assigned to relevant tasks.
2. **Swarming Service Desk**: The swarming model is a collaborative approach to issue resolution, where technicians from various disciplines work together to solve problems without the need for formal escalation. This model can lead to faster resolution times and improved knowledge sharing among team members. However, it may require a higher level of coordination and communication to function effectively.
3. **Dedicated Support Team**: In this model, MSPs assign dedicated support teams to specific clients, ensuring that technicians are familiar with the client's environment and requirements. This approach can improve the overall quality of service and foster stronger client relationships, but it may also result in higher operational costs due to the need for specialized resources. This style is also called "Pod-Style".
4. **Shared Service Desk**: A shared service desk is a centralized support model where multiple clients' needs are addressed by a single team of technicians. This model can offer cost savings and improved resource utilization for MSPs but may lead to less personalized service for clients.

MSPs can choose from these service desk types or adopt a hybrid approach, combining elements from different models to best suit their clients' needs and their operational goals. Ultimately, the most effective MSP service desk model will depend on factors such as client expectations, available resources, and the MSP's overall strategy for growth and operational maturity.

Within these styles there are several operational differences that define how the service desk works at a tactical level as well, where the primary categories are:

#### 1. Service Desk with Dispatchers

In this style, MSPs utilize dedicated dispatchers to manage incoming service requests, assign tasks to technicians, and oversee the overall service delivery process. This model allows for improved coordination and efficient allocation of resources, leading to higher operational maturity. Dispatchers can ensure that tasks are assigned according to technicians' skills, availability, and workload, enabling timely resolution of issues and adherence to SLAs (Service Level Agreements).

#### 2. Service Desk without Dispatchers

In contrast, a service desk without dispatchers relies on technicians to self-assign tasks and manage their workload independently. While this model can offer flexibility and autonomy, it may lead to suboptimal resource allocation, longer response times, and potential breaches of SLAs. This approach is generally associated with lower operational maturity, as there is less centralized control over service delivery processes.

#### 3. Service Desk with SLAs

Service desks that operate under SLAs have predefined response and resolution timeframes based on the severity and priority of service requests. Implementing SLAs can help MSPs maintain a high level of operational maturity by setting clear expectations for service delivery and ensuring that client issues are addressed promptly. This approach also allows MSPs to measure their performance against industry standards and make data-driven improvements to their processes.

#### 4. Service Desk without SLAs

Operating a service desk without SLAs can hinder an MSP's ability to achieve higher operational maturity. Without clearly defined expectations for response and resolution times, it becomes challenging to measure performance and ensure consistent service quality. MSPs without SLAs may struggle to prioritize tasks effectively, leading to inefficiencies and potential client dissatisfaction.

MSPs should carefully consider their service desk style and adopt practices that promote higher operational maturity. Incorporating dispatchers and implementing SLAs can enhance resource allocation, streamline processes, and ensure timely resolution of service requests. By continuously evaluating and refining their service desk operations, MSPs can deliver exceptional support and build lasting relationships with their clients.


# Professional Services Department: Technical Expertise and Collaboration with the Service Desk

The professional services department within an MSP plays a critical role in delivering specialized solutions and consulting services to clients. This department is responsible for addressing complex client needs that may fall outside the scope of standard service desk offerings. In this section, we'll explore how the professional services department operates on a technical level and how it collaborates with the service desk.

#### Technical Expertise

The professional services department is comprised of highly skilled technicians, engineers, and consultants with deep expertise in various areas of technology and IT management. This team is responsible for providing specialized services such as:

* IT strategy development and planning
* System design and architecture
* Advanced troubleshooting and root cause analysis
* Integration of disparate systems and applications
* Implementation of new technologies and solutions
* Business process optimization and IT service management (ITSM) consulting

The professional services department stays up-to-date with the latest industry trends, emerging technologies, and best practices to ensure they can deliver cutting-edge solutions and advice to clients.

#### Collaboration with Service Desk

The professional services department works closely with the service desk to ensure seamless delivery of services and support. Collaboration between these two teams typically occurs in several ways:

1. **Escalation of complex issues**: When the service desk encounters an issue that requires advanced technical expertise or falls outside their scope, they escalate the problem to the professional services department. This ensures that clients receive timely and effective support from technicians with the appropriate skills and knowledge.
2. **Project support**: Professional services may be called upon to provide support for specific projects, such as infrastructure upgrades, migrations, or system deployments. In these cases, the service desk and professional services teams work together to ensure a smooth transition and minimal disruption to the client's operations.
3. **Knowledge sharing**: The professional services department often shares their expertise with the service desk through training sessions, documentation, and regular communication. This enables the service desk to expand their technical knowledge and provide better support to clients.
4. **Client engagement**: Professional services and service desk teams may collaborate on client engagements, such as onboarding new clients, conducting IT assessments, or developing customized support plans. This collaborative approach ensures that clients receive comprehensive and tailored services that address their unique needs and requirements.

The professional services department within an MSP delivers specialized technical expertise and works closely with the service desk to ensure clients receive the best possible support and solutions. By leveraging the unique strengths of both teams, MSPs can provide a comprehensive range of services that drive value and satisfaction for their clients.


# Sales, Account Management, and Marketing: Driving MSP Growth and Client Satisfaction

The combined efforts of sales, account management, and marketing teams within an MSP play a critical role in driving business growth and ensuring client satisfaction. These interconnected departments work together to attract new clients, retain existing ones, and promote the MSP's brand and services. In this section, we'll explore how these teams collaborate to achieve their common goals.

Smaller MSPs often face resource constraints that necessitate combining roles and responsibilities to operate efficiently. As a result, it is common for employees in smaller MSPs to wear multiple hats, handling tasks that may span sales, account management, and marketing. This approach allows smaller MSPs to optimize their resources while still delivering the essential functions required for growth and client satisfaction.

Given the specialized nature of marketing and the time-consuming tasks involved, smaller MSPs frequently opt to utilize external marketing resources, such as marketing agencies or freelancers. This enables them to access expert marketing services without the need for a dedicated in-house team. By outsourcing marketing activities, smaller MSPs can focus on their core services and effectively scale their business while maintaining a lean and agile structure.

Smaller MSPs demonstrate that by combining roles and leveraging external resources, it is possible to achieve growth and success in the industry, even with limited resources. This flexible and adaptable approach enables these MSPs to navigate the challenges of a competitive market and deliver exceptional service to their clients.

### Sales: Attracting New Clients and Upselling Services

The sales team is responsible for identifying and pursuing new business opportunities, as well as upselling additional services to existing clients. They are skilled at understanding clients' needs and presenting tailored solutions that address their unique requirements. The sales team works closely with account management and marketing to ensure they have the right resources and support to close deals effectively.

### Account Management: Building Strong Client Relationships

Account management focuses on maintaining and nurturing relationships with existing clients. This team is responsible for addressing clients' ongoing needs, resolving any issues or concerns, and ensuring they remain satisfied with the MSP's services. By building strong relationships and demonstrating a deep understanding of clients' businesses, account managers can help retain clients and identify new opportunities for growth.

### Marketing: Promoting the MSP Brand and Services

The marketing team works to raise awareness of the MSP's brand and services, attracting potential clients and positioning the MSP as a trusted and reliable partner. They create marketing campaigns, develop content, and utilize digital marketing strategies to reach target audiences. The marketing team also supports the sales and account management teams by providing resources, such as case studies, whitepapers, and sales presentations, that help showcase the MSP's value proposition and expertise.

### Collaboration and Alignment

To achieve their common goals, sales, account management, and marketing teams must work closely together and align their efforts. This collaboration can take several forms:

* **Shared objectives and targets**: Setting common goals and key performance indicators (KPIs) ensures all teams are working towards the same objectives and can measure their success consistently.
* **Regular communication and feedback**: Open lines of communication between these teams facilitate knowledge sharing, feedback on client needs, and the sharing of insights on market trends or competitor activities.
* **Cross-functional initiatives**: Joint projects, such as events, webinars, or targeted campaigns, can maximize the impact of each team's efforts and help drive the overall success of the MSP.

Tthe collaboration between sales, account management, and marketing teams within an MSP is crucial for driving growth and maintaining client satisfaction. By working together and aligning their efforts, these teams can effectively attract new clients, retain existing ones, and promote the MSP's brand and services in a competitive market.


# Industry Roles & Responsibilities

A reference of the technical and support roles found inside MSPs and the vendors that serve them, and what each one is responsible for.

MSPs and the vendors that serve them are staffed by a wide range of roles. The tables below group the most common ones by where they sit — technical roles inside MSPs, technical roles inside vendors, and the support roles found across both.

## Technical Roles Inside MSPs

| Role                          | What they do                                                                                                                                                                                      |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Help Desk Technician**      | Provides first-level technical support to clients, resolving basic issues and escalating more complex problems to higher-level technicians.                                                       |
| **On-site Engineer**          | Provides hands-on support at client locations. Addresses technical issues that cannot be resolved remotely and may also perform installations, hardware maintenance, and infrastructure upgrades. |
| **Network Administrator**     | Maintains the MSP's internal network infrastructure and ensures that client networks are stable, secure, and optimized for performance.                                                           |
| **Systems Administrator**     | Manages and maintains clients' servers, storage systems, and applications, ensuring optimal performance, reliability, and security.                                                               |
| **Security Specialist**       | Protects MSPs and their clients from cyber threats by implementing security measures, monitoring for potential breaches, and responding to incidents.                                             |
| **Cloud Specialist**          | Helps clients migrate to, manage, and optimize their cloud-based infrastructure, leveraging public, private, or hybrid cloud environments.                                                        |
| **Virtualization Specialist** | Designs, implements, and manages virtualized environments for clients, optimizing resource usage, performance, and scalability.                                                                   |
| **IT Consultant**             | Works with clients to assess their technology needs, develop strategies, and recommend solutions to improve efficiency, productivity, and security.                                               |

## Technical Roles Inside Vendors

| Role                                | What they do                                                                                                                                                                  |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Product Manager**                 | Guides the development of products and services, working closely with development teams and stakeholders to define requirements and prioritize features.                      |
| **Software Developer/Engineer**     | Designs, develops, tests, and maintains software applications and systems, ensuring they meet the needs of customers and adhere to quality standards.                         |
| **Quality Assurance (QA) Engineer** | Tests products and services, identifying and reporting defects, and ensuring that they meet quality standards and customer requirements.                                      |
| **DevOps Engineer**                 | Improves collaboration between development and operations teams, streamlining the software development lifecycle and automating processes for efficiency and consistency.     |
| **Solution Architect**              | Designs and oversees the implementation of complex technology solutions, ensuring they meet the needs of customers and align with the vendor's product offerings.             |
| **Technical Support Engineer**      | Assists customers experiencing issues with the vendor's products or services, working to diagnose and resolve problems as efficiently as possible.                            |
| **Sales Engineer**                  | Works closely with sales teams to provide technical expertise, demonstrating the value of the vendor's products and services to potential clients and helping to close deals. |

## Support Roles in MSPs and Vendors

| Role                                            | What they do                                                                                                                                                                                                                                                                                                                |
| ----------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Account Manager / Customer Success Manager**  | Maintains relationships with clients, ensuring their needs are met and working to upsell additional services or products. Focused on ensuring clients have a positive experience with the company, service, or product, and resolving any issues that arise.                                                                |
| **Sales / Business Development Representative** | Generates new business by identifying potential clients, presenting the benefits of the company's products and services, and closing deals.                                                                                                                                                                                 |
| **Marketing Specialist**                        | Creates and implements marketing strategies to promote the company's products and services, generate leads, and build brand awareness.                                                                                                                                                                                      |
| **Project Manager**                             | Oversees the planning, execution, and completion of projects, coordinating resources and ensuring projects are delivered on time, within scope, and budget.                                                                                                                                                                 |
| **Business Analyst / Operations**               | Works to understand client needs and identify opportunities for improvement, often collaborating with technical teams to develop solutions and drive business growth.                                                                                                                                                       |
| **Training Specialist**                         | Develops and delivers training programs to both internal employees and clients, ensuring users can effectively utilize the company's products and services.                                                                                                                                                                 |
| **Automation Engineer**                         | Develops and implements automation solutions to enhance efficiency and effectiveness within the MSP's service delivery framework. Requires a deep understanding of automation technologies and best practices, with responsibilities including the design, deployment, and maintenance of automation scripts and workflows. |
| **Integration Specialist**                      | Ensures the seamless integration of various IT systems and applications within the MSP's infrastructure. Involves analyzing system requirements, coordinating with different teams to facilitate smooth data exchange, and optimizing the overall IT ecosystem for enhanced operational efficiency.                         |


# MSP Compliance & Regulations

Why compliance matters for MSPs, the regulations that most often apply, and how to manage risk, incidents, and client obligations.

MSPs sit at the intersection of many clients' regulatory obligations. This section explains why compliance matters, the regulations that most commonly apply, the practical challenges of meeting them, and how MSPs handle risk, incident response, and client-facing compliance work.

### In this section

{% content-ref url="/pages/ykN51HIGmESGEaUUgVrU" %}
[Importance of Compliance for MSPs](/msp-operations/msp-compliance-and-regulations/importance-of-compliance-for-msps)
{% endcontent-ref %}

{% content-ref url="/pages/htfnTKrX800n0d4ttUWw" %}
[Common Regulations Affecting MSPs](/msp-operations/msp-compliance-and-regulations/common-regulations-affecting-msps)
{% endcontent-ref %}

{% content-ref url="/pages/v0T1UJDmimEeHgUKEWr3" %}
[Compliance Challenges & Strategies for MSPs](/msp-operations/msp-compliance-and-regulations/compliance-challenges-and-strategies-for-msps)
{% endcontent-ref %}

{% content-ref url="/pages/1yzS2nudPD4qcusKH7Z9" %}
[Risk Management and Incident Response](/msp-operations/msp-compliance-and-regulations/risk-management-and-incident-response)
{% endcontent-ref %}

{% content-ref url="/pages/ftBOUVIzgpg2ypyn8GOs" %}
[Working with Clients on Compliance](/msp-operations/msp-compliance-and-regulations/working-with-clients-on-compliance)
{% endcontent-ref %}


# Importance of Compliance for MSPs

In an increasingly regulated business environment, compliance with industry regulations and standards is a key aspect of running a successful MSP. This section will discuss the reasons why compliance is so important for MSPs, including building trust and credibility, avoiding legal and financial consequences, and gaining a competitive advantage in the market.

* **Trust and credibility:** Compliance with industry regulations and standards is essential for MSPs to build trust and credibility with their clients. Demonstrating adherence to these rules shows clients that the MSP takes data protection and security seriously.
* **Legal and financial consequences:** Non-compliance can lead to severe legal and financial penalties for both MSPs and their clients. Ensuring compliance helps MSPs avoid these consequences and protect their reputation in the industry.
* **Competitive advantage:** MSPs that consistently maintain compliance can gain a competitive advantage over other providers who struggle with regulatory requirements. Compliance can be a differentiating factor that helps MSPs attract and retain clients.


# Common Regulations Affecting MSPs

A quick-reference guide to the regulations MSPs most often encounter — GDPR, ISO 27001, NIS2, SOC 2, HIPAA, and Cyber Essentials — and who each applies to.

As MSPs serve clients across various industries and regions, they must navigate a complex landscape of regulations and standards. This section will provide an overview of some common regulations that MSPs often encounter, such as GDPR, HIPAA, and PCI-DSS, and the implications of these regulations for their operations.

**At a glance:**

| Regulation           | Scope                                              | Applies to                                            |
| -------------------- | -------------------------------------------------- | ----------------------------------------------------- |
| **GDPR**             | EU data-protection law                             | Any MSP handling EU citizens' data                    |
| **ISO 27001**        | International information-security standard (ISMS) | MSPs adopting a formal security framework             |
| **NIS2**             | EU directive (upcoming)                            | All EU-based MSPs                                     |
| **SOC 2**            | US audit of security controls                      | Service organizations demonstrating security maturity |
| **HIPAA**            | US healthcare privacy law                          | MSPs handling Protected Health Information (PHI)      |
| **Cyber Essentials** | UK government-backed certification scheme          | MSPs, especially those with UK government contracts   |

Each is covered in more detail below.

### GDPR Compliance

GDPR (General Data Protection Regulation) is a critical regulatory framework for businesses operating within the European Union (EU) or handling EU citizens' data. MSPs need to ensure they adhere to GDPR guidelines to protect their clients' data and avoid potential penalties. GDPR compliance involves implementing appropriate technical and organizational measures to safeguard personal data, notifying relevant authorities in case of data breaches, and respecting data subjects' rights.

### ISO 27001 and NIS2

ISO 27001 is an internationally recognized standard for information security management systems (ISMS). It provides a comprehensive framework for securing an organization's data and processes. MSPs can benefit from adopting ISO 27001 best practices to improve their security posture and demonstrate their commitment to data protection.

NIS2 (Network and Information Systems Directive) is an upcoming regulatory requirement for all EU-based MSPs. It aims to strengthen the security and resilience of critical infrastructure, making it mandatory for MSPs to adhere to NIS2 guidelines. By complying with both ISO 27001 and NIS2, MSPs can ensure they meet security standards and regulatory requirements.

### SOC 2 Compliance

SOC 2 (Service Organization Control) is an auditing procedure that assesses a service organization's controls over security, availability, processing integrity, confidentiality, and privacy. Achieving SOC 2 compliance is an essential step for MSPs to demonstrate their commitment to maintaining a robust security framework. However, it is important to note that SOC 2 compliance is not a guarantee of absolute security and MSPs should continuously assess and update their security measures.

### HIPAA Compliance

HIPAA (Health Insurance Portability and Accountability Act) is a U.S. federal law that establishes requirements for the handling and protection of sensitive healthcare data, known as Protected Health Information (PHI). MSPs working with healthcare organizations or handling PHI must comply with HIPAA regulations to ensure the confidentiality, integrity, and availability of this sensitive data.

Compliance with HIPAA involves implementing administrative, physical, and technical safeguards to protect PHI. Administrative safeguards include policies and procedures that address privacy and security, workforce training, and designated privacy and security officers. Physical safeguards involve secure access to facilities and workstations, while technical safeguards require implementing access controls, encryption, and audit controls for electronic PHI.

MSPs should conduct regular risk assessments to identify and address potential vulnerabilities in their systems and processes. By adhering to HIPAA guidelines, MSPs can maintain the trust of their healthcare clients and avoid potential legal and financial consequences of non-compliance.

### Cyber Essentials Compliance

Cyber Essentials is a UK government-backed scheme that helps protect organizations, regardless of size, against a whole range of the most common cyber attacks. Compliance with Cyber Essentials is crucial for MSPs, especially those handling UK government contracts or looking to improve their cybersecurity defenses. The scheme focuses on five key controls:

1. **Secure Configuration:** Ensuring that systems are configured in the most secure way for the needs of the organization.
2. **Boundary Firewalls and Internet Gateways:** These devices form the boundary between an organization's network and the Internet. Proper setup of these devices is crucial for preventing unauthorized access.
3. **Access Control and Administrative Privilege Management:** Ensuring only those who should have access to systems to have it and at the appropriate level.
4. **Patch Management:** Keeping software on computers and network devices up to date and fixing known vulnerabilities.
5. **Malware Protection:** Ensuring that virus and malware protection is installed and up to date.

Achieving Cyber Essentials certification demonstrates an MSP's commitment to security, providing reassurance to clients and a competitive edge in the marketplace. The certification process involves a self-assessment questionnaire and an external scan of the network, validated by a certification body.

For MSPs, adhering to Cyber Essentials can significantly reduce the risk of prevalent cyber threats. By implementing the scheme's controls, MSPs can not only protect their own operations but also offer added value to their clients by enhancing their cybersecurity posture.

### Misrepresentation of Certifications

Both vendors and MSPs sometimes misrepresent their security posture by claiming their data center(AWS, Azure, Google Cloud) is certified, rather than their organization itself. This misconception can lead to a false sense of security and a lack of proper due diligence.

It is crucial for MSPs to understand that data center certifications apply only to the data center vendor themselves and are not transferable. A vendor or MSP is not SOC2 certified if they host data in AWS, as their business layer has not been evaluated .

MSPs should be cautious not to overstate their compliance status and ensure they have implemented appropriate security measures at every level of their organization.


# Compliance Challenges & Strategies for MSPs

Ensuring compliance with industry regulations and standards can present several challenges for MSPs, from keeping up with the constantly changing regulatory landscape to addressing diverse client requirements. In this section, we delve into these challenges and explore the factors that can make compliance management complex for MSPs.

* **Keeping up with changing regulations:** MSPs must stay informed about the latest regulatory changes and updates, which can be challenging due to the constantly evolving landscape of laws and standards.
* **Diverse client requirements:** MSPs often serve clients from various industries and regions, each with its own set of regulatory requirements. Catering to these diverse needs can be complex and resource-intensive.
* **Limited resources and expertise:** Smaller MSPs may struggle to allocate sufficient resources and expertise to compliance management, particularly if they lack dedicated in-house legal or compliance teams.

### Strategies for Ensuring Compliance

* **Regular training and education:** MSPs should provide ongoing training and education to their employees on relevant regulations and standards, ensuring they are equipped with the knowledge needed to maintain compliance.
* **Compliance audits:** Conducting regular internal and external compliance audits can help MSPs identify gaps or areas of non-compliance, allowing them to address these issues proactively.
* **Utilizing compliance management tools:** MSPs can leverage various tools and software solutions to automate and streamline their compliance management processes, such as monitoring data privacy, tracking regulatory changes, and managing documentation.
* **Partnering with experts:** MSPs can collaborate with legal or compliance consultants to ensure they are meeting all relevant regulatory requirements and staying up to date with industry best practices.


# Risk Management and Incident Response

In a world where cyber threats are ever-evolving, MSPs must prioritize risk management and incident response to protect their clients' sensitive data and IT infrastructure. This section will discuss the importance of implementing risk management processes, the role of incident response in mitigating the impact of cyber threats, and the strategies MSPs can use to effectively manage risks and respond to incidents.

### Importance of Risk Management for MSPs

Risk management is a critical aspect of an MSP's operations, as it helps identify, assess, and mitigate potential threats to clients' IT systems and data. By proactively addressing risks, MSPs can minimize the impact of security incidents, maintain client trust, and protect their own reputation. Effective risk management allows MSPs to:

* Ensure the confidentiality, integrity, and availability of client data and systems
* Reduce the likelihood and impact of security breaches and incidents
* Strengthen client relationships by demonstrating a commitment to security
* Comply with industry regulations and standards

### Key Components of an Incident Response Plan

An incident response plan outlines the steps MSPs should take to quickly detect, contain, and remediate security incidents. Key components of an incident response plan include:

* **Incident identification and reporting:** Establishing clear guidelines for identifying and reporting potential security incidents
* **Roles and responsibilities:** Defining the roles and responsibilities of the incident response team and other stakeholders
* **Communication and escalation procedures:** Outlining how information should be shared and escalated within the organization and with clients during a security incident
* **Incident containment and eradication:** Detailing the steps to contain and eradicate threats to minimize their impact
* **Recovery and restoration:** Describing the process for restoring affected systems and data to their pre-incident state
* **Post-incident review and analysis:** Conducting a thorough review and analysis of the incident to identify lessons learned and improve future incident response efforts

### Best Practices for Risk Management and Incident Response

To effectively manage risks and respond to incidents, MSPs should consider the following best practices:

* Regularly assess and update risk management processes to ensure they remain relevant and effective
* Conduct security awareness training for employees to help prevent incidents caused by human error
* Implement a multi-layered security approach that includes proactive monitoring, regular vulnerability assessments, and timely patch management
* Collaborate with clients to establish clear expectations around incident response and communication
* Test and update the incident response plan regularly to ensure its effectiveness and alignment with the changing threat landscape


# Working with Clients on Compliance

As trusted IT partners, MSPs play a critical role in helping their clients achieve and maintain compliance with industry regulations and standards. This section will cover how MSPs can collaborate with their clients to ensure compliance, from setting expectations and providing guidance to offering compliance-focused services and solutions.

### Setting Compliance Expectations with Clients

To help clients achieve and maintain compliance, MSPs should:

* Clearly communicate the role of the MSP in supporting clients' compliance efforts, including the services and solutions provided
* Establish a shared understanding of the client's compliance obligations and the associated risks
* Define the client's responsibilities in achieving and maintaining compliance, such as providing necessary information and implementing recommended security measures
* Educating clients about their compliance responsibilities
* Aligning services with clients' regulatory requirements
* Collaborating with clients on incident response and risk management

### Providing Compliance Guidance and Education

MSPs can support their clients' compliance efforts by:

* Educating clients on relevant regulations and standards and their implications for the client's business
* Offering guidance on best practices for achieving and maintaining compliance, tailored to the client's specific needs and industry
* Regularly updating clients on changes to regulations and standards that may impact their compliance status

### Offering Compliance-Focused Services and Solutions

To further assist clients in achieving compliance, MSPs can offer specialized services and solutions, such as:

* Compliance assessments and audits to identify gaps and areas for improvement
* Remediation services to help clients address identified compliance issues
* Managed security services that help clients maintain a secure IT environment and meet regulatory requirements
* Compliance-focused toolsets and integrations to streamline the compliance management process


# Managing Strategic Relationships

Turning transactional vendor relationships into strategic partnerships: co-selling, MDFs, vendor-specific programs, and channel best practices.

While many vendor relationships in the MSP industry are transactional, focused primarily on upselling, strategic partnerships can be highly beneficial for both parties. In a strategic partnership, MSPs and vendors work closely together, aligning their goals and resources to create mutual value. Here are some thoughts to consider and address when forming and managing strategic vendor relationships:

<details>

<summary>Selecting the Right Strategic Partners</summary>

As an MSP, you can only manage a limited number of strategic partners effectively. Therefore, it's essential to carefully evaluate potential partners to ensure they align with your business goals and can deliver significant value to your clients.

* Assess the vendor's products and services to determine if they meet your clients' needs and complement your existing offerings.
* Evaluate the vendor's reputation, expertise, and commitment to innovation, as well as their ability to provide ongoing support and resources.
* Determine if the vendor shares your values and vision, and if they're willing to invest in a long-term partnership.

</details>

<details>

<summary>Leveraging Co-selling Opportunities and MDFs</summary>

Strategic partners can offer valuable opportunities for co-selling and access to Market Development Funds (MDFs). These resources can help you expand your market reach and grow your business.

* Collaborate with your vendor partners on joint marketing efforts, such as co-branded content, webinars, and events, to reach a broader audience and showcase your combined value proposition.
* Leverage MDFs to support marketing initiatives and campaigns that promote your partnership and drive sales of the vendor's products or services.
* Engage in co-selling activities, working together with your vendor partners to identify leads, create tailored solutions, and close deals.

</details>

<details>

<summary>Establishing Clear Contracts and Expectations</summary>

When entering into a strategic partnership, it's crucial to read and understand the contract thoroughly and establish clear expectations for both parties.

* Review the contract terms, including pricing, support, and SLAs, to ensure they align with your business requirements and goals.
* Clearly define each party's roles and responsibilities in the partnership, including communication, collaboration, and performance expectations.
* Establish a framework for measuring the success of the partnership, such as KPIs and milestones, and schedule regular check-ins to review progress and address any issues or concerns.

</details>

<details>

<summary>Managing and Nurturing Vendor Relationships</summary>

To fully realize the potential of strategic vendor partnerships, MSPs must actively manage and nurture these relationships.

* Communicate regularly with your vendor partners, sharing updates on your business, market insights, and feedback on their products and services.
* Engage in ongoing training and development opportunities provided by your vendors, ensuring your team stays up-to-date on the latest technologies, best practices, and certifications.
* Recognize and celebrate the successes and milestones achieved through your partnership, reinforcing your commitment to mutual growth and collaboration.

</details>

By carefully selecting the right strategic partners, leveraging co-selling opportunities and MDFs, establishing clear contracts and expectations, and actively managing and nurturing vendor relationships, MSPs can build strong, mutually beneficial partnerships that drive business growth and create lasting value.

### In this section

{% content-ref url="/pages/9osU50hMfWH28QOFPUTn" %}
[A Guide to Co-selling and MDF Strategies](/msp-relationships/managing-strategic-relationships/a-guide-to-co-selling-and-mdf-strategies)
{% endcontent-ref %}

{% content-ref url="/pages/O0UHeIcLetpwcgMGyZ5p" %}
[Requesting MDFs from Vendors: Best Practices](/msp-relationships/managing-strategic-relationships/requesting-mdfs-from-vendors-best-practices)
{% endcontent-ref %}

{% content-ref url="/pages/a3QnsLcYnmD69fvMMUye" %}
[Exploring Vendor-Specific Programs for MSPs](/msp-relationships/managing-strategic-relationships/exploring-vendor-specific-programs-for-msps)
{% endcontent-ref %}

{% content-ref url="/pages/I0KtApsriloeO12Pxdzh" %}
[Best Practices for Vendor Channel programs](/msp-relationships/managing-strategic-relationships/best-practices-for-vendor-channel-programs)
{% endcontent-ref %}


# A Guide to Co-selling and MDF Strategies

Managed Service Providers (MSPs) can benefit significantly from channel programs that emphasize co-selling and Market Development Funds (MDF) strategies. This comprehensive guide will help you understand these strategies and their importance in building successful partnerships between MSPs and vendors.

## Co-selling Strategies

Co-selling is a collaborative sales approach where MSPs and vendors work together to identify sales opportunities, develop tailored solutions, and close deals. This collaborative approach helps MSPs expand their reach and leverage the vendor's expertise and resources.

### **Key Benefits of Co-selling:**

* Access to the vendor's sales and marketing resources, including training, collateral, and lead sharing.
* Collaboration tools that enable seamless communication between MSPs and vendors.
* Opportunities to close deals more effectively by leveraging the vendor's expertise and customer base.

## Market Development Funds (MDF) Strategies

MDFs are funds provided by vendors to their partners, such as MSPs, to help them invest in marketing initiatives promoting the vendor's products and services. By reimbursing a portion of their marketing expenses, vendors enable MSPs to execute more impactful marketing campaigns and expand their customer base.

### **Key Benefits of MDFs:**

* Financial support for marketing campaigns, events, and other promotional activities.
* Opportunities to invest in marketing initiatives that drive sales of the vendor's products and services.

By focusing on collaboration and investing in marketing support, these channel programs demonstrate the importance of co-selling and MDF strategies in building successful partnerships between MSPs and vendors. Engaging in these programs enables MSPs to grow their businesses and deliver better services to their clients.


# Requesting MDFs from Vendors: Best Practices

### **Research Vendor MDF Programs**

* Familiarize yourself with each vendor's MDF program requirements, application process, and reporting expectations.
* Review the vendor's MDF program documentation and attend any available training or webinars to gain a clear understanding of their process.

### **Develop a Marketing Plan**

* Create a detailed marketing plan outlining the objectives, target audience, tactics, timeline, and expected results of the campaign.
* Clearly align the marketing plan with the vendor's products, services, or solutions.
* Provide a realistic budget and breakdown of the marketing expenses that you plan to incur during the campaign.

### **Prepare a Compelling MDF Proposal**

* Present your marketing plan in a clear and concise proposal, demonstrating the value of the campaign for both your MSP and the vendor.
* Highlight the expected return on investment (ROI) and key performance indicators (KPIs) that will be used to measure the success of the campaign.
* Emphasize how the campaign will drive demand for the vendor's products or services and strengthen your partnership.

### **Submit the MDF Request**

* Follow the vendor's MDF request submission process, ensuring that all required documentation and information is provided.
* Submit the request within the vendor's specified time frame, and keep track of any deadlines for reporting or reimbursement claims.

### **Track Campaign Performance and Report Results**

* Monitor the performance of the marketing campaign, tracking the KPIs and ROI as outlined in your proposal.
* Regularly communicate the progress of the campaign to your vendor contact, providing updates and addressing any concerns.
* Complete any required post-campaign reporting, including proof of performance and expense documentation, to ensure timely reimbursement and compliance with the vendor's MDF program requirements.


# Exploring Vendor-Specific Programs for MSPs

### **Importance of Vendor Programs**

* Vendor programs, such as Microsoft's "coop funds," can provide valuable financial support, resources, and incentives for MSPs.
* These programs can enhance an MSP's ability to grow its business, improve its service offerings, and strengthen its relationships with vendors.

### **Proactively Seeking Opportunities**

* Encourage MSPs to actively research and inquire about the availability of vendor-specific programs, as they may not always be widely advertised or promoted.
* Highlight the importance of maintaining open communication with vendor representatives to stay informed about new programs, updates, or changes to existing programs.

### **Eligibility and Qualification**

* Remind MSPs not to assume they are ineligible for vendor-specific programs, as qualification criteria can vary widely and may be more flexible than expected.
* Encourage MSPs to review the eligibility requirements for each program carefully and consult with their vendor representatives to determine their qualification status.

### **Making the Most of Vendor Programs**

* Suggest that MSPs create an internal process or designate a team member to stay up-to-date on vendor programs, track relevant deadlines, and submit necessary applications or documentation.
* Encourage MSPs to measure the benefits of participating in vendor programs and share their success stories with both the vendor and the MSP community.

### Examples of Channel Programs with Successful Co-selling and MDF Strategies

1. **Cisco Partner Program**
   * *Co-selling:* Provides dedicated sales support, including access to sales resources, training, and lead sharing, to help partners expand their reach and increase deal size.
   * *MDF:* Rewards partners for their marketing efforts by reimbursing a portion of their marketing expenses, enabling them to invest in marketing initiatives promoting Cisco's products and services.
2. **Microsoft Partner Network (MPN)**
   * *Co-selling:* Offers access to Microsoft's extensive sales and marketing resources, collaboration tools, and lead sharing to enable partners to reach new customers and close deals more effectively.
   * *MDF:* Supports partners in executing marketing campaigns, events, and other promotional activities through a comprehensive MDF program based on their performance.
3. **ConnectWise Partner Program**
   * *Co-selling:* Works closely with partners to identify sales opportunities, develop tailored solutions, and close deals, providing access to sales resources such as training, collateral, and lead sharing.
   * *MDF:* Rewards partners for investing in marketing activities promoting ConnectWise's products and services, offering reimbursement for marketing expenses to help them execute more impactful campaigns and expand their customer base.

By focusing on collaboration and investing in marketing support, these channel programs demonstrate the importance of co-selling and MDF strategies in building successful partnerships between MSPs and vendors. Engaging in these programs enables MSPs to grow their businesses and deliver better services to their clients.


# Best Practices for Vendor Channel programs

#### Best Practices for Vendors Setting Up a Channel Program for MSPs

**1. Clearly Define Program Objectives and Benefits**

* Establish clear goals and objectives for your channel program, focusing on mutual benefits for both the vendor and MSPs.
* Communicate the advantages of participating in the program, such as co-selling opportunities, MDFs, training, and support.

**2. Develop a Comprehensive Partner Portal**

* Create a user-friendly partner portal that centralizes all relevant program information, resources, and tools for MSPs.
* Ensure the portal includes marketing materials, sales enablement resources, training modules, and a way to request MDFs or submit co-selling opportunities.

**3. Offer Comprehensive Training and Certification Programs**

* Provide MSPs with training opportunities and certifications to help them become proficient in selling, implementing, and supporting your products or services.
* Regularly update training materials and offer webinars, workshops, or online courses to ensure MSPs stay informed about the latest product features, industry trends, and best practices.

**4. Implement a Tiered Partner Program Structure**

* Develop a tiered program structure that rewards MSPs based on their commitment, expertise, and performance.
* Include incentives, such as increased MDFs or co-selling support, for MSPs that achieve higher tiers or demonstrate exceptional performance.

**5. Establish a Clear MDF Application and Approval Process**

* Design a straightforward process for MSPs to request MDFs, including guidelines for proposal submissions, approval criteria, and reporting requirements.
* Provide templates and examples of successful MDF proposals to help guide MSPs in crafting their requests.

**6. Foster Collaboration and Communication**

* Encourage open communication between your vendor team and MSP partners through regular check-ins, webinars, or partner events.
* Provide a platform or forum for MSPs to share their experiences, successes, and challenges with one another, fostering a sense of community within your channel program.

**7. Monitor Program Performance and Iterate**

* Regularly evaluate the performance of your channel program, gathering feedback from MSP partners to identify areas for improvement.
* Make adjustments to your program based on feedback and changing market conditions, ensuring that it remains relevant and beneficial for both your company and your MSP partners.


# Peer Groups and Accountability Groups

How MSPs use peer groups and accountability groups to benchmark, learn, and grow — with the benefits and the risks.

Many MSP owners accelerate their growth by joining structured communities of their peers. This section covers two related formats — peer groups and accountability groups — including the benefits they offer and the risks to weigh.

### In this section

{% content-ref url="/pages/StyWHx8mQGtGfa0tPkFe" %}
[Peer Groups for MSPs Benefits and Potential Risks](/msp-relationships/peer-groups-and-accountability-groups/peer-groups-for-msps-benefits-and-potential-risks)
{% endcontent-ref %}

{% content-ref url="/pages/19ZqTqKVZxQBqnqRGrD3" %}
[Accountability Groups: Fostering Growth and Success for MSPs](/msp-relationships/peer-groups-and-accountability-groups/accountability-groups-fostering-growth-and-success-for-msps)
{% endcontent-ref %}


# Peer Groups for MSPs Benefits and Potential Risks

Peer groups offer MSPs a great way to connect with fellow professionals, exchange ideas, and learn from each other's experiences. They're an excellent resource for staying up-to-date with industry trends and getting insights into common challenges. However, it's also important to be aware of potential risks associated with peer groups, like the risk of creating echo chambers.

#### Knowledge Sharing and Collaboration

When MSPs get together in peer groups, they can share their knowledge and expertise, tapping into a diverse range of experiences. These groups are perfect for learning about new technologies and finding innovative solutions to challenges. By working together, MSPs can develop best practices and find more efficient ways to meet clients' needs.

#### Benchmarking and Performance Improvement

Joining a peer group allows MSPs to compare their performance with other providers. By looking at metrics, services, and processes, MSPs can identify what they're good at and what needs improvement. This data-driven approach helps set realistic growth targets and make smart decisions about resources and planning.

#### Networking and Business Development

Peer groups are also great for networking, helping MSPs build relationships with potential partners, vendors, and clients. These connections can lead to new opportunities, collaborations, and strategic alliances that contribute to an MSP's growth and success.

#### Emotional Support and Shared Experiences

Running an MSP can be tough, especially for smaller businesses or those new to the industry. Peer groups offer a supportive environment where MSPs can talk about their struggles, celebrate their successes, and learn from one another. This sense of camaraderie can help reduce stress and encourage personal and professional growth.

#### Potential Risk: Echo Chambers

While peer groups offer many benefits, they can also pose a risk if they turn into echo chambers. When group members only share similar opinions and experiences, it can limit the diversity of ideas and stifle creativity. MSPs should be aware of this risk and make an effort to seek out different perspectives and experiences to avoid falling into the echo chamber trap.

In conclusion, peer groups can play a vital role in an MSP's growth and success by providing a platform for learning, collaboration, and networking. By actively participating in these groups, MSPs can gain valuable insights and improve their service offerings. However, it's essential to be aware of the potential risks and ensure a diverse range of ideas and experiences are considered.

> **Find some Peer Groups here:** <https://docs.themspkb.com/resources/communities/peer-groups>


# Accountability Groups: Fostering Growth and Success for MSPs

Accountability groups serve as a powerful tool for MSPs to stay focused on their goals, maintain motivation, and foster growth. These groups comprise like-minded professionals who commit to holding each other accountable for achieving individual and collective objectives. In this section, we'll discuss the benefits of participating in accountability groups and how they can contribute to the success of MSPs.

#### Goal Setting and Progress Tracking

One of the key features of an accountability group is the emphasis on setting specific, measurable, achievable, relevant, and time-bound (SMART) goals. Members share their goals with the group and regularly update their progress, allowing for valuable feedback and advice from peers. This structured approach to goal setting helps MSPs maintain focus and work diligently towards their targets, ultimately contributing to their long-term success.

#### Collective Wisdom and Problem Solving

Accountability groups bring together MSP professionals with varying backgrounds and expertise, creating a wealth of collective wisdom. By sharing challenges and discussing potential solutions, group members can benefit from the experiences of their peers and gain new perspectives. This collaborative problem-solving approach helps MSPs address issues more effectively, leading to better service offerings and client satisfaction.

#### Mutual Support and Encouragement

Running an MSP can be demanding and, at times, overwhelming. Accountability groups provide a supportive environment for MSPs to share their struggles and celebrate their achievements. Members can draw on each other's strengths and learn from their experiences, fostering a sense of camaraderie that can alleviate stress and promote personal and professional growth.

#### Networking and Relationship Building

Participating in accountability groups offers MSPs the opportunity to network and build relationships with fellow professionals. These connections can lead to new business opportunities, partnerships, and collaborations that contribute to an MSP's growth and success.

#### Avoiding Procrastination and Staying Motivated

Accountability groups can help keep MSPs motivated and focused on their goals by providing regular check-ins and progress updates. The sense of responsibility that comes from reporting to a group of peers can be a powerful deterrent against procrastination, encouraging members to stay on track and make consistent progress toward their objectives.

In conclusion, accountability groups can be a valuable resource for MSPs, providing a platform for goal setting, problem solving, mutual support, and networking. By actively participating in these groups and leveraging the collective wisdom and support of their peers, MSPs can stay focused on their objectives and build a strong foundation for long-term success in the industry.


# AI in the MSP Stack

Practical guide to understanding where AI actually shows up in MSP tools, how it differs from automation, and how to assess claims responsibly.

### **Introduction**

AI features are appearing across MSP tools, but marketing often exaggerates or blurs what they can really do. This section provides a framework to:

* Separate vendor claims from actual capability.
* Understand where AI fits into MSP operations today.
* Recognize where human oversight remains essential.
* Evaluate new AI claims with a consistent model.

### **Why Accuracy Matters**

MSPs sit at the intersection of finance, security, and client trust. Misunderstanding AI—by overselling to clients or overbuying from vendors—creates risks such as:

* Spending on features with little or no ROI.
* Gaining false confidence in security or monitoring.
* Automating workflows based on weak or noisy signals.
* Making promises to clients that AI can’t deliver.

### **AI in MSP Work: What It Is (and Isn’t)**

In this guide, AI is treated as an **augmentation layer**, not a replacement. It can:

* Automate repetitive triage and categorization.
* Spot patterns humans miss (e.g., predictive failures, anomalies).
* Summarize and surface knowledge efficiently.
* Assist decision-making while leaving final calls to staff.

It is **not**:

* A system for full autonomy over client environments.
* A “magic fix” that eliminates human review.
* A catch-all label for any form of automation.

### **Audience**

This section is for MSP operators and decision-makers who:

* Need to evaluate AI features in existing tools.
* Want clarity on where AI helps and where it falls short.
* Must explain AI’s role and limits to clients and colleagues.

***

### How This Section Works

The introduction leads into four short modules:

1. [**AI vs. Automation**](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) – clarifies the difference, with examples.
2. [**Where It Shows Up**](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up) – identifies where AI is embedded today.
3. [**What It Can’t Do Yet**](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) – explains current blind spots and risks.
4. [**Where We’re Going**](/ai-for-msps/ai-in-the-msp-stack/where-were-going) – a grounded look at what may come next.

Each module builds on the previous. Read in sequence for a clear progression.

***


# AI vs. Automation

Understand the technical difference between deterministic automation and probabilistic AI, with decision frameworks for MSP workflows.

### Introduction

Automation executes predefined rules or scripts. AI adapts outputs based on patterns in data, but is probabilistic, not deterministic. Understanding this distinction prevents false expectations and helps choose the right tool for each workflow.

### **Technical Difference**

| Characteristic   | Automation                   | AI                                  |
| ---------------- | ---------------------------- | ----------------------------------- |
| **Process**      | Follows predefined rules     | Learns patterns from data           |
| **Output**       | Same result every time       | Varies based on input patterns      |
| **Failure Mode** | Breaks predictably           | "Confidently wrong" answers         |
| **Best For**     | Repetitive, rule-based tasks | Pattern recognition, judgment calls |

### **MSP Workflow Examples**

**Automation in Action:**

* RMM script restarts failed services across 500 endpoints
* PSA creates tickets from monitoring alerts using set rules
* Backup verification runs same checks nightly

**AI in Action:**

* Ticket triage groups similar issues based on description patterns
* Security tools flag unusual login patterns (not specific rules)
* Documentation search suggests KB articles based on ticket content

{% hint style="info" %}

#### *Why AI Outputs Vary*

Modern AI systems (e.g., GPT, Copilot) use *Transformers*—models built entirely on “attention” rather than fixed sequences. Instead of following a strict rule, they weight different parts of input data to predict what comes next. That’s why two similar tickets can produce slightly different AI triage outputs: the system is making probabilistic judgments, not running a script.

For the research behind these terms, see [**Foundational AI Concepts**](/ai-for-msps/foundational-ai-concepts): [Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism), [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer), and [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models).
{% endhint %}

### **Decision Framework**

**Use automation when:**

* Process has clear, consistent rules
* Same input should always produce same output
* Failure impact is predictable and recoverable

**Use AI when:**

* Pattern recognition improves outcomes
* Human judgment would normally be required
* You can verify outputs before acting

### **Common Mistakes**

MSPs in various community spaces regularly state many “AI” features are just automation in disguise.

* **Treating AI like automation:** Expecting consistent outputs leads to over-reliance
* **Treating automation like AI:** Assuming scripts can handle edge cases they weren't designed for

### **Implementation Checklist**

* [ ] Classify each workflow: rule-based or pattern-based?
* [ ] Define success criteria and failure recovery procedures
* [ ] Train staff on when to trust outputs vs verify manually
* [ ] Set up monitoring for both false positives and missed cases

**Key terms**: *deterministic automation*, *probabilistic AI*, *pattern recognition*, *human-in-the-loop*.


# Where It Shows Up

Specific AI tools and features available in PSA/RMM platforms, with costs, capabilities, and vendor comparison for MSP decision-makers.

### Introduction

AI features are now embedded across PSA, RMM, and specialized tools serving MSPs. Some add measurable value, others are rebranded automation. This section aims to compare what’s available, where it fits, and how to evaluate claims responsibly.&#x20;

***

### **Example Implementation Categories**

<table><thead><tr><th width="143.48828125">Category</th><th width="180.53515625">Strength</th><th width="192.22265625">Limitation</th><th>Examples</th></tr></thead><tbody><tr><td><strong>General AI Assistants</strong></td><td>Flexible, cheap</td><td>No MSP-specific context, limited business logic</td><td>ChatGPT, Claude, Microsoft Copilot (often approved due to no-training policy)</td></tr><tr><td><strong>PSA-Native Features</strong></td><td>Built into existing workflows, access to client-specific data, bi-directional sync</td><td>Vendor lock-in, limited to single PSA ecosystem</td><td>Atera, ConnectWise, Autotask, Syncro</td></tr><tr><td><strong>Specialized AI Tools</strong></td><td>Fill gaps PSA/RMM don’t cover</td><td>Fragmented ecosystem, requires integration</td><td>Mizo AI, zofiQ, Neo Agent/Cooper Copilot, Rewst, N8N, DialPad, Nextiva, Riscosity, Augmentt, Auvik</td></tr></tbody></table>

***

### **Example PSA Platform Comparison**

*Something missing or incorrect? Make an edit! \*Still needs sources added.*

<table><thead><tr><th width="126.27734375">Platform</th><th width="208.09375">AI Features</th><th width="138.66015625">Cost Model</th><th width="140.65234375">ROI Claims</th><th>Data Handling</th></tr></thead><tbody><tr><td><strong>Atera</strong></td><td>Diagnostics, script gen, ticket summarization, alert analysis</td><td>$129+/tech/mo</td><td>Faster troubleshooting</td><td>SOC 2, ISO 27001</td></tr><tr><td><strong>ConnectWise Sidekick</strong></td><td>Triage, email replies, sentiment tracking, scripting</td><td>~$1,042/mo saved per tech</td><td>5 min saved/ticket</td><td>No-training, secure access</td></tr><tr><td><strong>Autotask PSA</strong></td><td>Categorization, summaries, polished comms</td><td>Seat-based</td><td>15–30% more tickets/tech</td><td>DPA, least-privilege</td></tr><tr><td><strong>Syncro</strong></td><td>Categorization, summaries, responses</td><td>Seat-based</td><td>Limited scope</td><td>Review privacy policy</td></tr></tbody></table>

***

### Agentic AI Explained

Agentic AI is marketed as the “next step” beyond automation. In practice, it chains multiple probabilistic decisions together. That makes it more flexible, but also more fragile.

**Key Points**

* Works by chaining LLM-driven tasks (interpret, act, summarize)
* Can save hours in triage and resolution
* Compounds risk if unchecked: one bad step can cascade
* Requires explicit rollback and human sign-off policies

*Example failure*: AI suggests a reboot script for all endpoints based on one vague ticket. Without review, this cascades into widespread disruption.

***

#### Bottom Line

MSPs now have a broad menu of AI features across PSA, RMM, and specialized tools. Real ROI is possible, but only when features are evaluated against data policies, integration depth, and oversight requirements. Agentic AI should be treated as a junior tech, useful and fast, but prone to confident mistakes without supervision.


# Implementation & ROI

#### Current ROI Reality

MSPs across Reddit and vendor reports note measurable benefits:

* **Resolution Speed:** 30–60% faster overall, up to 60% faster for P1 tickets
* **Productivity:** 15–30% more tickets per tech (≈ 2 FTEs saved)
* **Escalation Reduction:** 80–86% fewer L2 handoffs
* **Alert Management:** 80–90% fewer false positives (example: ConnectWise RMM)

*(Source citations still needed — mix of vendor claims + MSP peer reports.)*

***

#### Common Implementation Mistakes

Most AI rollout failures come not from the tools, but from how they’re deployed. Avoiding common mistakes prevents wasted spend and broken processes.

**Strategic Errors**

* Expecting AI to solve non-existent processes\
  *e.g., deploying AI triage when categories are inconsistent = garbage in, garbage out*
* Lack of measurable objectives or success criteria\
  *e.g., rolling out summaries without tracking resolution time or escalation rates*
* Choosing generic tools without MSP context\
  *e.g., using ChatGPT for ticket notes instead of a PSA-integrated assistant*

**Technical Errors**

* Insufficient data quality before AI implementation\
  *e.g., alert fatigue from noisy monitoring data means AI just replicates noise faster*
* Poor integration causing duplicate data entry\
  *e.g., AI summaries don’t sync both ways, forcing manual copy-paste*
* Missing human verification workflows\
  *e.g., allowing AI scripts to run without engineer review → confidently wrong fixes*

***

#### Evaluation Framework

Ask before enabling any AI feature:

* **Data boundaries:** Does the DPA explicitly state *no training* on client data?
* **Integration depth:** Is it PSA/RMM-native or just API glue?
* **Cost model:** Per-tech, usage-based, or bundled?
* **Auditability:** Is AI decision-making logged for review?

***

#### Checklist

* [x] Confirm process exists and is consistent
* [x] Define measurable goals
* [x] Verify clean data and integrations
* [x] Keep human-in-the-loop for critical workflows

***

#### Bottom Line

AI won’t fix broken workflows. Success comes from clean processes, clear metrics, and disciplined human verification. The biggest ROI gains come when MSPs treat AI as an augmentation layer, not a replacement for process.


# What It Cant Do Yet

AI brings efficiency but has hard limits that create operational and legal risks. Misuse or overconfidence can damage client trust, reduce staff capability, and increase liability.

### Introduction

AI features in MSP tools are marketed as powerful, but their limits are real. These systems generate patterns, not certainty, and they lack context about individual client environments. Without safeguards, AI creates new risks: false confidence, broken processes, and legal exposure. This section outlines where AI fails today and how MSPs can mitigate those gaps.

***

### Technical Limitations

* **Hallucination (Confident Wrong Answers):** AI can generate plausible but incorrect guidance.\
  ***Example:*** Suggests PowerShell commands that don’t exist.\
  ***Risk:*** Techs may copy errors into production without verification.
* **Context Boundaries:** Generic models lack awareness of client-specific environments.\
  ***Example:*** Suggests a generic “Outlook fix” that conflicts with a client’s M365 setup.\
  ***Risk:*** Misaligned advice drives ticket volume higher.

***

### Client Impact

* **False Confidence in Security**\
  AI-based detection may over-alert or under-alert. While techs chase false positives, real threats can slip through.
* **Expectation Gap**\
  Clients may believe AI “fixes” issues automatically. In reality, it only suggests. Overselling creates liability when AI misses something.
* **Compliance Mismatch**\
  Some AI tools cannot provide legally required explanations for automated actions. Outputs may be valid technically but unacceptable contractually.

***

### Operational Risks

<table><thead><tr><th width="213.42578125">Risk</th><th width="250.1328125">Impact on MSP</th><th>Safeguard</th></tr></thead><tbody><tr><td><strong>Skill erosion</strong></td><td>Techs rely on AI instead of learning troubleshooting</td><td>Maintain manual training labs</td></tr><tr><td><strong>Over-automation</strong></td><td>AI runs unchecked, compounding errors</td><td>Keep human-in-the-loop checkpoints</td></tr><tr><td><strong>Vendor lock-in</strong></td><td>Proprietary AI becomes dependency</td><td>Negotiate portability rights</td></tr><tr><td><strong>Audit gaps</strong></td><td>AI decisions not logged</td><td>Require exportable audit trails</td></tr></tbody></table>

***

### Safety Checklist Before Enabling AI

* [x] Review the Data Processing Agreement (look for **no-training** guarantees)
* [x] Confirm liability limits in the contract — who pays if AI fails?
* [x] Identify which client data will be processed and where (data residency)
* [x] Establish rollback steps if AI guidance is wrong
* [x] Train staff to verify outputs and document misses
* [x] Maintain manual fallback workflows for critical services

**Key terms**: *hallucination*, *liability squeeze*, *data processing agreement*, *human-in-the-loop*, *false positive*.

***

#### Bottom Line

AI can augment MSP operations, but it cannot replace human oversight or compliance guardrails. The risks are operational as much as technical: hallucinations, blind spots, and expectation gaps must be managed deliberately.

👉 See [**Where We’re Going**](/ai-for-msps/ai-in-the-msp-stack/where-were-going) for how these risks are evolving into regulatory and contract requirements.


# Where We're Going

Regulatory trends, compliance requirements, and preparation strategies for MSPs adopting AI tools in client environments.

### Regulatory Landscape

AI adoption in MSP environments is being shaped less by feature releases and more by compliance pressure. Early preparation around governance, explainability, and data residency reduces risk and builds trust.

#### Active Now

* **GDPR Article 45:** restricts EU data transfer.
  * **Practical step:** Ask AI providers for clear data residency disclosures in their DPAs to avoid liability if processing occurs outside approved regions.
* **CCPA:** requires client notification when processing locations change.
  * Practical step: Keep an eye on AI provider change logs and be ready to update contracts if regions shift.
* **Sovereign cloud mandates:** apply to some public sector clients.
  * Practical step: Confirm whether your AI tools can meet these requirements, since generic offerings may be disqualified.

#### Coming Soon

* **EU AI Act:** introduces transparency rules for automated decisions.
  * **Practical step:** Be prepared to log AI-generated recommendations so they can be reviewed if challenged.
* **GDPR Article 22:** protects the “right to explanation” for automated actions.
  * **Practical step:** Keep justification logs for AI-driven triage or routing decisions, as auditors may request them.
* **HIPAA and SOX expansions:** will likely extend to AI usage.
  * **Practical step:** Treat AI logs as in-scope for compliance reviews, similar to other system records.

***

### Client Audit Evolution

**Now being asked:**

* Which AI tools touch our data?
* Where is processing performed?
* What happens if AI is wrong?

**Emerging requirements:**

* DPA documentation for AI tools
* Staff AI training records
* Incident response procedures for AI misfires
* Shadow AI detection policies

***

### Vendor Contract Shifts

**Current gaps:**&#xB9;

* 92% of AI vendors claim training rights over customer data
* Liability caps = monthly fee only
* No performance warranties

**Expected changes:**

* Default “no-train” modes
* Mutual liability caps
* Model portability clauses
* Regional data residency guarantees

¹ [*Source: Stanford Law review of AI vendor contracts, 2024*](https://law.stanford.edu/2025/03/21/navigating-ai-vendor-contracts-and-the-future-of-law-a-guide-for-legal-tech-innovators/)

***

### **Technology Development Trends**

*Note: These are projections based on current vendor roadmaps and MSP community discussions, not guaranteed outcomes.*

**Near-term (12–18 months):**

* PSA/RMM-native AI replacing add-ons
* Voice → ticket transcription standard (DialPad, Nextiva)
* Shadow AI detection built into SaaS management

**Mid-term (18–36 months):**

* Controlled “agentic AI” pilots (autonomous but rollback-capable)
* Cross-platform orchestration (PSA + RMM + KB)
* Predictive analytics for resource planning (*only if PSA data is clean*)

**Key terms**: *data residency*, *AI Act compliance*, *vendor lock-in*, *agentic AI*, *human+AI service delivery*.

***

### **Bottom Line**

AI in MSP stacks will be audited, explained, and contract-bound before it’s trusted. The winning MSP position is not “AI-first” but “AI-safely”: prove governance, maintain human expertise, and give clients confidence that automation won’t outpace accountability.

{% hint style="info" %}
See the [**Strategic Positioning**](/ai-for-msps/ai-in-the-msp-stack/where-were-going/positioning-and-preparation#strategic-positioning) section on the next page for how MSPs can turn these external pressures into client-facing strengths.
{% endhint %}


# Positioning & Preparation

### Introduction

MSPs can't win on AI by being “first.” The opportunity is to be the **trusted partner who makes AI safe**: governed, explainable, and client-ready. SMBs will lean on their MSP not for AI hype, but for assurance that new tools won’t create compliance, liability, or trust problems.

***

### **Strategic Positioning**

**MSP Opportunity:** Position as the "safe AI adoption partner" for SMBs by:

* Providing governance expertise clients lack internally
* Managing AI vendor relationships and compliance
* Offering hybrid human+AI service delivery models
* Building AI literacy among client staff

***

### **Preparation Framework**

**Policy:**

* [ ] Draft AI Acceptable Use Policy
* [ ] Create client AI disclosure template
* [ ] Document shadow AI detection

**Vendor:**

* [ ] Audit all AI features in stack
* [ ] Review DPAs for training opt-outs
* [ ] Negotiate liability + residency terms

**Staff:**

* [ ] Train on **output verification** (not just prompts)
* [ ] Add AI steps to incident response
* [ ] Run tabletop exercises for AI misfires

**Ongoing:**

* [ ] Track false positives and misses
* [ ] Log AI-assisted actions for audit
* [ ] Maintain manual fallback for critical workflows

***

#### Bottom Line

MSPs win client trust not by selling AI as revolutionary, but by proving **it won’t outpace accountability.** Strategic positioning is simple: govern it, explain it, and keep people in the loop. The MSP that makes AI safe is the MSP that keeps the client.

{% hint style="info" %}
These steps respond directly to the regulatory, audit, and vendor trends outlined in [**Where We’re Going**](/ai-for-msps/ai-in-the-msp-stack/where-were-going)
{% endhint %}


# Foundational AI Concepts

Plain-language reference pages for the foundational research concepts behind the AI tools in the MSP stack — transformers, attention, BERT, large language models, in-context learning, foundation model

### Why this section exists

Elsewhere in this KB we treat AI as an **augmentation layer** and focus on how to evaluate it responsibly (see [AI in the MSP Stack](/ai-for-msps/ai-in-the-msp-stack) and [AI Security](/ai-for-msps/ai-security)). This section goes one layer deeper: it explains the **core research ideas** that make tools like ChatGPT, Copilot, and the "AI" features in RMM/PSA platforms work.

You do not need a machine-learning background to sell, buy, or govern these tools — but a working mental model of *why AI outputs vary*, *why models hallucinate*, and *why bigger is not automatically better* helps you separate real capability from marketing. Each page is a self-contained **entity page**: a summary, a plain-language explanation, why it matters for MSPs, related concepts, noted contradictions between the source papers, and a link to the original research.

{% hint style="info" %}
This section is **descriptive, not prescriptive**. It explains what these concepts *are* so you can understand the tools you already use — it is not a tutorial on building models.
{% endhint %}

### The five papers behind modern AI

Every mainstream AI assistant in use today descends from a short lineage of research papers. Read in order, they tell the story of how we got from spell-check to ChatGPT:

| Year | Paper                                                                                   | Concept it introduced                   | Entity page                                                                                                                                                             |
| ---- | --------------------------------------------------------------------------------------- | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 2017 | [Attention Is All You Need](https://arxiv.org/pdf/1706.03762)                           | The Transformer architecture            | [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer)                                                                                           |
| 2018 | [BERT](https://arxiv.org/pdf/1810.04805)                                                | Bidirectional pretraining + fine-tuning | [BERT](/ai-for-msps/foundational-ai-concepts/bert) · [Pretraining & Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning)                     |
| 2020 | [Language Models are Few-Shot Learners (GPT-3)](https://arxiv.org/pdf/2005.14165)       | Scale + in-context learning             | [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning) |
| 2021 | [On the Opportunities and Risks of Foundation Models](https://arxiv.org/pdf/2108.07258) | The term "foundation model"             | [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models)                                                                                            |
| 2022 | [Training LMs to Follow Instructions (InstructGPT)](https://arxiv.org/pdf/2203.02155)   | Alignment via human feedback (RLHF)     | [RLHF & Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment)                                                                                            |

### How the concepts connect

```
Attention ──▶ Transformer ──┬──▶ BERT (bidirectional, fine-tuned)
                            │
                            └──▶ GPT-3 / LLMs (autoregressive, in-context learning)
                                     │
                                     ├──▶ Foundation Models (the category + its risks)
                                     └──▶ RLHF / InstructGPT (aligning models to humans)
```

The [Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism) is the engine; the [Transformer](/ai-for-msps/foundational-ai-concepts/transformer) is the machine built around it. From that same machine, two families branched: **BERT-style** models that read text bidirectionally and are *fine-tuned* per task, and **GPT-style** [large language models](/ai-for-msps/foundational-ai-concepts/large-language-models) that generate text left-to-right and learn tasks *in-context*. As these models grew general enough to underpin everything, the research community named the category [foundation models](/ai-for-msps/foundational-ai-concepts/foundation-models) — and warned about its risks. [RLHF](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment) was the technique that turned a raw text-predictor into a helpful assistant.

### Where the papers disagree

These papers are a lineage, but they are not a consensus. The most useful tensions to understand:

* **Bidirectional vs. one-directional.** [BERT](/ai-for-msps/foundational-ai-concepts/bert) argues that reading text in both directions at once is necessary for strong language understanding and explicitly frames left-to-right-only models as limited. GPT-3 keeps the left-to-right approach and still reaches state-of-the-art results — suggesting the limitation BERT identified was not fatal.
* **Fine-tuning vs. in-context learning.** BERT's whole paradigm is *fine-tune a copy of the model for each task*. [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) pushes back, listing the downsides of fine-tuning and showing a model can often learn a task from a few examples in the prompt with **no weight updates at all**.
* **Scale vs. alignment.** GPT-3's headline is *bigger is better*. [InstructGPT](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment) directly complicates this: human raters preferred a **1.3B-parameter aligned model over the 175B GPT-3 — a model over 100× larger**, showing that *how* you train can beat *how big* you build.
* **Capability optimism vs. risk caution.** GPT-3 celebrates broad capability; the [foundation models](/ai-for-msps/foundational-ai-concepts/foundation-models) paper reframes that same generality as a concentration of risk — one flawed base model propagating its flaws to everything built on top.

Each entity page carries a **Contradictions & debates** section with the specifics.

### Start here

If you are new to the topic, read in this order: [Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism) → [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) → [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) → [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning) → [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment). Then loop back to [BERT](/ai-for-msps/foundational-ai-concepts/bert), [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning), and [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) for the full picture.

***

**Key terms**: *transformer*, *attention*, *large language model (LLM)*, *pretraining*, *fine-tuning*, *in-context learning*, *foundation model*, *RLHF*, *alignment*.


# Attention Mechanism

The attention mechanism — how modern AI models decide which parts of the input matter most — explained in plain terms for MSP operators, with a link to the 2017 paper that made it the core of the Tran

### Summary

**Attention** is the technique that lets an AI model, when processing one word, look back at every other word in the input and decide how much each one matters. Introduced as the sole building block of the [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) in the 2017 paper *Attention Is All You Need*, it replaced the older approach of reading text strictly one word at a time. Attention is the reason a model can connect "it" in a sentence back to the noun it refers to twenty words earlier — and, ultimately, the reason today's AI assistants can hold context across a long ticket or document.

### In plain terms

Imagine reading a support ticket and, for every word, instantly highlighting the other words most relevant to understanding it. When you hit "restart," you glance at "server" and "failed"; when you hit "it," you glance back at whatever "it" refers to. **Self-attention** does exactly this, mathematically, for every word against every other word, all at once.

The mechanism works with three roles for each word, often called **query, key, and value**:

* The **query** is "what am I looking for?"
* The **key** is "what do I offer?"
* The **value** is the actual information passed along once a match is found.

A word's new representation becomes a weighted blend of the values of all the words it "attended" to. The paper also uses **multi-head attention** — running several attention operations in parallel — so the model can track different kinds of relationships at once (grammar, subject matter, tone).

Crucially, attention looks at all words **in parallel** rather than in sequence. That parallelism is what made these models practical to train at large scale.

### Why it matters for MSPs

* **It explains why AI outputs vary.** The [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) page notes that Transformers "weight different parts of input data to predict what comes next." Attention *is* that weighting. Because the weights are computed from data rather than fixed rules, two near-identical tickets can yield slightly different results — this is probabilistic AI, not deterministic automation.
* **It explains context limits.** Attention compares every word to every other word, so cost grows sharply with input length. This is a root cause of the **context window** limits you hit when pasting a huge log or document into an AI tool.
* **It demystifies the marketing.** When a vendor says their feature "understands context," they almost always mean an attention-based model is weighting your input — useful to know when you [evaluate the claim](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up).

### Related concepts

[Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [BERT](/ai-for-msps/foundational-ai-concepts/bert) · [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning)

**In the MSP KB:** [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) · [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet)

### Contradictions & debates

* The 2017 paper's title — *Attention Is All You Need* — is a deliberate claim that the recurrence and convolution mechanisms dominant before it were **unnecessary**. Among the papers in this section there is no disagreement on this point; every later model here is built on attention. The "contradiction" is historical: attention overturned the prior orthodoxy that sequence models required recurrence.
* A subtler debate the paper opened: attention shows *which* words a model weighted, which is sometimes marketed as "explainability." Later research disputes how much attention weights truly *explain* a model's reasoning. Treat attention-based "explanations" with the same caution the [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) page applies to AI outputs generally.

### Source paper

Vaswani et al. (2017), *Attention Is All You Need* — <https://arxiv.org/pdf/1706.03762>

***

**Key terms**: *attention*, *self-attention*, *query/key/value*, *multi-head attention*, *context window*.


# Transformer Architecture

The Transformer — the neural-network architecture that underpins virtually every modern AI assistant — explained for MSP operators, with a link to the 2017 paper that introduced it.

### Summary

The **Transformer** is the neural-network design introduced in the 2017 paper *Attention Is All You Need*. It builds an entire model out of the [Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism) and simple feed-forward layers, discarding the step-by-step recurrence that earlier language models relied on. Because it processes all words in parallel, it can be trained on enormous datasets efficiently — which is what made today's [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) possible. The "GPT" in ChatGPT stands for **Generative Pre-trained Transformer**, and Microsoft Copilot, [BERT](/ai-for-msps/foundational-ai-concepts/bert), and nearly every current AI feature in the MSP stack are Transformers under the hood.

### In plain terms

Earlier models read a sentence like a person reading aloud — one word at a time, carrying a running memory forward. That was slow and tended to "forget" the start of a long passage by the time it reached the end.

The Transformer does something different. It looks at the whole input at once and uses [attention](/ai-for-msps/foundational-ai-concepts/attention-mechanism) to let every word directly consult every other word. Key pieces of the design:

* **Encoder and decoder stacks.** The original design had two halves — an *encoder* that reads and represents the input, and a *decoder* that generates output. The base model stacked six of each.
* **Multi-head attention.** Several attention operations run in parallel, each tracking a different kind of relationship in the text.
* **Positional encoding.** Because the model reads all words at once (with no inherent sense of order), it adds a signal marking each word's position, so "server restarted the service" isn't confused with "service restarted the server."
* **Feed-forward layers and residual connections.** Standard neural-network plumbing that processes and stabilizes the attention output.

Later models often keep only one half: [BERT](/ai-for-msps/foundational-ai-concepts/bert) is **encoder-only** (built to *understand* text), while GPT-style models are **decoder-only** (built to *generate* text).

### Why it matters for MSPs

* **It is the thing behind "the AI."** When a PSA/RMM vendor, a documentation tool, or a security product advertises AI, it is almost certainly a Transformer. Knowing the one architecture demystifies the whole category.
* **It explains the cost and speed trade-offs.** Transformers are expensive to run because attention compares everything to everything. That cost is why AI features carry per-seat or per-token pricing, and why large inputs are slower and pricier — relevant when you model [implementation and ROI](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up/implementation-and-roi).
* **It explains why the same core tech shows up everywhere.** A single architecture powering search, chat, code, and security tooling is exactly the *homogenization* the [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) page describes — a convenience that also concentrates risk.

### Related concepts

[Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism) · [BERT](/ai-for-msps/foundational-ai-concepts/bert) · [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) · [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning)

**In the MSP KB:** [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) · [AI in the MSP Stack](/ai-for-msps/ai-in-the-msp-stack)

### Contradictions & debates

* The Transformer paper's core claim — that **recurrence is unnecessary** — was a direct challenge to the prevailing RNN/LSTM approach of its time. History sided with the Transformer; none of the other papers in this section dispute it.
* A genuine fork appears *downstream* of the Transformer, not within it: the [BERT](/ai-for-msps/foundational-ai-concepts/bert) lineage and the [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) lineage take the same architecture in incompatible directions — bidirectional-and-fine-tuned versus left-to-right-and-prompted. See those pages for the disagreement.

### Source paper

Vaswani et al. (2017), *Attention Is All You Need* — <https://arxiv.org/pdf/1706.03762>

***

**Key terms**: *Transformer*, *encoder/decoder*, *decoder-only*, *positional encoding*, *multi-head attention*, *GPT (Generative Pre-trained Transformer)*.


# BERT

BERT — the bidirectional language model that reshaped how machines understand text — explained for MSP operators, including how it differs from GPT-style models, with a link to the 2018 paper.

### Summary

**BERT** (Bidirectional Encoder Representations from Transformers) is a 2018 model from Google that learns language by reading text in **both directions at once** — considering the words before *and* after a given word — rather than strictly left to right. It popularized the two-step recipe of [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning): train one general model on massive unlabeled text, then adapt small copies of it to specific tasks. BERT dominated language-*understanding* benchmarks and still powers a great deal of behind-the-scenes AI — search relevance, classification, intent detection — even though the more visible chat assistants come from the rival GPT lineage of [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models).

### In plain terms

BERT is an **encoder-only** [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer): it is built to *read and represent* text, not to generate it. Its training used two clever tricks:

* **Masked Language Modeling (MLM).** During training, random words are hidden and the model must guess them from the surrounding context on *both* sides. Fill-in-the-blank forces genuine two-directional understanding — this is BERT's signature idea.
* **Next Sentence Prediction (NSP).** The model is shown two sentences and learns to judge whether the second naturally follows the first — teaching it relationships between sentences.

The paper released two sizes: **BERT-Base** (\~110 million parameters) and **BERT-Large** (\~340 million). Both were pretrained on English Wikipedia and a large book corpus, then fine-tuned to set new records across a suite of language-understanding tasks (the GLUE benchmark, question answering, and more).

### Why it matters for MSPs

* **Not all "AI" is a chatbot.** Much of the AI quietly embedded in MSP tools — routing a ticket to the right queue, tagging a document, detecting the intent of an email, ranking KB search results — is a classification job that a BERT-style model does cheaply and reliably. Recognizing this helps you tell *workhorse* AI from *generative* AI when [evaluating where it shows up](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up).
* **Fine-tuning means your data may train the model.** BERT's paradigm involves adapting a model on task-specific data. When a vendor offers a model "tuned on your tickets," that is fine-tuning — which makes the **no-training guarantees** and data-handling questions on the [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) and [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) pages directly relevant.
* **Understanding ≠ generating.** BERT reads well but does not write fluent long-form answers. Knowing which kind of model sits behind a feature sets correct expectations for clients.

### Related concepts

[Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [Attention Mechanism](/ai-for-msps/foundational-ai-concepts/attention-mechanism) · [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning) · [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models)

**In the MSP KB:** [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) · [Where It Shows Up](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up)

### Contradictions & debates

* **Bidirectional (BERT) vs. one-directional (GPT).** BERT's central argument is that reading text left-to-right *only* is a real limitation, and that bidirectional context is needed for strong understanding — a point the paper makes explicitly against earlier GPT-style models. The [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) lineage never adopted bidirectionality and still reached strong, sometimes state-of-the-art results, showing the limitation was surmountable by scale and generation-first design. Both approaches remain in use for different jobs; the "contradiction" resolved into a **division of labor**, not a winner.
* **Fine-tuning vs. in-context learning.** BERT assumes you *fine-tune* a separate model per task. Two years later, [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) argued that fine-tuning has real downsides (it needs labeled data and can latch onto spurious patterns) and demonstrated learning tasks from a few prompt examples with no weight changes — see [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning). This is the sharpest methodological disagreement among the five papers.

### Source paper

Devlin et al. (2018), *BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding* — <https://arxiv.org/pdf/1810.04805>

***

**Key terms**: *BERT*, *bidirectional*, *encoder-only*, *masked language modeling*, *next sentence prediction*, *GLUE benchmark*.


# Pretraining and Fine-Tuning

The pretrain-then-fine-tune paradigm — train one general model, then adapt it to specific tasks — explained for MSP operators, with links to the BERT and GPT-3 papers that defined and then challenged

### Summary

**Pretraining and fine-tuning** is the two-stage recipe that made modern language AI practical. First, **pretrain** one large model on a huge pile of unlabeled text so it absorbs general language ability. Then **fine-tune** that model — continue training it on a smaller, labeled dataset — to specialize it for a specific task (classifying tickets, extracting entities, answering a certain kind of question). Popularized by the 2018 [BERT](/ai-for-msps/foundational-ai-concepts/bert) paper, this paradigm meant organizations no longer had to train models from scratch. It remains how many task-specific AI features are built — though the 2020 [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) paper argued the fine-tuning half is often unnecessary (see [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning)).

### In plain terms

Think of pretraining as a general education and fine-tuning as on-the-job training:

* **Pretraining** is expensive, slow, and done once by a model maker (Google, OpenAI, Meta, etc.). The model reads enormous amounts of text and learns how language works in general. BERT did this with masked fill-in-the-blank; GPT models do it with next-word prediction.
* **Fine-tuning** is cheap and fast by comparison. You take the pretrained model and nudge it with a modest number of labeled examples so it excels at *your* task. BERT showed you could reach state-of-the-art results by adding just one small output layer and fine-tuning.

The big idea is **transfer learning**: knowledge gained in pretraining transfers to many downstream tasks, so each new task starts from a strong base instead of from nothing.

### Why it matters for MSPs

* **It clarifies what "trained on your data" means.** A vendor offering a model "tuned to your environment" is fine-tuning. That has direct implications: your data is being used to adjust a model, which is exactly why the **no-training guarantees**, data residency, and tenant-isolation questions on [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) and [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) matter.
* **It separates two cost models.** Fine-tuning is an upfront investment that buys consistency; [prompting](/ai-for-msps/foundational-ai-concepts/in-context-learning) is pay-as-you-go flexibility. Knowing which a feature uses helps you forecast [ROI](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up/implementation-and-roi).
* **It underlies vendor lock-in risk.** A model fine-tuned on your accumulated data can become hard to move — reinforcing the *portability* and *lock-in* concerns raised throughout [Where We're Going](/ai-for-msps/ai-in-the-msp-stack/where-were-going).

### Related concepts

[BERT](/ai-for-msps/foundational-ai-concepts/bert) · [Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning) · [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment)

**In the MSP KB:** [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) · [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet)

### Contradictions & debates

* **Fine-tuning as the goal vs. fine-tuning as a burden.** [BERT](/ai-for-msps/foundational-ai-concepts/bert) treats fine-tuning as the natural, desirable final step. [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) pushes back explicitly: fine-tuning requires task-specific datasets of thousands to tens of thousands of examples, limits generalization, and lets models latch onto spurious patterns in the fine-tuning data. GPT-3 offers [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning) as a way to skip it. This is the central methodological fork among the five papers — and both approaches remain in active use.
* **Fine-tuning vs. alignment.** The [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment) paper is itself a *kind* of fine-tuning, but on human-preference data rather than task labels — showing the paradigm evolved rather than disappeared. Fine-tuning did not die; it changed target.

### Source papers

* Devlin et al. (2018), *BERT* — <https://arxiv.org/pdf/1810.04805>
* Brown et al. (2020), *Language Models are Few-Shot Learners (GPT-3)* — <https://arxiv.org/pdf/2005.14165>

***

**Key terms**: *pretraining*, *fine-tuning*, *transfer learning*, *downstream task*, *labeled data*.


# Large Language Models

Large language models (LLMs) — what they are, why scale matters, and where the "bigger is better" story breaks down — explained for MSP operators, with a link to the 2020 GPT-3 paper.

### Summary

A **large language model (LLM)** is a [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) trained on a vast amount of text to do one deceptively simple thing: predict the next word. The 2020 paper *Language Models are Few-Shot Learners* introduced **GPT-3**, an autoregressive (left-to-right) LLM with **175 billion parameters** — roughly 10× larger than any comparable model before it. Its headline finding was that sheer scale unlocks a new ability: the model can perform many tasks it was never specifically trained for, learning them from a few examples in the prompt with **no gradient updates** (see [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning)). LLMs are the engine behind ChatGPT, Copilot, and most generative "AI" features now appearing in MSP tooling.

### In plain terms

An LLM is trained by covering the next word in billions of sentences and adjusting itself until its guesses are good. Do that at enormous scale and the model absorbs grammar, facts, styles, and reasoning patterns as a side effect of getting good at prediction.

GPT-3's contribution was to show what happens when you make the model *much* bigger and train it on *much* more text (hundreds of billions of words scraped largely from the web, books, and Wikipedia). Capabilities that smaller models lacked — translation, question answering, arithmetic, unscrambling words, writing news articles humans struggle to distinguish from real ones — appeared without task-specific training. GPT-3 is **decoder-only**: unlike [BERT](/ai-for-msps/foundational-ai-concepts/bert), it reads and writes strictly left to right, which makes it a natural text *generator*.

Importantly, the paper is candid about limits: GPT-3 sometimes only *approaches* the performance of specially fine-tuned systems, struggles on some tasks, and inherits biases and factual errors from its web training data.

### Why it matters for MSPs

* **This is what "generative AI" means.** When a tool drafts a ticket reply, summarizes a call, or writes documentation, an LLM is generating that text word by word — probabilistically. This is precisely the *probabilistic AI* the [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) page contrasts with deterministic scripts.
* **It explains hallucination.** An LLM is optimized to produce *plausible* next words, not *true* ones. That is the mechanical reason for the "confidently wrong" answers flagged in [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) — the model has no built-in fact-checker.
* **Scale drives cost.** 175 billion parameters is expensive to run. LLM pricing (per-token, per-seat) and latency trace back to model size, which matters when you assess [implementation and ROI](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up/implementation-and-roi).
* **Web-trained means data-provenance questions.** LLMs learn from scraped text of unknown licensing and accuracy — part of why [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) and vendor **no-training** guarantees deserve scrutiny.

### Related concepts

[In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning) · [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) · [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment) · [BERT](/ai-for-msps/foundational-ai-concepts/bert)

**In the MSP KB:** [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) · [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet)

### Contradictions & debates

* **Scale vs. alignment — the sharpest disagreement in this section.** GPT-3's thesis is that scaling up is the path to capability. The [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment) paper (InstructGPT, 2022) directly complicates it: human raters preferred the outputs of a **1.3B-parameter aligned model over the 175B GPT-3** — a model over 100× larger. Raw scale makes a model *capable*; it does not make it *helpful, honest, or harmless*. Both can be true, but the "bigger is automatically better" reading of GPT-3 does not survive InstructGPT.
* **Generation-first (GPT) vs. understanding-first (BERT).** GPT-3 keeps the left-to-right design that [BERT](/ai-for-msps/foundational-ai-concepts/bert) argued was a limitation — and still reaches strong, sometimes state-of-the-art results. The two lineages settled into different jobs rather than one displacing the other.
* **Capability vs. risk framing.** GPT-3 showcases broad capability; the [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) paper (published a year later) reframes that same generality as concentrated societal risk. Same phenomenon, opposite emphasis.

### Source paper

Brown et al. (2020), *Language Models are Few-Shot Learners* — <https://arxiv.org/pdf/2005.14165>

***

**Key terms**: *large language model (LLM)*, *GPT-3*, *autoregressive*, *decoder-only*, *parameters*, *next-token prediction*, *scaling*.


# In-Context Learning

In-context learning — how large language models learn a task from a few examples in the prompt, with no retraining — explained for MSP operators, with a link to the 2020 GPT-3 paper.

### Summary

**In-context learning** is the ability of a [large language model](/ai-for-msps/foundational-ai-concepts/large-language-models) to perform a new task purely from instructions or examples placed in its prompt — with **no gradient updates and no retraining**. Named and demonstrated in the 2020 GPT-3 paper, it comes in three flavors: **zero-shot** (just an instruction), **one-shot** (one worked example), and **few-shot** (a handful of examples). It is the reason you can "teach" ChatGPT a format or a classification rule just by showing it a couple of samples in your message. In-context learning is also the practical foundation of **prompt engineering**.

### In plain terms

Before GPT-3, adapting a model to a task meant **fine-tuning** — collecting thousands of labeled examples and retraining a copy of the model (the [BERT](/ai-for-msps/foundational-ai-concepts/bert) / [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning) approach). GPT-3 showed a different path: describe the task in plain language, optionally give a few examples, and the model just does it.

* **Zero-shot:** *"Classify this ticket as billing, technical, or sales: …"* — instruction only.
* **One-shot:** the instruction plus a single solved example.
* **Few-shot:** the instruction plus several solved examples the model pattern-matches against.

Nothing about the model changes — the "learning" happens entirely within the single prompt and is forgotten afterward. GPT-3 found that this ability improves dramatically as models get larger: bigger models are far better few-shot learners.

### Why it matters for MSPs

* **It is why AI tools are configurable without code.** When a PSA/RMM feature lets you steer AI behavior with a "prompt" or "instructions" box, you are using in-context learning. No data-science team required.
* **It shapes what you paste into the prompt — and the privacy stakes.** Because the model learns from what is in the prompt, staff naturally paste real client data (tickets, logs, configs) to get better answers. That is exactly the exposure the [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) and [Governance & Acceptable Use](/ai-for-msps/ai-security/ai-governance-and-acceptable-use-policies) pages address.
* **It has real limits.** In-context learning is bounded by the model's **context window** (how much text it can consider at once) and is inconsistent — the same few examples can yield slightly different results, reinforcing the [human-in-the-loop verification](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) principle.
* **It is a cheaper first step than fine-tuning.** Before paying to fine-tune a model on your data, a well-crafted few-shot prompt often gets most of the way there — a useful cost lever for [implementation and ROI](/ai-for-msps/ai-in-the-msp-stack/where-it-shows-up/implementation-and-roi).

### Related concepts

[Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning) · [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment)

**In the MSP KB:** [Data Handling & Privacy](/ai-for-msps/ai-security/data-handling-and-privacy) · [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation)

### Contradictions & debates

* **In-context learning vs. fine-tuning.** This is the head-to-head with the [BERT](/ai-for-msps/foundational-ai-concepts/bert) lineage. GPT-3 explicitly lists the downsides of fine-tuning — it needs task-specific datasets of thousands to tens of thousands of examples, and models can exploit spurious correlations in that data — and offers in-context learning as an alternative that needs neither. BERT's paradigm assumes the opposite: that fine-tuning per task is *the* way to reach state-of-the-art quality. In practice both survive; teams fine-tune when they have data and need consistency, and prompt when they need flexibility and speed.
* **Is it really "learning"?** The GPT-3 paper is careful with the term, and later researchers debate whether the model is genuinely *learning* the task or merely *retrieving and recombining* patterns already absorbed during pretraining. For MSP purposes the practical takeaway is the same: outputs are pattern-driven and must be verified.

### Source paper

Brown et al. (2020), *Language Models are Few-Shot Learners* — <https://arxiv.org/pdf/2005.14165>

***

**Key terms**: *in-context learning*, *zero-shot*, *one-shot*, *few-shot*, *prompt engineering*, *context window*.


# Foundation Models

Foundation models — the category name for the large, general-purpose AI models that power today's tools, and the risks of building everything on them — explained for MSP operators, with a link to the

### Summary

**Foundation model** is the term coined in a 2021 Stanford report (*On the Opportunities and Risks of Foundation Models*) for a model that is **trained on broad data at scale and then adapted to a wide range of downstream tasks**. [BERT](/ai-for-msps/foundational-ai-concepts/bert) and [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) are the canonical examples. The report's contribution is not a new model but a new *lens*: it names the category, identifies two defining properties — **emergence** and **homogenization** — and argues that as more of the world's software comes to depend on a handful of these base models, their flaws, biases, and failure modes get inherited by everything built on top. It is the most **cautionary** of the five papers in this section.

### In plain terms

A foundation model is a single, general-purpose base that many different applications are built from. Instead of building a bespoke model per task, you adapt one powerful model — by [fine-tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning), by [prompting](/ai-for-msps/foundational-ai-concepts/in-context-learning), or by [alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment). The report highlights two properties:

* **Emergence.** Capabilities appear that were never explicitly programmed and are hard to predict — they *emerge* from scale. This is powerful but also means behavior isn't fully understood, even by the model's creators.
* **Homogenization.** Because so many systems are built on the *same* few base models, they all share the same strengths — and the same weaknesses. A flaw or bias in one foundation model propagates to every application that depends on it: a single point of failure at civilizational scale.

The report is deliberately balanced — it catalogs opportunities *and* risks across capabilities, applications, technology, and society — but its lasting message is caution about concentrated dependence.

### Why it matters for MSPs

* **It names the thing MSPs actually depend on.** The AI features in your PSA, RMM, documentation, and security tools are, overwhelmingly, thin layers over a small number of foundation models from a few providers. Understanding this concentration is the starting point for supply-chain and continuity risk assessment.
* **Homogenization = concentrated vendor risk.** If most of your AI-enabled tools sit on the same underlying model, an outage, price change, policy shift, or newly discovered bias at that provider hits all of them at once. This is the technical backbone of the **vendor lock-in** and **portability** concerns raised in [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) and [Where We're Going](/ai-for-msps/ai-in-the-msp-stack/where-were-going).
* **Emergence = unpredictability you must govern.** Because capabilities (and failures) emerge rather than being specified, you cannot assume a foundation model will behave the same after every update. That unpredictability is exactly why the [Operational Safeguards & Oversight](/ai-for-msps/ai-security/operational-safeguards-and-oversight) and [Governance & Acceptable Use](/ai-for-msps/ai-security/ai-governance-and-acceptable-use-policies) controls exist.
* **It anticipated the regulation.** The report's risk framing foreshadows the compliance pressures (EU AI Act, right to explanation) tracked in [Where We're Going](/ai-for-msps/ai-in-the-msp-stack/where-were-going).

### Related concepts

[Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [BERT](/ai-for-msps/foundational-ai-concepts/bert) · [Transformer Architecture](/ai-for-msps/foundational-ai-concepts/transformer) · [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning) · [RLHF and Alignment](/ai-for-msps/foundational-ai-concepts/rlhf-and-alignment)

**In the MSP KB:** [AI Security](/ai-for-msps/ai-security) · [Where We're Going](/ai-for-msps/ai-in-the-msp-stack/where-were-going) · [Risks & Guardrails](/ai-for-msps/ai-security/risks-and-guardrails-for-ai-in-msp-environments)

### Contradictions & debates

* **Risk-first vs. capability-first framing.** The [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) paper celebrates broad capability as an achievement. The foundation models report reframes that *same* generality as a source of concentrated, hard-to-govern risk. They do not dispute the facts — they disagree on emphasis, and that difference of emphasis is exactly the debate MSPs sit inside when weighing AI adoption against accountability.
* **Is the term even a good idea?** The report's naming of "foundation models" was itself contested — some researchers argued it overstated the novelty or lent marketing weight to a few large labs. The debate matters for MSPs mainly as a caution: a category name is not a capability guarantee, and the [AI vs. Automation](/ai-for-msps/ai-in-the-msp-stack/ai-vs.-automation) discipline of separating claim from reality still applies.
* **Homogenization: efficiency vs. fragility.** Building everything on one base model is efficient (the upside GPT-3 shows) *and* fragile (the downside this report stresses). The same fact reads as a feature or a bug depending on whether you are optimizing for cost or for resilience — a live trade-off in MSP tool selection.

### Source paper

Bommasani et al. (2021), *On the Opportunities and Risks of Foundation Models* (Stanford CRFM) — <https://arxiv.org/pdf/2108.07258>

***

**Key terms**: *foundation model*, *emergence*, *homogenization*, *single point of failure*, *downstream adaptation*, *concentration risk*.


# RLHF and Alignment

RLHF and alignment — how raw language models are turned into helpful, instruction-following assistants using human feedback — explained for MSP operators, with a link to the 2022 InstructGPT paper.

### Summary

**Alignment** is the work of getting an AI model to actually do what a user *intends* — helpfully, honestly, and harmlessly — rather than just predicting plausible next words. **RLHF** (Reinforcement Learning from Human Feedback) is the technique that made this practical. The 2022 InstructGPT paper (*Training language models to follow instructions with human feedback*) showed that fine-tuning a [large language model](/ai-for-msps/foundational-ai-concepts/large-language-models) on human preferences produces far more useful outputs than scale alone. Its striking result: human raters preferred the outputs of a **1.3-billion-parameter aligned model over the 175-billion-parameter GPT-3** — a model over 100× larger. RLHF is the step that turned raw LLMs into the assistants (ChatGPT and its peers) now embedded across the MSP stack.

### In plain terms

A pretrained LLM predicts likely text — which is not the same as *following instructions*. Ask a raw model a question and it might continue with more questions, because that is a plausible continuation. The InstructGPT paper describes the base language-modeling objective as **misaligned** with "follow the user's instructions helpfully and safely."

RLHF fixes this in **three steps**:

1. **Supervised fine-tuning (SFT).** Human labelers write high-quality example responses to prompts; the model is fine-tuned to imitate them.
2. **Reward model (RM).** Labelers *rank* several model outputs from best to worst. A separate model learns to predict those human preferences — becoming a stand-in for human judgment.
3. **Reinforcement learning (PPO).** The main model is optimized to produce outputs the reward model scores highly, using an algorithm called Proximal Policy Optimization. A refinement, **PPO-ptx**, mixes in the original pretraining objective to avoid degrading general ability.

The alignment target is often summarized as **helpful, honest, and harmless**.

### Why it matters for MSPs

* **It is why today's AI tools feel usable.** The difference between a raw text-predictor and a tool that follows a support tech's instructions *is* RLHF. Nearly every assistant-style feature in MSP tooling has been through this process.
* **It measurably reduces (but does not eliminate) two big risks.** InstructGPT was about **twice as truthful** as GPT-3 on the TruthfulQA benchmark, cut made-up information on closed-domain tasks roughly in half (a 21% vs. 41% hallucination rate), and produced about **25% fewer toxic outputs**. This is concrete evidence for the [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) warning that hallucination is *reduced*, never *removed* — verification stays mandatory.
* **Alignment reflects the labelers' values, not universal truth.** The model is tuned to what a specific group of human raters preferred. That is a governance consideration: "aligned" means aligned *to someone*, which is why internal [Governance & Acceptable Use](/ai-for-msps/ai-security/ai-governance-and-acceptable-use-policies) policies still matter on top of vendor alignment.

### Related concepts

[Large Language Models](/ai-for-msps/foundational-ai-concepts/large-language-models) · [Pretraining and Fine-Tuning](/ai-for-msps/foundational-ai-concepts/pretraining-and-fine-tuning) · [Foundation Models](/ai-for-msps/foundational-ai-concepts/foundation-models) · [In-Context Learning](/ai-for-msps/foundational-ai-concepts/in-context-learning)

**In the MSP KB:** [What It Can't Do Yet](/ai-for-msps/ai-in-the-msp-stack/what-it-cant-do-yet) · [Governance & Acceptable Use](/ai-for-msps/ai-security/ai-governance-and-acceptable-use-policies) · [Risks & Guardrails](/ai-for-msps/ai-security/risks-and-guardrails-for-ai-in-msp-environments)

### Contradictions & debates

* **Alignment vs. scale — a direct rebuttal of the GPT-3 story.** The [GPT-3](/ai-for-msps/foundational-ai-concepts/large-language-models) paper's implicit message is that bigger is better. InstructGPT's opening line is almost the opposite: *"Making language models bigger does not inherently make them better at following a user's intent."* The 1.3B-beats-175B result is a quantified counterexample to naive scaling. The reconciliation: scale creates raw capability; alignment directs it. Both are needed, but they are not the same axis.
* **The "alignment tax."** Optimizing for human preferences can slightly degrade performance on some standard NLP benchmarks — a trade-off known as the alignment tax. The InstructGPT authors reduced it with the PPO-ptx variant (mixing pretraining back in), so regressions were minimal, but the tension between "aligned to humans" and "maximally capable on benchmarks" is real. This complicates any assumption that improvements are purely additive.
* **Helpful vs. honest vs. harmless can conflict.** The three alignment goals sometimes pull against each other (a maximally *helpful* answer may not be the most *harmless*). The paper acknowledges the model still makes simple mistakes — alignment is a direction, not a solved problem.

### Source paper

Ouyang et al. (2022), *Training language models to follow instructions with human feedback (InstructGPT)* — <https://arxiv.org/pdf/2203.02155>

***

**Key terms**: *alignment*, *RLHF*, *supervised fine-tuning (SFT)*, *reward model*, *PPO*, *alignment tax*, *helpful/honest/harmless*.


# AI Security

Framework for securing AI in MSP environments, covering risks, compliance, governance, and operational safeguards.

### **Introduction**

MSPs adopting AI must treat it as a new class of SaaS with unique risks. This section outlines the major risk areas, the safeguards MSPs should apply, and the policies needed to govern AI responsibly. Each subpage provides detail, examples, and guardrails.

### Subpages Overview

1. [**Risks & Guardrails for AI in MSP Environments**](/ai-for-msps/ai-security/risks-and-guardrails-for-ai-in-msp-environments)\
   Explains the main risks (data, operational, business) and practical guardrails (policy, monitoring, oversight).
2. [**Data Handling & Privacy**](/ai-for-msps/ai-security/data-handling-and-privacy)\
   Covers how AI tools process, store, and transmit data; residency and training risks; anonymization, tenant isolation, and contractual safeguards.
3. [**Operational Safeguards & Oversight**](/ai-for-msps/ai-security/operational-safeguards-and-oversight)\
   Details practical controls: human-in-the-loop enforcement, sandbox testing, incident response, logging, and AI-native security layers.
4. [**AI Governance & Acceptable Use Policies**](/ai-for-msps/ai-security/ai-governance-and-acceptable-use-policies)\
   Guidance on writing internal and client-facing policies, managing shadow AI, defining augmentation vs automation, and training users.

### **Bottom Line**

MSPs can safely adopt AI by following structured governance: identify risks, secure data handling, enforce clear policies, and maintain oversight.


# Risks & Guardrails for AI in MSP Environments

A practical overview of risks and guardrails for securely integrating AI into MSP workflows.

## **Introduction**

Integrating AI into MSP operations offers efficiency gains but introduces risks around data governance, operational reliability, and business stability. This page explains the primary risks and outlines guardrails to reduce them.

### Data Privacy and Governance Risks

Many AI tools train on customer data by default, or store inputs without transparency. Unauthorized “shadow AI” tools (e.g., Teams/Zoom assistants) may capture sensitive discussions. Consumer-grade AI tools often lack audit logging or API visibility.

#### **Guardrails:**

* Vet vendors (choose those with explicit “no training” guarantees, e.g., Microsoft Copilot).
* Enforce DPA review and residency clauses.
* Ban unapproved AI apps via policy, treating violations as HR/IT issues.

**Key terms:** *shadow IT*, *data lineage*, *audit logging*, *DPA*.

***

### Operational and Reliability Risks

AI can be “confidently wrong” and propagate errors. Scripts or config changes may be unsafe if deployed without checks. Over-reliance risks eroding technician troubleshooting skills. Models may also “hallucinate” outputs when inputs are incomplete.

#### **Guardrails:**

* Require human validation of AI-generated code/config.
* Sandbox-test all scripts and enforce peer review.
* Position AI as augmentation, not replacement.

**Key terms:** *hallucination*, *skill erosion*, *over-reliance*.

***

### Business and Financial Risks

Client AI adoption can shrink per-user billing if businesses reduce staff. Proliferation of AI tools creates vendor sprawl and management overhead.

#### **Guardrails:**

* Review AI cost impact on per-seat models.
* Monitor AI tool use to limit sprawl.
* Offer advisory services on AI governance as added value.

### Bottom Line

AI adoption in MSP environments is valuable but risky if unmanaged. By applying clear policies, vendor vetting, monitoring tools, and human oversight, MSPs can use AI effectively without compromising governance, reliability, or financial stability.


# Data Handling & Privacy

How AI tools process, store, and protect client data. Covers residency risks, training restrictions, anonymization, tenant isolation, and contract requirements.

### **Introduction**

MSPs must treat AI as a data processor with unique risks. This page outlines how AI tools handle client data, the privacy issues that follow, and the technical and contractual controls needed to keep data secure.

***

### Processing, Storage, and Transmission

AI tools transform inputs (tickets, calls, docs) into outputs, creating risks at each stage. Anything sent to AI may be stored or routed outside your region.

* **Guardrails:** Require **encryption**, **audit logs**, and **zero-retention modes** where possible.
* **Terms:** *Retrieval-Augmented Generation (RAG)*, *zero-retention*, *audit logging*.

### Data Residency and Training Risks

Where data lives and how vendors use it are critical. Laws (GDPR, HIPAA, EU AI Act) restrict cross-border data flow. Some vendors train on customer inputs by default.

* **Guardrails:** Insist on **local data zones** and contract language: *“Customer/tenant data is not used for training.”*
* **Terms:** *Data residency*, *Standard Contractual Clauses (SCCs)*, *no-train mode*, *output memorization*.

### Anonymization, Redaction, and Tenant Isolation

Reduce what AI sees and keep clients separated. Don’t send sensitive details unless required.

* **Guardrails:** Use **redaction/DLP tools** (AWS Comprehend, Google Cloud DLP) and **synthetic data** for testing. Enforce **tenant isolation** and **RBAC** under a *Zero-Trust Architecture*.
* **Terms:** *Anonymization*, *pseudonymisation/tokenization*, *tenant isolation*, *RBAC*, *ZTA*.

### Contracts and DPAs with Vendors

A strong **Data Processing Agreement (DPA)** is the main safeguard. Without the right clauses, vendors may store, transfer, or train on client data.

* **Guardrails:** Require **DPAs** with SOC 2 / ISO 27001 compliance.
* **Terms:** *Processing details*, *security measures*, *training restrictions*, *residency clauses*, *deletion/return*, *exit strategy (data portability)*

***

### **Bottom Line**

MSPs must enforce residency, anonymization, isolation, and contractual controls to adopt AI securely while maintaining compliance and client trust.


# Operational Safeguards & Oversight

AI tools in MSP environments need strong oversight. This page explains the safeguards that keep AI outputs reliable, auditable, and safe to use in production.

### **Introduction**

AI tools should always be deployed with human oversight, safe testing environments, and strong monitoring. By treating AI as a controlled automation layer rather than a black box, MSPs can safely gain value while minimizing risk.

***

### Human-in-the-Loop Enforcement

AI is fallible. Without human review, errors or unsafe outputs can slip into production.

* **Guardrails:** Require staff to review AI outputs (ticket notes, scripts, configs) before applying changes. Treat AI as a *copilot*, never the lead.
* **Key terms:** *human-in-the-loop (HITL)*, *augmentation vs automation*.

### Sandbox Testing of AI Outputs

AI-generated scripts, configs, or automation can misfire if deployed directly.

* **Guardrails:** Enforce **sandbox environments** for testing, followed by peer review. Apply version control and rollback options.
* **Key terms:** *sandbox testing*, *peer review*, *rollback*.

### Incident Response for AI Misfires

AI failures can cause service outages or data exposure if not contained quickly.

* **Guardrails:** Update IR plans to cover AI-specific risks (hallucinated outputs, unauthorized integrations). Include alerting, containment, and rollback steps.
* **Key terms:** *incident response (IR)*, *containment*, *alerting*.

***

### Logging and Audit Trails

Without visibility into AI actions, errors or abuses go undetected.

* **Guardrails:** Enable audit logging for all AI interactions. Record prompts, outputs, and system actions. Route alerts to SOC/NOC as appropriate.
* **Key terms:** *audit logging*, *non-human identity monitoring*, *traceability*.

***

### AI-Native Security Layers

Traditional controls don’t fully cover AI. Extra layers are needed to prevent misuse or data leaks.

* **Guardrails:** Deploy **prompt filtering**, **DLP scanning**, and usage monitoring. Enforce token limits to manage cost and prevent over-consumption.
* **Key terms:** *prompt injection*, *DLP (data loss prevention)*, *token limits*.

### **Monitoring and Metrics**

Track AI system performance and usage to identify problems early.

* **Guardrails:** Monitor token consumption, response times, and error rates. Set alerts for unusual usage patterns or system failures. Track human override rates as AI reliability indicators.
* **Key terms:** *usage metrics*, *override tracking*, *performance monitoring*.

***

### **Bottom Line**

AI tools require structured oversight to remain safe and effective. Human review, sandbox testing, proper logging, and continuous monitoring ensure AI augments MSP operations without creating new risks.


# Governance & Acceptable Use

This guide provides policy templates, enforcement procedures, and training frameworks for how MSPs and clients should define, document, and disclose AI use responsibly.

### **Introduction**

Documented guardrails reduce shadow IT, clarify responsibilities, and prevent unsafe expectations. These core rules apply whether AI is used by staff, embedded in services, or adopted by clients.

***

#### **Internal and Client-Facing Policies**

* **Reality:** Without documented policies, staff or clients may adopt AI tools unsafely, leading to shadow IT and unmanaged risk.
* **Guardrails:**
  * Create separate internal (staff) and client-facing (service) policies
  * Define roles, responsibilities, and escalation points for AI use

#### Defining Augmentation vs Automation

* **Reality:** Not all AI tasks are equal. Some augment human work, others attempt full automation. Misclassification can create unsafe expectations.
* **Guardrails:**
  * Classify each AI use case
  * Require human-in-the-loop (HITL) for automation
  * State explicitly which functions AI may suggest vs execute

#### Training Staff and Clients

* **Reality:** Staff and clients may lack awareness of AI risks, making them vulnerable to misuse or overtrusting outputs.
* **Guardrails:**
  * Deliver regular training on responsible AI use
  * Include safe prompting, data handling, and error recognition
  * Use simulations (e.g., phishing with AI-generated lures)

#### Policy Enforcement

* **Reality:** Policies are only effective if enforced consistently.
* **Guardrails:**
  * Define consequences for policy violations (HR action, service restriction)
  * Audit compliance with client AI agreements
  * Provide clear reporting channels for violations

***

### Internal AI Acceptable Use Policy Template

Internal usage needs a defined baseline, or staff will improvise with AI tools in inconsistent ways.

<table><thead><tr><th width="192.9140625">Policy Area</th><th>Requirement</th><th>Decision Criteria</th></tr></thead><tbody><tr><td><strong>Data Confidentiality</strong></td><td>Treat all customer and company information as highly confidential</td><td>Prohibit disclosing PII, confidential, or sensitive data to public AI platforms</td></tr><tr><td><strong>Accountability</strong></td><td>Users retain full responsibility for all AI-generated outputs</td><td>AI assists human judgment; never replaces critical thinking</td></tr><tr><td><strong>Transparency</strong></td><td>AI-generated content must be acknowledged where it materially contributes</td><td>Outputs used in client documentation require review and attribution</td></tr><tr><td><strong>Secure Usage</strong></td><td>All AI interactions occur over secure, authenticated systems</td><td>Only use approved enterprise AI systems for processing sensitive data</td></tr></tbody></table>

**Internal AI AUP Checklist**

* [x] All AI usage requires Infosec Committee approval
* [x] Vendors reviewed under Vendor Risk Management policy
* [x] Staff trained on data privacy and AI bias recognition
* [x] Monitoring mechanisms for AI interactions established

***

### Client AI Disclosure Framework

#### **DPA Negotiation Summary**

MSPs should require vendors to ban training on client data, guarantee data residency, and disclose subprocessors with audit rights. These terms set the baseline for compliant AI adoption.

<table><thead><tr><th width="167.359375">Clause Type</th><th>Required Language</th><th>Risk Mitigation</th></tr></thead><tbody><tr><td><strong>Data Usage</strong></td><td>"MSP and client data SHALL NOT be used for vendor model training"</td><td>IP exposure and privacy violations</td></tr><tr><td><strong>Data Residency</strong></td><td>Specify exact jurisdictions for data storage and processing</td><td>GDPR/CCPA compliance violations</td></tr><tr><td><strong>Subprocessors</strong></td><td>Full disclosure of all subcontractors and processing chains</td><td>Unauthorized data exposure</td></tr><tr><td><strong>Audit Rights</strong></td><td>Right to examine algorithmic decision-making and adherence</td><td>Limited control over AI vendor ecosystem</td></tr></tbody></table>

#### **Client Communication Protocol**

Clients often experiment with AI without understanding the risks. Give practical guardrails for AI use, covering policy, data handling, and safe tool selection by:

* Helping clients establish their own AI acceptable use policies
* Advising against inputting confidential information into public AI platforms
* Running AI tools through the same due diligence as other SaaS apps
* Using solutions with no-training / data localization features

**Key terms:** *policy enforcement*, *compliance audit*, *risk acceptance,* AI governance, acceptable use policy (AUP), risk ownership, *responsible AI*, *prompt hygiene*, *AI-enhanced phishing, augmentation*, *automation*, *HITL (human-in-the-loop)*.

***

### **Bottom Line**

Strong AI governance gives MSPs control over how AI enters their environment. Clear policies, consistent enforcement, and client communication reduce shadow IT and align AI adoption with security standards.

***


# Training, Detection & Enforcement

Train staff on safe AI use, detect unauthorized “shadow AI,” and enforce policies with clear guardrails. Covers fundamentals, operational training, monitoring methods,

#### Introduction

Policies define intent, but operations determine outcomes. MSPs need **structured training** so staff use AI safely, plus **detection and enforcement** controls to stop shadow AI before it creates compliance or data risks. This section combines both, giving MSPs a practical playbook for managing AI responsibly.

***

### **Staff Training Framework**

#### AI Fundamentals and Governance

Core knowledge every staff member should understand before using AI in workflows.

<table><thead><tr><th width="149.26953125">Focus Area</th><th>Key Concepts</th><th>Practical Goal</th></tr></thead><tbody><tr><td><strong>Compliance</strong></td><td>GDPR, HIPAA, and industry-specific AI requirements</td><td>Ensure workflows remain audit-ready when AI is introduced</td></tr><tr><td><strong>Ethical Use</strong></td><td>Data privacy, security practices, AI bias recognition</td><td>Apply internal AUPs and prevent reputational risk</td></tr><tr><td><strong>AI Basics</strong></td><td>Differentiate AI, ML, and automation; understand AI system lifecycle</td><td>Dispel myths and set realistic expectations</td></tr></tbody></table>

***

#### Operational Training

Hands-on skills for safe, effective use of AI in day-to-day MSP work.

<table><thead><tr><th width="163.8359375">Focus Area</th><th>Key Concepts</th><th>Practical Goal</th></tr></thead><tbody><tr><td><strong>Human–AI Loop</strong></td><td>AI augments expertise, never replaces critical judgment</td><td>Humans must review AI triage before high-impact actions</td></tr><tr><td><strong>Prompt Engineering</strong></td><td>Contextualizing inquiries and refining outputs</td><td>Staff can elicit specific, accurate responses</td></tr><tr><td><strong>Output Validation</strong></td><td>Identifying hallucinations and vague answers</td><td>Staff can detect and correct AI misfires</td></tr><tr><td><strong>Client Communication</strong></td><td>Explaining AI benefits and limits</td><td>Improves transparency in QBRs and client reviews</td></tr></tbody></table>

**Guardrails:**

* Always require **human-in-the-loop (HITL)** for automation
* Clearly state which functions AI may **suggest vs execute**
* Train staff to recognize **hallucinations and bias**
* Reinforce through simulations (e.g., AI-generated phishing lures)

A strong training framework ensures AI is used to **augment, not replace**, staff expertise.

***

### **Shadow AI Detection and Enforcement**

Shadow AI (the unauthorized use of unapproved AI tools) creates unmanaged risks around data exposure, compliance, and liability. MSPs need both **detection methods** to spot usage and **enforcement measures** to guide staff toward secure, approved alternatives.

#### Detection Procedures

Layered monitoring helps identify shadow AI before it becomes a breach or audit failure.

| Focus Area                  | Tools / Methods                 | Purpose                                                  |
| --------------------------- | ------------------------------- | -------------------------------------------------------- |
| **API / Domain Monitoring** | DNS and web proxy monitoring    | Detect traffic to known AI domains and APIs              |
| **SaaS Inventory**          | Auvik SaaS Management, Augmentt | Identify unauthorized AI apps, plugins, and integrations |
| **Data Loss Prevention**    | Endpoint DLP tools              | Block sensitive data from being submitted to public AI   |
| **User Activity Tracking**  | Behavior monitoring             | Pinpoint employees initiating unauthorized AI usage      |

#### Enforcement Actions

Shadow AI is inevitable if detection isn't paired with consistent enforcement to prevent recurrence. Minimize unmanaged risk and maintain compliance across client environments by:

* Establishing clear **AI Acceptable Use Policies** defining approved tools
* Providing **secure, enterprise-grade AI alternatives** to minimize shadow usage
* Implementing **least privilege access** to protect proprietary and client data
* Defining and communicating **disciplinary consequences** for policy violations

***

## **Bottom Line**

MSPs can’t rely on policies alone. By training staff to use AI responsibly, detecting unauthorized usage, and enforcing clear boundaries, AI adoption becomes **controlled, auditable, and client-safe**. This dual approach reduces shadow IT and strengthens client trust.


# Communities

Explore how MSP communities foster collaboration, technical skill-sharing, and business growth, benefiting participants across the ecosystem.

## Introduction

Communities for MSPs offer more than networking opportunities—they are growth engines for collaboration, innovation, and problem-solving. These communities exist in various formats, from real-time chat platforms to structured forums and in-person groups. They are built on shared challenges and mutual respect, not solely business objectives.

Whether technical or business-focused, these spaces empower MSPs to improve their operations and services while fostering relationships that extend beyond transactional interactions.

***

## Types of MSP Communities

**1. Real-Time Chat Platforms**

* **Examples:** Slack channels (MSPGeek), Discord servers (CyberDrain).
* **Focus:** Immediate problem-solving, casual discussions, and quick collaboration.
* **Best For:**
  * Rapid Q\&A about tools, automation, and best practices.
  * Engaging in live discussions with peers or businesses serving MSPs.
  * Staying updated on fast-changing topics like cybersecurity threats.

**2. Online Forums**

* **Examples:** Reddit (r/MSP), dedicated vendor communities.
* **Focus:** Long-form discussions, deep dives into recurring challenges, and referenceable advice.
* **Best For:**
  * Exploring detailed technical or business strategies.
  * Reading and contributing to comprehensive threads for persistent knowledge-sharing.

**3. Social Media Groups**

* **Examples:** Facebook groups, LinkedIn communities.
* **Focus:** Broad industry engagement, sharing news, and lightweight collaboration.
* **Best For:**
  * Connecting with a wide range of MSPs and stakeholders.
  * Sharing insights, events, or relevant updates.

**4. User Groups and Meetups**

* **Examples:** Local user groups, vendor-specific gatherings.
* **Focus:** Strengthening relationships through in-person collaboration and training.
* **Best For:**
  * Building deeper connections through face-to-face interaction.
  * Participating in panels or workshops for hands-on learning.

**5. Event-Based Communities**

* **Examples:** MSP-centric conferences, or vendor-hosted summits.
* **Focus:** Thought leadership, showcasing trends, and creating momentum around specific challenges.
* **Best For:**
  * Learning from top industry leaders.
  * Expanding your network and exploring new tools or practices.

***

## Key Insights for Businesses Engaging in MSP Communities

**1. Communities Are Built on Common Ground**

Communities thrive when members rally around shared challenges or goals—not when one party dominates. MSPs and businesses serving them should focus on collaboration, offering value, and fostering respect.

**2. Mutual Growth Benefits Everyone**

Members and businesses that contribute authentic expertise enhance the collective knowledge base. For example, sharing tools, workflows, or solutions—such as PowerShell scripts on MSPGeek or automation tips in CyberDrain—helps everyone improve.

**3. Feedback Drives Innovation**

Communities are a rich source of insights. Active participation allows MSPs and businesses to identify pain points early, adapt tools, and co-create solutions. This collaboration benefits products and strengthens community trust.

**4. Patience and Consistency Matter**

Building trust in a community takes time. MSPs and contributors should focus on showing up consistently, sharing value, and engaging authentically to create meaningful, long-term relationships.

***

## Why MSPs Should Participate

1. **Expand Knowledge:**
   * Learn from peers and thought leaders about managing technical, operational, and business challenges.
   * Discover emerging trends and best practices that improve efficiency and service quality.
2. **Build Relationships:**
   * Collaborate with like-minded professionals to develop partnerships and mentorships.
   * Strengthen connections with businesses offering tools or services.
3. **Stay Competitive:**
   * Leverage real-time discussions and innovations to maintain an edge in the industry.
   * Use community-shared solutions to solve challenges faster than working in isolation.

***

## How Businesses Serving MSPs Benefit

**Role in Communities**

Businesses serving MSPs enhance community spaces by providing insights, solving challenges, and facilitating collaboration. Successful participation requires authenticity, patience, and a genuine interest in mutual success.

**Engagement Strategies:**

* **Contribute, Don’t Dominate:**
  * Share actionable advice, templates, or solutions without overtly promoting products.
  * Example: Rewst users share workflows on GitHub, creating value for the broader MSP community.
* **Celebrate User Achievements:**
  * Highlight innovations from MSPs in the community, fostering trust and amplifying engagement.
* **Leverage Feedback for Growth:**
  * Act on user feedback to refine products and align with community needs.

***

## Best Practices for Engagement

1. **Choose Diverse Spaces:** Balance technical and business-focused communities.
2. **Be an Active Contributor:** Share experiences to foster collaboration.
3. **Adopt a Long-Term View:** Build trust with consistent participation.
4. **Encourage Transparency:** Share lessons learned and invite feedback.

***

## Conclusion

MSP communities offer unmatched opportunities for growth, innovation, and collaboration. By contributing authentically, staying consistent, and fostering respect, MSPs and businesses alike can thrive in these spaces. Community engagement is more than a strategy—it's a commitment to mutual success that drives the entire industry forward.

### In this section

{% content-ref url="/pages/1hQ326j2iGDrMqMc3VWQ" %}
[Online Communities](/resources/communities/forums-and-chat-communities)
{% endcontent-ref %}

{% content-ref url="/pages/tGBsk20WjtjPNl5iUJh1" %}
[Peer Groups](/resources/communities/peer-groups)
{% endcontent-ref %}

{% content-ref url="/pages/3sbnW7adpadrKnsGrlxW" %}
[Social Media communities](/resources/communities/social-media-communities)
{% endcontent-ref %}


# Online Communities

Explore online MSP communities for real-time collaboration, technical advice, and business insights. Engage with peers and grow professionally across various platforms.

## Community Profiles

## **Reddit: r/msp**

* **Overview:**\
  With over 140,000 members, r/msp is the largest online MSP-focused community. It’s an invaluable space for discussing pricing strategies, vendor relationships, service delivery, and occasional technical topics. Active threads range from industry trends to peer recommendations.
* **Target Audience:** Mix of business-focused and technical insights.
* **Why Join:**
  * Peer-driven advice on MSP operations.
  * Access to real-world insights from a global member base.
* **Link:** [Visit r/msp](https://www.reddit.com/r/msp/)

***

## **MSPGeek (Discord)**

* **Overview:**\
  Originally built as a technical forum for MSPs, MSPGeek is now a thriving community offering support for troubleshooting, and vendor specific challenges with their dedicated spaces for engagement. It is especially popular for RMM and automation focused technicians.
* **Target Audience:** MSP technicians and engineers, with some business conversations.
* **Why Join:**
  * Dive deep into RMM tools, scripting, and automation.
  * Collaborative and constructive discussions for day-to-day MSP work.
  * Engage directly with the business you work with in their dedicated vendor channels.
* **Link:** [Visit MSPGeek](https://mspgeek.org/)

***

## **Spiceworks**

* **Overview:**\
  Spiceworks is a broad IT forum with a dedicated section for managed service providers. Members discuss both technical and business topics, making it a versatile resource for MSPs of all sizes.
* **Target Audience:** MSPs looking for both technical and business-focused discussions.
* **Why Join:**
  * Gain insights from IT professionals across different sectors.
  * Network with peers and explore vendor-neutral resources.
* **Link:** [Visit Spiceworks](https://community.spiceworks.com/managed-service-providers)

***

## **MSPs’r’us (Discord)**

* **Overview:**\
  A real-time collaboration platform tied to the Reddit r/msp community, MSPs’r’us has over 5,000 members. It focuses on technical problem-solving, quick-fire advice, and informal networking.
* **Target Audience:** Primarily technical, but also open to business-oriented MSP discussions.
* **Why Join:**
  * Get feedback on technical challenges.
  * Build connections in a casual, fast-paced environment.
* **Link:** [Join MSPs’r’us](https://discord.gg/mspexchange)

***

#### **CyberDrain (Discord)**

* **Overview:**\
  This community, centered around emphasizes scripting, automation, and cybersecurity practices, as well as the home of the Open Source software tool CIPP.&#x20;
* **Target Audience:** Technical professionals focused on M365, GDAP, Graph APIs & PowerShell
* **Why Join:**
  * Participate in challenges like Capture The Flag (CTF) for skill-building.
  * Engage with the Open Source community of the CyberDrain Improved Partner Portal
* **Link:** [Join CyberDrain](https://discord.gg/cyberdrain)

***

#### **6. The Tech Degenerates (TTD)**

* **Overview:**\
  The Tech Degenerates is a community for MSPs, vendors, and other IT channel professionals. TTD combines a Discord server with structured monthly activities like happy hours, and host an extensive industry events calendar. Its unique approach blends professional growth with a sense of humor and inclusivity.
* **Target Audience:** Channel professionals seeking collaboration and shared knowledge.
* **Why Join:**
  * Access diverse initiatives like consulting programs, peer groups, and exclusive events.
  * Stay informed with curated resources and a centralized industry calendar.
* **Link:**
  * [Join the TTD Discord](https://discord.gg/jointhedegenerates)
  * [Explore the Industry Calendar](https://thetechdegenerates.com/Public/Resources/IndustryCalendar/)


# Peer Groups

Peer groups foster collaboration, knowledge-sharing, and problem-solving among MSP leaders and professionals. These communities provide a mix of resources, events, and networking opportunities tailored to enhance MSP operations and growth.

***

#### **1. The Tech Tribe**

* **Overview:**\
  A global community for MSP owners and employees, The Tech Tribe offers marketing materials, Tribal Perks (discounts on 3rd-party services), and curated resources for improving business operations. Regular in-person meetups connect members worldwide.
* **Target Audience:** Primarily MSP owners and senior staff, with resources accessible to all employees through membership.
* **Cost:** Membership fee required.
* **Link:** [Visit The Tech Tribe](https://thetechtribe.com/)

***

#### **2. ASCII Group**

* **Overview:**\
  The ASCII Group is the oldest MSP peer group in North America, offering eight annual conferences and an online forum for networking. ASCII emphasizes marketing and provides a platform for knowledge-sharing among MSPs and VARs.
* **Main Events:** IT SMB Success Summits in various US locations.
* **Target Audience:** MSPs and VARs interested in marketing, networking, and business growth.
* **Link:** [Visit ASCII Group](https://www.ascii.com/)

***

#### **3. IT Nation Evolve (formerly HTG)**

* **Overview:**\
  IT Nation Evolve continues HTG’s legacy of fostering peer groups for MSP executives. Groups of 10–12 non-competing MSPs meet regularly to share strategies, discuss challenges, and collaborate on business development. Quarterly events provide additional networking opportunities.
* **Main Events:** Quarterly Business Reviews.
* **Target Audience:** MSP executives and owners seeking strategic guidance and peer collaboration.
* **Link:** [Visit IT Nation Evolve](https://www.connectwise.com/theitnation/evolve)

***

#### **4. SMBiT Professionals**

* **Overview:**\
  Based in Australia, SMBiT serves MSPs with small to mid-sized clients. The group offers best practices for efficiency and growth, as well as monthly chapter meetings for networking. Members also access vendor discounts, industry insurance, and other business resources.
* **Main Events:** Monthly chapter meetings across Australia and New Zealand.
* **Target Audience:** MSPs serving SMB clients.
* **Link:** [Visit SMBiT Professionals](https://www.smbitpro.org/)

***

#### **5. MSP-Ignite**

* **Overview:**\
  MSP-Ignite facilitates peer groups led by business advisors who help members collaborate on profitability, growth, and operational challenges. Groups consist of MSPs from non-competing industries, ensuring open and candid discussions.
* **Main Events:** Biannual meetings and webinars.
* **Target Audience:** MSPs focused on profitability and collaborative problem-solving.
* **Link:** [Visit MSP-Ignite](https://www.msp-ignite.com/)

***

#### **6. The Network Group**

* **Overview:**\
  A UK-based peer group, The Network Group connects IT businesses and MSPs through live events and vendor collaborations. Members gain access to operational tools, training, vendor discounts, and large-scale events like VISION and FOCUS.
* **Main Events:** VISION and FOCUS, plus regional roadshows.
* **Target Audience:** UK-based MSPs and IT channel businesses.
* **Link:** [Visit The Network Group](https://www.nbg.co.uk/)

***

#### How to Choose a Peer Group

1. **Define Your Needs:**
   * For global resources and support, consider The Tech Tribe.
   * For marketing and networking, ASCII Group is a strong choice.
   * If you're seeking location-specific resources, SMBiT or The Network Group may be better suited.
2. **Evaluate Costs and Benefits:**
   * Membership fees often come with perks such as vendor discounts or curated resources.
3. **Commit to Engagement:**
   * Participate actively in meetings, share insights, and take full advantage of the tools and events offered.

Peer groups are invaluable for fostering collaboration and driving MSP growth. By joining the right group, you can gain new perspectives, strengthen your network, and achieve your business goals.


# Social Media communities

**All Things MSP (Eric Anthony)**

All Things MSP is a Facebook group that serves as a platform for MSP professionals to share ideas, resources, and experiences related to the MSP industry.

**Link:** <https://www.facebook.com/groups/allthingsmsp/>

**Everything MSP (Dan Tomaszewski)**

Everything MSP is a Facebook group dedicated to MSPs, covering various topics, including technology, business growth, and industry trends.

**Link:** <https://www.facebook.com/groups/everythingmsp/>

**ConnectWise Boss (Adam Bolanski)**

ConnectWise Boss is a Facebook group for MSPs who use ConnectWise products. The group provides a platform for users to discuss best practices, share tips, and network with fellow professionals.

**Link:** <https://www.facebook.com/groups/CWBoss/>

**IT Managed Services**

This LinkedIn group is dedicated to IT managed services, providing a space for professionals to discuss industry trends, share resources, and network with peers.

**Link:** <https://www.linkedin.com/groups/38615/>

**CompTIA Connect**

CompTIA Connect is a LinkedIn group for IT professionals and MSPs, offering resources, discussions, and networking opportunities related to the IT industry.

**Link:** <https://www.linkedin.com/groups/83900/>

**MSP 501**

MSP 501 is a LinkedIn group focused on managed services providers, covering topics such as industry trends, best practices, and business growth.

**Link:** <https://www.linkedin.com/groups/2729912/>


# Business Resources

Blogs, books, podcasts, and webinars to help MSPs grow the business side of their practice.

Online business resources for MSPs, such as blogs, books, webinars, and podcasts, offer invaluable insights and tools to help Managed Service Providers grow and thrive in a competitive industry. These resources cover a wide range of topics, catering to both technical and business-focused MSPs.

Blogs and books provide in-depth analysis and practical advice on various aspects of running an MSP business, including marketing, sales, customer relations, and operations management. By staying current with industry trends and learning from the experiences of successful MSP leaders, professionals can enhance their skills and implement best practices to drive their businesses forward.

Webinars and podcasts offer opportunities for MSPs to gain knowledge from industry experts, covering topics such as new technologies, security, and business growth strategies. These resources provide valuable learning experiences that can help MSPs stay up-to-date with the latest developments and best practices in the managed services industry.

By leveraging these online business resources, MSPs can continuously refine their strategies, services, and processes, ensuring their success in the ever-changing landscape of managed services.

### In this section

{% content-ref url="/pages/ONYw2qr0W4iQWhHaVb7n" %}
[Podcasts & Webinars](/resources/business-resources/podcasts-and-webinars)
{% endcontent-ref %}

{% content-ref url="/pages/27OmJqN4eyNa43G99u6B" %}
[Blogs & Books](/resources/business-resources/blogs-and-books)
{% endcontent-ref %}


# Podcasts & Webinars

#### MSP Podcasts

#### The MSP Voice

\[blurb]

**Link:** <https://mspvoice.com/>

#### The IT Provider Network

\[blurb]

**Link:** <https://www.itprovidernetwork.com/>

#### Frankly MSP Podcast

\[blurb]

**Link:** <https://www.franklymsp.com/>

#### MSP Growth Hacks

\[blurb]

**Link:** <https://mspgh.com/>

#### The Continuum Podcast Network

\[blurb]

**Link:** <https://www.continuum.net/podcast>

#### The Confessions of an IT Business Owner

\[blurb]

**Link:** <https://connectbooster.com/podcast/>

#### TubbTalk - The Podcast for IT Consultants

\[blurb]

**Link:** <https://www.tubblog.co.uk/tubbtalk-podcast/>

#### The Business of Tech

In an industry that always changes, those who deliver technology services need to focus on the information that matters to them. The Business of Tech podcast focuses on the news you need to know. Covering both the story and asking "why do we care" to the way services are created and delivered, channel veteran Dave Sobel brings you up to speed and gives you resources to go deeper. With insights and analysis, this five-minute podcast focuses on the knowledge you need to be effective, profitable, and relevant

**Link:** <https://www.businessof.tech/>


# Blogs & Books

#### Operational Maturity by Auvik

This blog decribes operational maturity levels and how to target growth

**Link:** <https://www.auvik.com/franklyit/blog/msp-operational-maturity/>

#### Jay McBain

\[blurb]

**Link:** <https://www.forrester.com/blogs/top-143-social-media-groups-for-msps-vars-and-tech-channel-professionals>

**Link:** [https://www.forrester.com/blogs/the-100-best-channel-podcasts-of-2021/](https://www.forrester.com/blogs/the-100-best-channel-podcasts-of-2021)


# Technical Resources

Technical blogs, books, podcasts, and a curated MSP toolkit of hands-on tools.

Online business resources for MSPs, such as blogs, books, webinars, and podcasts, offer invaluable insights and tools to help Managed Service Providers grow and thrive in a competitive industry. These resources cover a wide range of topics, catering to both technical and business-focused MSPs.

Blogs and books provide in-depth analysis and practical advice on various aspects of running an MSP business, including marketing, sales, customer relations, and operations management. By staying current with industry trends and learning from the experiences of successful MSP leaders, professionals can enhance their skills and implement best practices to drive their businesses forward.

Webinars and podcasts offer opportunities for MSPs to gain knowledge from industry experts, covering topics such as new technologies, security, and business growth strategies. These resources provide valuable learning experiences that can help MSPs stay up-to-date with the latest developments and best practices in the managed services industry.

By leveraging these online business resources, MSPs can continuously refine their strategies, services, and processes, ensuring their success in the ever-changing landscape of managed services.

### In this section

{% content-ref url="/pages/9JQJxkdi4JCLojNnJX1J" %}
[Podcasts & Webinars](/resources/technical-resources/podcasts-and-webinars)
{% endcontent-ref %}

{% content-ref url="/pages/GAKrXzso6zFcTXWoCwoO" %}
[Blogs & Books](/resources/technical-resources/blogs-and-books)
{% endcontent-ref %}

{% content-ref url="/pages/HSmSws9vR19umoO6p2QQ" %}
[MSP Toolkit](/resources/technical-resources/msp-toolkit)
{% endcontent-ref %}


# Podcasts & Webinars


# Blogs & Books

#### The RMM comparison sheet

This online excel sheet contains a compare of all current RMM products. The sheet is completely community sourced and based on data by actual users.

**Link:** [http://rmm.msp.zone](http://rmm.msp.zone/)

#### CyberDrain

CyberDrain is a techblog that contains PowerShell scripts, resources for MSPS, and announcements important to technichians at MSPs. CyberDrain also organizes several events such as the CyberDrain CTF.

**Link:** <https://cyberdrain.com>


# MSP Toolkit

A curated list of popular, practical tools MSP technicians reach for regularly.

The MSP Toolkit is a curated list of popular tools which are used regularly. Take look as some of the tools listed, and if you want to share your own, then do so!

### In this section

{% content-ref url="/pages/grYnakZkLKDtt3w1rvHK" %}
[Screen Capture](/resources/technical-resources/msp-toolkit/screen-capture)
{% endcontent-ref %}

{% content-ref url="/pages/OmItCJXOEqPWPVP5hFEQ" %}
[USB Stick Essentials](/resources/technical-resources/msp-toolkit/usb-stick-essentials)
{% endcontent-ref %}


# Screen Capture

Tools for capturing screenshots, GIFs, and video guides.

These tools specifically deal with screen capture. For example the creation of screenshots, gifs or video guides.

### In this section

{% content-ref url="/pages/SD4Y26iJLOAmIJ6v9T9e" %}
[Greenshot](/resources/technical-resources/msp-toolkit/screen-capture/greenshot)
{% endcontent-ref %}

{% content-ref url="/pages/U7Gls8IRz224H6zP9pqI" %}
[PSR](/resources/technical-resources/msp-toolkit/screen-capture/problem-screen-recorder)
{% endcontent-ref %}

{% content-ref url="/pages/gFFhwWT8g7zmRM6gsyuZ" %}
[ShareX](/resources/technical-resources/msp-toolkit/screen-capture/sharex)
{% endcontent-ref %}


# Greenshot

What is Greenshot? Greenshot is a light-weight screenshot software tool for Windows with the following key features:

Quickly create screenshots of a selected region, window or fullscreen; you can even capture complete (scrolling) web pages from Internet Explorer. Easily annotate, highlight or obfuscate parts of the screenshot. Export the screenshot in various ways: save to file, send to printer, copy to clipboard, attach to e-mail, send Office programs or upload to photo sites like Flickr or Picasa, and others. …and a lot more options simplifying creation of and work with screenshots every day.

Being easy to understand and configurable, Greenshot is an efficient tool for project managers, software developers, technical writers, testers and anyone else creating screenshots.

**Pricing:** Free / Open Source

**Link:** <http://getgreenshot.org/>

**Download:** <http://getgreenshot.org/downloads/>


# PSR

Problem Screen Recorder. Is a handy screen grabber and set by step documentation tool. It is built directly into Windows 7+

## To record and save steps on your computer

* To open Steps Recorder, select the **Start** button, and then select **Windows Accessories** > **Steps Recorder** (in Windows 10), or **Accessories** > **Problem Steps Recorder** (in Windows 7 or Windows 8.1)
* Select **Start Record**
* Go through the steps to reproduce or solve the problem. You can pause and resume the recording at any time.
* As you record, select **Add Comment**, use your mouse to select the part of the screen that you want to comment on, type your comment, and then select **OK**
* When you’re done, select **Stop Record**
* Review the record of the steps you followed to make sure it shows what you want it to show. Select **Save**, name the .zip file, choose where to save it, and then select **Save**. Now you can attach and send this .zip file to the person helping you troubleshoot the problem on your PC. It can be viewed in any web browser.


# ShareX

![Sharex](/files/kDjKE60KQJ22Qb6HqVNv)

## Features

### Capturing

ShareX incorporates the following methods to allow screen capture.

* Fullscreen
* Active window
* Active monitor
* Window menu
* Monitor menu
* Region
* Region (Light)
* Region (Transparent)
* Last region
* Custom region
* Screen recording
* Screen recording (GIF)
* Scrolling capture
* Webpage capture
* Text capture (OCR)
* Auto capture

### Region capture tools

* Region
  * Rectangle
  * Rounded rectangle
  * Ellipse
  * Freehand
* Drawing
  * Rectangle
  * Rounded rectangle
  * Ellipse
  * Freehand
  * Line
  * Arrow
  * Text
  * Speech balloon
  * Step
  * Image
* Effect
  * Blur
  * Pixelate
  * Highlight

### After capture tasks

You can select any or all of these tasks to be automatically run after each screen capture.

* Show quick task menu
* Show "After capture" window
* Add image effects / watermark
* Open in image editor
* Copy image to clipboard
* Print image
* Save image to file
* Save image to file as
* Save thumbnail image to file
* Perform actions
* Copy file to clipboard
* Copy file path to clipboard
* Show file in explorer
* Recognize text (OCR)
* Show "Before upload" window
* Upload image to host
* Delete file locally

### Uploading

ShareX has multiple ways to upload files.

* Upload file
* Upload folder
* Upload from clipboard
* Upload from URL
* Drag and drop upload (drop area or main window)
* Upload from Windows shell context menu
* Upload from Windows send to menu
* Watch folder

### After upload tasks

These tasks will automatically run after successful upload to any host.

* Show "After upload" window
* Shorten URL
* Share URL
* Copy URL to clipboard
* Open URL
* Show QR code window

## Destinations

ShareX supports the following destinations.

### Image uploaders

* [Imgur](http://imgur.com)
* [ImageShack](https://imageshack.us)
* [TinyPic](http://tinypic.com)
* [Flickr](https://www.flickr.com)
* [Photobucket](http://photobucket.com)
* [Google Photos Picasa](https://picasaweb.google.com)
* [Twitter](https://twitter.com)
* [Chevereto](https://chevereto.com)
* [UltraIMG](http://ultraimg.com)
* [Yukle.at](http://yukle.at)
* [PatiFile](http://img.patifile.com)
* [BoltIMG](http://boltimg.com)
* [Snapie](http://snapie.net)
* [picgur](http://picgur.org)
* [pixr](http://pixr.co)
* [sexr](http://sexr.co)
* [Lightpics](http://lightpics.net)
* [Imgfly](http://imgfly.me)
* [ImgPinas](http://imgpinas.com)
* [imu.gr](http://imu.gr)
* [Upsieutoc](http://www.upsieutoc.com)
* [StoreMyPic](http://www.storemypic.com)
* [TL Things](http://i.tlthings.net)
* [vgy.me](http://vgy.me)
* [SomeImage](https://someimage.com)
* [Imgland](http://imgland.net)
* [SLiMG](https://sli.mg)
* [Custom image uploader](https://github.com/ShareX/CustomUploaders)

### Text uploaders

* [Pastebin](http://pastebin.com)
* [Paste2](http://paste2.org)
* [Slexy](http://slexy.org)
* [Pastee.org](https://pastee.org)
* [Paste.ee](https://paste.ee)
* [GitHub Gist](https://gist.github.com)
* [uPaste](http://upaste.me)
* [Hastebin](http://hastebin.com)
* [OneTimeSecret](https://onetimesecret.com)
* [Custom text uploader](https://github.com/ShareX/CustomUploaders)

### File uploaders

* [Dropbox](https://www.dropbox.com)
* [FTP](https://en.wikipedia.org/wiki/File_Transfer_Protocol)
* [OneDrive](https://onedrive.live.com)
* [Google Drive](https://drive.google.com)
* [puush](http://puush.me)
* [Box](https://www.box.com)
* [MEGA](https://mega.co.nz)
* [Amazon S3](http://aws.amazon.com/s3/)
* [ownCloud](https://owncloud.org)
* [MediaFire](https://www.mediafire.com)
* [Gfycat](http://gfycat.com)
* [Pushbullet](https://www.pushbullet.com)
* [SendSpace](https://www.sendspace.com)
* [Minus](http://minus.com)
* [Ge.tt](http://ge.tt)
* [Hostr](https://hostr.co)
* [JIRA](https://www.atlassian.com/software/jira)
* [Lambda](http://lambda.sx)
* [VideoBin](http://videobin.org)
* [Pomf](https://github.com/nokonoko/Pomf)
* [1339.cf](http://1339.cf)
* [catgirlsare.sexy](https://catgirlsare.sexy)
* [comfy.moe](http://comfy.moe)
* [cocaine.ninja](https://cocaine.ninja)
* [cuntflaps.me](http://cuntflaps.me)
* [files.plebeianparty.com](http://files.plebeianparty.com)
* [g.zxq.co](http://g.zxq.co)
* [glop.me](http://glop.me)
* [kyaa.sg](http://kyaa.sg)
* [maxfile.ro](https://maxfile.ro)
* [mixtape.moe](https://mixtape.moe)
* [nigger.cat](https://nigger.cat)
* [pomf.cat](https://pomf.cat)
* [pomf.hummingbird.moe](http://pomf.hummingbird.moe)
* [pomf.is](https://pomf.is)
* [reich.io](http://reich.io)
* [sugoi.vidyagam.es](https://sugoi.vidyagam.es)
* [up.che.moe](http://up.che.moe)
* [Uguu](https://uguu.se)
* [Dropfile](https://dropfile.to)
* [Seafile](https://www.seafile.com)
* [Streamable](https://streamable.com)
* [s-ul](https://s-ul.eu)
* [Lithiio](https://lithi.io)
* [transfer.sh](https://transfer.sh)
* [Uplea](http://uplea.com)
* Shared Folders
* [Email](https://en.wikipedia.org/wiki/Email)
* [Custom file uploader](https://github.com/ShareX/CustomUploaders)

### URL shorteners

* [bit.ly](https://bitly.com)
* [goo.gl](https://goo.gl)
* [is.gd](https://is.gd)
* [v.gd](https://v.gd)
* [tinyurl.com](http://tinyurl.com)
* [turl.ca](http://turl.ca)
* [yourls.org](http://yourls.org)
* [adf.ly](https://adf.ly)
* [coinurl.com](https://coinurl.com)
* [qr.net](http://qr.net)
* [vurl.com](http://vurl.com)
* [2.gp](http://2.gp)
* [Polr](https://github.com/Cydrobolt/polr)
* [Custom URL shortener](https://github.com/ShareX/CustomUploaders)

### URL sharing services

* [Email](https://en.wikipedia.org/wiki/Email)
* [Twitter](https://twitter.com)
* [Facebook](https://www.facebook.com)
* [Google+](https://plus.google.com)
* [Reddit](http://www.reddit.com)
* [Pinterest](https://www.pinterest.com)
* [Tumblr](https://www.tumblr.com)
* [LinkedIn](https://www.linkedin.com)
* [StumbleUpon](https://www.stumbleupon.com)
* [Delicious](https://delicious.com)
* [VK](https://vk.com)
* [Pushbullet](https://www.pushbullet.com)

## Tools

Productivity tools to make certain tasks more efficient.

* Color picker
* Screen color picker
* Image editor
* Image effects
* Hash check
* DNS changer
* QR code
* Ruler
* Automate
* Directory indexer
* Image combiner
* Video thumbnailer
* FTP client
* Tweet message
* Monitor test

Pricing: Free / Open Source

**Link:** [ShareX](https://getsharex.com)


# USB Stick Essentials

Portable go-to tools worth keeping on your USB stick.

These are the best tools to carry about on your favorite USB Stick. We all have those "go-to tools" so why keep them to yourself?

### In this section

{% content-ref url="/pages/6JXl0c93EoG5QrJuxv5N" %}
[User Profile Wizard](/resources/technical-resources/msp-toolkit/usb-stick-essentials/user-profile-wizard)
{% endcontent-ref %}

{% content-ref url="/pages/h2v19oqwEwMf7curzezg" %}
[PortableApps](/resources/technical-resources/msp-toolkit/usb-stick-essentials/portableapps)
{% endcontent-ref %}


# User Profile Wizard

User Profile Wizard 3.11 is the latest version of ForensiT's powerful workstation migration tool. User Profile Wizard will migrate your current user profile to your new user account so that you can keep all your existing data and settings.

## Large-scale migration made easy

User Profile Wizard has been used to automatically migrate hundreds of thousands of workstations to new domains. It can be used to migrate workstations to a new domain from any existing Windows network, or from a Novell NDS network; it can join standalone computers to a domain for the first time, or migrate workstations from a domain back to a workgroup.

## No need to lose personal data and settings

A User Profile is where Windows stores your stuff. Normally, when you change your user account Windows will create a new profile for you, and you lose all your data and settings - your “My Documents”, “My Pictures” and “My Music” files and all the other information that makes your computer personal to you, like your desktop wallpaper, Internet favorites and the lists of documents you've recently opened.

User Profile Wizard is an easy-to-use migration tool that means this doesn’t need to happen – you can simply migrate your original profile to your new user account. User Profile Wizard does not move, copy or delete any data. Instead it configures the profile “in place” so that it can be used by your new user account. This makes the process both very fast and very safe.

With the User Profile Wizard Deployment Kit you can build a scalable, enterprise solution to automatically migrate tens of thousands of workstations.

## Scalable - up or down

Unlike some alternatives, User Profile Wizard does not assume that there is an enterprise directory in place. It supports all environments from Small Business Server through to a Global Domain Consolidation.

## Benefits

Migrates all user profile data and settings on Windows XP/Windows 7/8 and Windows 10 Automatically joins a machine to a new domain Supports domain migrations over a VPN Supports all Active Directory and Samba domains Migrates from a domain back to a workgroup Includes Enterprise strength scripting support Supports push migrations of remote machines Tried and trusted - over one million licenses sold

**Link:** <http://www.forensit.com/>

**Download:** <http://www.forensit.com/domain-migration.html>


# PortableApps

By far the best starting point for any engineer is the PortableApps USB Stick. This really is the powerhouse of tools. What makes it unique is you can install a massive amount of standalone applications on your USB stick, and run them with no additional installation required on the client PC. This is useful for those systems that are reasonably secure, but still allow you USB access. Check out the suite here:

![PortableApps](/files/Z9OGwHzFQT0RT5mVlzrI)

**Link:** <http://portableapps.com/>

**Download:** [http://portableapps.com/download](http://portableapps.com/)


