Agents Reference

Agents are specialized subagents that perform multi-step MSP workflows autonomously. There are 146 agents across all plugins.

What are Agents?

Agents combine skills, commands, and domain knowledge to execute higher-level tasks — auditing a tenant, reconciling billing, triaging an alert — without you walking Claude through every step. Each agent is scoped to a clear role and a focused set of tools.

/agent identity-auditor "Audit Acme Corp's M365 tenant"

Agents by Category

Auditing & Compliance

Agents that audit configurations, identities, devices, and surface compliance gaps.

Agent Plugin Description
compliance-reporter Blumira Use this agent when generating compliance-oriented security reports from Blumira SIEM data — not for live incident investigation, but for producing evidence packages, coverage gap assessments, and log source health summaries for frameworks like SOC 2, HIPAA, and CIS.
tenant-policy-auditor Checkpoint Avanan Use this agent when an MSP needs to audit email security policy completeness and correctness across Avanan (Check Point Harmony Email & Collaboration) managed tenants — verifying anti-phishing coverage, attachment sandboxing, impersonation protection, DLP rules, and exception hygiene.
rmm-health-auditor Datto RMM Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet.
documentation-auditor Hudu Use this agent when an MSP technician or vCIO needs to find and fix documentation debt in Hudu.
runbook-freshness-auditor Hudu Use this agent when an MSP needs to audit the currency and coverage of runbooks and SOPs in Hudu.
documentation-auditor IT Glue Use this agent when an MSP needs to audit documentation completeness and freshness across their IT Glue client portfolio.
identity-auditor Microsoft 365 Use this agent when an MSP needs to perform a comprehensive Microsoft 365 tenant security audit.
license-auditor Microsoft 365 Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant.
device-health-auditor NinjaOne (NinjaRMM) Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio.
patch-compliance-reporter NinjaOne (NinjaRMM) Use this agent when an MSP needs dedicated patch compliance reporting across their NinjaOne-managed portfolio — not a general health check, but a focused analysis of OS patch levels, third-party application versions, missing critical patches, devices pending reboot, and patch policy exceptions.
email-security-auditor Proofpoint Use this agent when auditing email security posture across Proofpoint-protected organizations, investigating threats via TAP intelligence, tracing specific emails, analyzing Very Attacked Persons (VAPs), or generating per-org security reports for MSP clients.
endpoint-hardening-auditor SentinelOne Use this agent when an MSP needs to audit and harden SentinelOne endpoint configuration across client sites — not to investigate active threats, but to proactively identify gaps before attackers can exploit them.
customer-account-auditor Sherweb Use this agent when an MSP needs a portfolio-wide health audit of its Sherweb customer accounts — enumerating all customers, checking accounts-receivable standing, correlating each customer's subscription footprint, and flagging accounts that are at financial or provisioning risk.
billing-auditor Syncro MSP Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization.
compliance-auditor Immybot Use this agent when an MSP needs a software-compliance audit across their ImmyBot-managed tenant portfolio — per-tenant compliance scorecards, failing-deployment analysis, software-inventory rollups, and task-queue health for QBR or operational reporting.
booking-pipeline-auditor Timezest Use this agent when reporting on the TimeZest scheduling pipeline — grouping requests by lifecycle state, finding stale requests waiting on customers, measuring booking conversion, and producing a dispatch-queue view across agents and teams.
fleet-health-auditor Threatlocker Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations.
asset-reconciliation-auditor Wyre Gateway Use this agent when an MSP needs to reconcile its asset estate across managed, secured, billed, and documented systems to surface security coverage gaps, revenue leakage, ghost assets, and shadow IT.
dr-readiness-auditor Wyre Gateway Use this agent when an MSP needs to assess the true disaster-recovery readiness of a client — going beyond backup dashboard green lights to evaluate coverage, test-restore history, runbook maturity, and RTO/RPO achievability.
service-profitability-auditor Wyre Gateway Use this agent when an MSP owner, operations leader, or finance lead needs to identify which clients and contracts are losing money or eroding margin across the portfolio.
meraki-network-auditor Meraki Use this agent when an MSP needs a read-only health and security audit of a Cisco Meraki organization — sweeping networks, devices, and appliances to surface offline or alerting hardware, appliances with site-to-site VPN peers down, overly-permissive firewall rules, and SSIDs configured with weak or open authentication.
device-auditor Ncentral Use this agent when the user wants a device audit across N-central customers - inventory sweeps, missing asset data, expired or expiring warranties, untracked lifecycle records, or failed service monitors.
board-health-auditor Ops Pack Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report.
pipeline-auditor Sales Pack Use this agent when a sales manager, deal desk owner, or MSP leadership needs a full cross-vendor sweep of the open sales pipeline — stalled and at-risk deals ranked by value and staleness, with each stall diagnosed against the full quote-to-close chain rather than CRM activity alone.
network-health-auditor Cloudops Pack Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected.
training-compliance-auditor Awareness Pack Use this agent when the MSP needs to verify security-awareness training completion for a single client or across the whole portfolio, and flag overdue users or clients falling behind their expected training cadence.
backup-health-auditor Backup Pack Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity.
retention-compliance-auditor Backup Pack Use this agent when an MSP needs to verify that actual backup retention configuration and cadence meet contracted or required retention/RPO policy, rather than assuming appliance defaults are adequate.
warranty-status-auditor Assets Pack Use this agent when someone needs a portfolio-wide or client-specific view of hardware warranty coverage, pulled and normalized across every connected RMM and documentation tool.

Health & Monitoring

Agents that watch backups, automation, uptime, and overall customer health.

Agent Plugin Description
customer-health-scorer Atera Use this agent when an MSP account manager, service manager, or owner needs to score and rank client health across the Atera portfolio — not live operations management, but a structured assessment of each client based on device health trends, ticket velocity, recurring issues, patch compliance, and alert frequency.
sla-uptime-reporter BetterStack Use this agent when an MSP needs to generate SLA-focused uptime reports for clients, calculate SLA achievement percentages, identify chronic underperforming monitors, or produce client-facing availability summaries.
uptime-incident-responder BetterStack Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report.
automation-health-checker ConnectWise Automate Use this agent when an MSP technician or engineer needs to audit the health of their ConnectWise Automate RMM environment.
backup-health-monitor Datto RMM Use this agent when an MSP needs to audit backup and BC/DR health across their Datto RMM managed client portfolio — not a general fleet health check, but a focused review of backup job success rates, last successful backups per device, retention policy compliance, offsite replication status, and restore test records.
rmm-health-auditor Datto RMM Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet.
device-health-auditor NinjaOne (NinjaRMM) Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio.
fleet-health-auditor Threatlocker Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations.
pipeline-health-reporter HubSpot CRM Use this agent when an MSP sales manager or leadership needs to analyze pipeline health, deal velocity, stage conversion rates, or forecast accuracy in HubSpot.
board-health-auditor Ops Pack Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report.
network-health-auditor Cloudops Pack Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected.
backup-health-auditor Backup Pack Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity.

Incident & Service Desk

Agents that triage alerts, drive incidents, and run service desk operations.

Agent Plugin Description
uptime-incident-responder BetterStack Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report.
service-desk-ops ConnectWise PSA Use this agent when an MSP dispatcher, service manager, or team lead needs to review the current state of the ConnectWise Manage service desk.
service-desk-ops HaloPSA Use this agent when an MSP dispatcher, team lead, or service manager needs to triage and manage the HaloPSA ticket queue.
incident-responder Huntress Use this agent when triaging Huntress incidents, reviewing SOC escalations, approving or rejecting endpoint remediations, investigating security signals, or managing the Huntress agent fleet across MSP client organizations.
change-detective Liongard Use this agent when an MSP needs to detect unauthorized or unexpected configuration changes, audit compliance drift, or surface undocumented systems across their client environments.
incident-commander PagerDuty Use this agent when an MSP engineer, SRE, or incident manager needs to command an active incident or review the state of open PagerDuty incidents.
soc-alert-investigator RocketCyber Use this agent when an MSP needs to investigate and triage RocketCyber SOC alerts and security incidents across their client portfolio.
incident-commander Rootly Use this agent when an MSP engineer, SRE, or incident manager needs to command an active Rootly incident or review open incidents.
incident-war-room-coordinator Wyre Gateway Use this agent when a major incident (P1 or Critical severity) has been declared or is suspected, and the team needs immediate situational awareness across all affected systems and stakeholders.
incident-timeline-builder Secops Pack Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question.

Client Lifecycle

Agents that handle onboarding, contracts, and renewal tracking.

Agent Plugin Description
contract-renewal-tracker Autotask PSA Use this agent when an MSP account manager, service manager, or operations lead needs to track and manage contract renewals in Autotask PSA — surfacing expiring contracts, identifying auto-renewal gaps, tracking MRR/ARR trends, and flagging clients who are still receiving service on expired contracts.
client-onboarding-validator Huntress Use this agent when validating a newly onboarded client in Huntress — checking that agents are deployed and reporting, confirming SOC coverage is active, identifying any endpoints missing agents, and surfacing initial detections that fired during or after deployment.
contract-tracker PandaDoc Use this agent when an MSP sales coordinator or account manager needs to track the status of pending proposals and contracts in PandaDoc.
renewal-calendar Pax8 Use this agent when an MSP needs a proactive view of upcoming Pax8 subscription renewals across all clients, wants to flag month-to-month subscriptions that should move to annual, or needs to identify annual renewals that require a seat count review before they lock in.
onboarding-completeness-checker Wyre Gateway Use this agent when an MSP needs to validate that a newly onboarded client has been fully set up across all MSP tools and systems before transitioning to steady-state support.
renewal-risk-analyzer Wyre Gateway Use this agent when an MSP account manager, sales leader, or operations manager wants to identify clients at risk of not renewing before the renewal conversation happens.
renewal-calendar-builder Finance Pack Use this agent when an MSP account manager, sales leader, or operations manager needs a forward-looking view of every upcoming contract and subscription renewal across the connected PSA and cloud-marketplace distributors, with recommended lead time per renewal.

Financial Operations

Agents focused on billing, licensing, margins, and procurement.

Agent Plugin Description
procurement-specialist ConnectWise PSA Use this agent when an MSP procurement lead, sales engineer, service manager, or owner needs to work against the ConnectWise Manage product catalog and the procurement/quoting workflows it feeds.
license-auditor Microsoft 365 Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant.
license-optimizer Pax8 Use this agent when an MSP needs to analyze license utilization across their Pax8 marketplace subscriptions, identify unused or over-provisioned seats, optimize costs, or plan renewals.
billing-reconciler QuickBooks Online Use this agent when an MSP needs to reconcile billing in QuickBooks Online — matching invoices to contracts, identifying unbilled work, flagging overdue accounts, or auditing revenue recognition.
margin-analyzer SalesBuildr Use this agent when an MSP sales manager or finance lead needs to analyze quote margin health across recent quotes in Salesbuildr.
billing-reconciler Sherweb Use this agent when an MSP needs to reconcile Sherweb distributor billing — reviewing payable charges for a billing period, drilling into individual charge details, separating Setup/Recurring/Usage charge types, verifying that billed quantities match active subscriptions, and calculating MSP margin between Sherweb cost and customer price.
billing-auditor Syncro MSP Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization.
billing-reconciler Xero Use this agent when an MSP needs to reconcile billing in Xero — matching invoices to contracts, tracking outstanding receivables, identifying billing discrepancies, or reviewing cash flow.
license-true-up-reconciler Wyre Gateway Use this agent when an MSP operations manager, account manager, or billing team needs to reconcile subscription license seats across the full provisioning-to-billing chain and quantify waste, leakage, and over-collection.
billing-drift-detector Finance Pack Use this agent when an MSP billing team, controller, or account manager needs to run a portfolio-wide sweep for contract-vs-invoice mismatches — surfacing every client where the PSA agreement and the accounting invoice disagree, ranked by dollar impact.

Documentation & Insights

Agents that link assets to documentation and surface optimization opportunities.

Agent Plugin Description
asset-documentation-linker IT Glue Use this agent when an MSP needs to find and fix broken or missing linkages between IT Glue objects — configurations without passwords, devices without runbooks, organizations without network diagrams, contacts unlinked from assets.
automation-opportunity-finder SuperOps.ai Use this agent when an MSP operations lead, service manager, or technician wants to identify repetitive ticket patterns in SuperOps.ai that should be automated — not live operations management, but a retrospective analysis of ticket history to find recurring issues with the same client, same category, and same resolution, calculate the manual time cost, and recommend runbooks or automation scripts to eliminate the pattern.

All Agents by Plugin

Abnormal Security

Agent Description
email-threat-analyst Use this agent when investigating email threats detected by Abnormal Security, analyzing attack chains, assessing user exposure, or managing remediation across client tenants.
threat-report-generator Use this agent when generating periodic threat landscape reports from Abnormal Security data across the MSP client portfolio — not for live threat investigation, but for summarizing attack trends, most targeted organizations, most common attack types, BEC attempt volumes, and remediation effectiveness over time.

Atera

Agent Description
customer-health-scorer Use this agent when an MSP account manager, service manager, or owner needs to score and rank client health across the Atera portfolio — not live operations management, but a structured assessment of each client based on device health trends, ticket velocity, recurring issues, patch compliance, and alert frequency.
msp-ops-assistant Use this agent when an MSP needs combined RMM and PSA operations assistance through Atera — triaging alerts, managing the ticket queue, checking device health, and identifying patterns across the client base.

Auvik

Agent Description
alert-responder Use this agent for Auvik alert-related questions - what's open, what matters, what to dismiss, what to escalate.
capacity-planner Use this agent for Auvik utilization, saturation, and headroom questions - "is this link maxed out?", "what links need an upgrade?", "where is the bottleneck?".
network-analyst Use this agent when the user is asking what's wrong with a tenant's network, investigating broad performance complaints, mapping topology, or doing multi-signal triage across devices, interfaces, alerts, and statistics in Auvik.

Autotask PSA

Agent Description
contract-renewal-tracker Use this agent when an MSP account manager, service manager, or operations lead needs to track and manage contract renewals in Autotask PSA — surfacing expiring contracts, identifying auto-renewal gaps, tracking MRR/ARR trends, and flagging clients who are still receiving service on expired contracts.
ticket-dispatcher Use this agent when an MSP dispatcher or service manager needs to intelligently manage the Autotask PSA ticket queue — reviewing priorities, suggesting technician assignments, monitoring SLA compliance, and driving dispatch decisions.

BetterStack

Agent Description
sla-uptime-reporter Use this agent when an MSP needs to generate SLA-focused uptime reports for clients, calculate SLA achievement percentages, identify chronic underperforming monitors, or produce client-facing availability summaries.
uptime-incident-responder Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report.

Blumira

Agent Description
compliance-reporter Use this agent when generating compliance-oriented security reports from Blumira SIEM data — not for live incident investigation, but for producing evidence packages, coverage gap assessments, and log source health summaries for frameworks like SOC 2, HIPAA, and CIS.
siem-investigator Use this agent when investigating Blumira SIEM alerts and findings, tracing attack chains across data sources, resolving detections, auditing security posture across MSP client accounts, or producing threat investigation reports.

Checkpoint Avanan

Agent Description
cloud-email-defender Use this agent when investigating quarantined threats, managing email security events, auditing Avanan tenant configuration, or performing cross-tenant threat sweeps in Check Point Avanan (Harmony Email & Collaboration).
tenant-policy-auditor Use this agent when an MSP needs to audit email security policy completeness and correctness across Avanan (Check Point Harmony Email & Collaboration) managed tenants — verifying anti-phishing coverage, attachment sandboxing, impersonation protection, DLP rules, and exception hygiene.

CIPP

Agent Description
security-posture-reviewer Use this agent when an MSP security lead, vCISO, or service manager needs to sweep the M365 portfolio for security posture issues — Secure Score regressions, MFA enrollment gaps, conditional access drift, BPA failures, and broken domain authentication.
user-offboarding-runner Use this agent when an MSP technician, dispatcher, or HR-facing operator needs to run a complete M365 user offboarding through CIPP.

Freshdesk

Agent Description
freshdesk-triage Use this agent when an MSP dispatcher, service coordinator, or help-desk lead needs to sweep the Freshdesk open ticket queue, summarize what is waiting, and recommend routing and priority.

Inforcer

Agent Description
inforcer-drift-reporter Use this agent when an MSP security lead, vCISO, or service manager needs to sweep the managed Microsoft 365 portfolio for baseline drift and posture using Inforcer — pulling alignment scores, per-policy drift detail, and secure scores across tenants and summarizing them into a prioritized picture.

ConnectWise Automate

Agent Description
automation-health-checker Use this agent when an MSP technician or engineer needs to audit the health of their ConnectWise Automate RMM environment.

ConnectWise PSA

Agent Description
procurement-specialist Use this agent when an MSP procurement lead, sales engineer, service manager, or owner needs to work against the ConnectWise Manage product catalog and the procurement/quoting workflows it feeds.
project-tracker Use this agent when an MSP project manager, service manager, or operations lead needs a review of all open projects in ConnectWise Manage — checking milestone deadlines, budget vs. actuals, overdue phases, and projects at risk of scope creep or delivery failure.
service-desk-ops Use this agent when an MSP dispatcher, service manager, or team lead needs to review the current state of the ConnectWise Manage service desk.

Datto RMM

Agent Description
backup-health-monitor Use this agent when an MSP needs to audit backup and BC/DR health across their Datto RMM managed client portfolio — not a general fleet health check, but a focused review of backup job success rates, last successful backups per device, retention policy compliance, offsite replication status, and restore test records.
rmm-health-auditor Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet.

HaloPSA

Agent Description
service-desk-ops Use this agent when an MSP dispatcher, team lead, or service manager needs to triage and manage the HaloPSA ticket queue.
sla-performance-reporter Use this agent when an MSP service manager, operations lead, or account manager needs SLA compliance reporting and trend analysis in HaloPSA — not live ticket triage, but retrospective reporting on how well the team has met SLA commitments by client, by technician, and by ticket category.

Hudu

Agent Description
documentation-auditor Use this agent when an MSP technician or vCIO needs to find and fix documentation debt in Hudu.
runbook-freshness-auditor Use this agent when an MSP needs to audit the currency and coverage of runbooks and SOPs in Hudu.

Huntress

Agent Description
client-onboarding-validator Use this agent when validating a newly onboarded client in Huntress — checking that agents are deployed and reporting, confirming SOC coverage is active, identifying any endpoints missing agents, and surfacing initial detections that fired during or after deployment.
incident-responder Use this agent when triaging Huntress incidents, reviewing SOC escalations, approving or rejecting endpoint remediations, investigating security signals, or managing the Huntress agent fleet across MSP client organizations.

IT Glue

Agent Description
asset-documentation-linker Use this agent when an MSP needs to find and fix broken or missing linkages between IT Glue objects — configurations without passwords, devices without runbooks, organizations without network diagrams, contacts unlinked from assets.
documentation-auditor Use this agent when an MSP needs to audit documentation completeness and freshness across their IT Glue client portfolio.

Knowbe4

Agent Description
security-awareness-analyst Use this agent when analyzing phishing simulation results, identifying high-risk users, tracking training completion, recommending targeted security awareness programs, or responding to user-reported phishing through KnowBe4 PhishER for MSP clients.
training-enforcer Use this agent when tracking and enforcing security awareness training completion in KnowBe4 — identifying users who have missed deadlines, finding repeat phishing simulation clickers who represent high-risk users, drafting re-training campaigns, or generating compliance completion reports for clients.

Liongard

Agent Description
change-detective Use this agent when an MSP needs to detect unauthorized or unexpected configuration changes, audit compliance drift, or surface undocumented systems across their client environments.
compliance-drift-reporter Use this agent when an MSP needs to generate compliance baseline drift reports, produce evidence for compliance frameworks, or identify coverage gaps where inspectors have not checked in.

Microsoft 365

Agent Description
identity-auditor Use this agent when an MSP needs to perform a comprehensive Microsoft 365 tenant security audit.
license-auditor Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant.

NinjaOne (NinjaRMM)

Agent Description
device-health-auditor Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio.
patch-compliance-reporter Use this agent when an MSP needs dedicated patch compliance reporting across their NinjaOne-managed portfolio — not a general health check, but a focused analysis of OS patch levels, third-party application versions, missing critical patches, devices pending reboot, and patch policy exceptions.

PagerDuty

Agent Description
incident-commander Use this agent when an MSP engineer, SRE, or incident manager needs to command an active incident or review the state of open PagerDuty incidents.
on-call-scheduler Use this agent when an MSP operations lead, SRE manager, or engineering manager needs to review and manage PagerDuty on-call schedules — not incident response, but the health of the schedule system itself: coverage gaps, upcoming holidays without coverage, overloaded individuals, escalation policy misconfigurations, and rotation balance.

PandaDoc

Agent Description
contract-tracker Use this agent when an MSP sales coordinator or account manager needs to track the status of pending proposals and contracts in PandaDoc.
template-standardizer Use this agent when an MSP needs to audit and standardize their PandaDoc proposal and contract templates — checking for outdated pricing, missing legal clauses, inconsistent formatting, and stale service descriptions.

Pax8

Agent Description
license-optimizer Use this agent when an MSP needs to analyze license utilization across their Pax8 marketplace subscriptions, identify unused or over-provisioned seats, optimize costs, or plan renewals.
renewal-calendar Use this agent when an MSP needs a proactive view of upcoming Pax8 subscription renewals across all clients, wants to flag month-to-month subscriptions that should move to annual, or needs to identify annual renewals that require a seat count review before they lock in.

Proofpoint

Agent Description
email-security-auditor Use this agent when auditing email security posture across Proofpoint-protected organizations, investigating threats via TAP intelligence, tracing specific emails, analyzing Very Attacked Persons (VAPs), or generating per-org security reports for MSP clients.
vap-reporter Use this agent when analyzing Very Attacked Persons (VAPs) in Proofpoint — tracking executives and high-value targets who receive the most sophisticated or highest-volume attacks, surfacing patterns over time, and recommending enhanced protections for the highest-risk users across the MSP client portfolio.

QuickBooks Online

Agent Description
billing-reconciler Use this agent when an MSP needs to reconcile billing in QuickBooks Online — matching invoices to contracts, identifying unbilled work, flagging overdue accounts, or auditing revenue recognition.
profitability-reporter Use this agent when an MSP needs to analyze per-client or per-service-line profitability in QuickBooks Online — calculating gross margin by client, identifying the most and least profitable accounts, tracking profitability trends over time, or surfacing service lines where costs are eroding margin.

RocketCyber

Agent Description
soc-alert-investigator Use this agent when an MSP needs to investigate and triage RocketCyber SOC alerts and security incidents across their client portfolio.
threat-correlation-analyst Use this agent when an MSP needs to correlate RocketCyber SOC detections with broader security context from across the Kaseya ecosystem — cross-referencing incidents with Datto RMM device data, IT Glue documentation, and Autotask ticket history to build richer threat narratives and identify whether incidents are isolated or part of a broader pattern.

Rootly

Agent Description
incident-commander Use this agent when an MSP engineer, SRE, or incident manager needs to command an active Rootly incident or review open incidents.
post-mortem-writer Use this agent when an MSP engineer, SRE, or incident manager needs to generate a structured post-incident review (PIR) for a resolved Rootly incident — not live incident command, but a thorough retrospective document covering what happened, why it happened, the full impact timeline, contributing factors, and the concrete action items the team is committing to fix.

SalesBuildr

Agent Description
margin-analyzer Use this agent when an MSP sales manager or finance lead needs to analyze quote margin health across recent quotes in Salesbuildr.
quote-builder Use this agent when an MSP sales team member needs to build, review, or standardize quotes in Salesbuildr.

SentinelOne

Agent Description
endpoint-hardening-auditor Use this agent when an MSP needs to audit and harden SentinelOne endpoint configuration across client sites — not to investigate active threats, but to proactively identify gaps before attackers can exploit them.
threat-hunter Use this agent when an MSP needs to autonomously hunt for threats across client endpoints using SentinelOne.

Sherweb

Agent Description
billing-reconciler Use this agent when an MSP needs to reconcile Sherweb distributor billing — reviewing payable charges for a billing period, drilling into individual charge details, separating Setup/Recurring/Usage charge types, verifying that billed quantities match active subscriptions, and calculating MSP margin between Sherweb cost and customer price.
customer-account-auditor Use this agent when an MSP needs a portfolio-wide health audit of its Sherweb customer accounts — enumerating all customers, checking accounts-receivable standing, correlating each customer's subscription footprint, and flagging accounts that are at financial or provisioning risk.
subscription-provisioner Use this agent when an MSP needs to provision, right-size, or audit Sherweb customer subscriptions — listing a customer's active subscriptions, looking up catalog products before ordering, planning seat-quantity changes, and walking quantity adjustments through Sherweb's confirmation flow.

SuperOps.ai

Agent Description
automation-opportunity-finder Use this agent when an MSP operations lead, service manager, or technician wants to identify repetitive ticket patterns in SuperOps.ai that should be automated — not live operations management, but a retrospective analysis of ticket history to find recurring issues with the same client, same category, and same resolution, calculate the manual time cost, and recommend runbooks or automation scripts to eliminate the pattern.
msp-service-ops Use this agent when an MSP technician, dispatcher, or manager needs a combined PSA and RMM operations review in SuperOps.ai.

Syncro MSP

Agent Description
billing-auditor Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization.
msp-service-ops Use this agent when an MSP technician, dispatcher, or owner needs an integrated review of tickets, devices, and billing in Syncro.

Blackpoint

Agent Description
alert-response-coordinator Use this agent when triaging the Blackpoint Cyber / CompassOne detection queue across one or many tenants — ranking open detections by severity and tenant impact, deciding what needs immediate escalation to the Blackpoint SOC versus routine follow-up, and producing a prioritized response plan.
detection-investigator Use this agent when investigating a Blackpoint Cyber / CompassOne MDR detection — reconstructing what fired, drilling from tenant to affected asset, mapping the asset's relationships to estimate blast radius, and cross-referencing vulnerabilities and dark-web exposure for context.
exposure-analyst Use this agent when assessing a tenant's attack-surface and exposure posture in Blackpoint Cyber / CompassOne — rolling up vulnerability findings, internet-facing external exposures, dark-web credential leaks, and scan coverage into a prioritized remediation view for QBRs, security reviews, or risk reporting.

Saas Alerts

Agent Description
saas-alerts-analyst Use this agent when investigating and triaging SaaS Alerts security alerts across managed M365 / Google Workspace tenants — reconstructing what fired, attributing it to a user/tenant, judging severity, and recommending response.

Immybot

Agent Description
compliance-auditor Use this agent when an MSP needs a software-compliance audit across their ImmyBot-managed tenant portfolio — per-tenant compliance scorecards, failing-deployment analysis, software-inventory rollups, and task-queue health for QBR or operational reporting.
endpoint-remediation-specialist Use this agent when an MSP needs to diagnose and remediate a problem on ImmyBot-managed endpoints — investigating failed maintenance sessions and tasks, running remediation scripts, and re-reconciling affected computers.
software-deployment-orchestrator Use this agent when an MSP needs to plan and execute a software rollout through ImmyBot — staging desired-state deployments, piloting, triggering maintenance sessions, and confirming compliance.

Timezest

Agent Description
booking-pipeline-auditor Use this agent when reporting on the TimeZest scheduling pipeline — grouping requests by lifecycle state, finding stale requests waiting on customers, measuring booking conversion, and producing a dispatch-queue view across agents and teams.
psa-integration-specialist Use this agent when working with the link between TimeZest and a PSA — building correct associatedEntities payloads for ConnectWise / Autotask / Halo, auditing scheduling requests for missing or wrong PSA associations, reconciling TimeZest bookings against PSA tickets, and choosing pod vs generate_url trigger modes.
scheduling-dispatcher Use this agent when booking a technician against a PSA ticket through TimeZest — resolving the right agent or team, picking the correct appointment type, creating the scheduling request with the PSA association, and confirming the customer booking link was issued.

Threatlocker

Agent Description
approval-triage-analyst Use this agent when reviewing the ThreatLocker pending approval queue, classifying application requests as high-confidence vs needs-review, recommending approve/deny decisions with documented reasoning, and escalating suspicious patterns.
fleet-health-auditor Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations.
threat-investigator Use this agent when investigating a ThreatLocker security event — reconstructing a timeline around a host/user/file, tracing a file's history across the fleet, identifying repeated denials, and surfacing policy bypasses or audit-only matches that warrant new policy rules.

HubSpot CRM

Agent Description
client-relationship-manager Use this agent when an MSP account manager or vCIO needs to review account health across the client portfolio in HubSpot.
pipeline-health-reporter Use this agent when an MSP sales manager or leadership needs to analyze pipeline health, deal velocity, stage conversion rates, or forecast accuracy in HubSpot.

Spamtitan

Agent Description
quarantine-release-reviewer Use this agent when an MSP technician or client needs to systematically review the SpamTitan quarantine queue for false positives, release legitimate messages, identify patterns of legitimate mail being blocked, or generate a quarantine digest for client review.
spam-filter-analyst Use this agent when analyzing spam and phishing patterns in SpamTitan, managing the quarantine queue, tuning allowlist and blocklist rules, investigating held email, or generating email filtering statistics for MSP clients.

Xero

Agent Description
billing-reconciler Use this agent when an MSP needs to reconcile billing in Xero — matching invoices to contracts, tracking outstanding receivables, identifying billing discrepancies, or reviewing cash flow.
cash-flow-analyzer Use this agent when an MSP needs to analyze cash flow position in Xero — tracking accounts receivable aging trends, forecasting upcoming payables vs. expected inflows, identifying months where collections may fall short of committed expenses, or producing a 90-day cash flow projection.

Alternative Payments

Agent Description
payment-reconciler Use this agent when an MSP needs to reconcile Alternative Payments activity — matching transactions to invoices, surfacing unpaid and overdue invoices, summarizing payouts and the transactions that compose them, flagging failed or declined transactions, and tracking outstanding receivables via hosted payment requests.

Ironscales

Agent Description
crowdsourced-intel-harvester Use this agent when harvesting and analyzing crowdsourced threat intelligence from IRONSCALES' global network — identifying trending attack types, surfacing indicators seeing increased reports, comparing client threat profiles to industry peers, and generating intelligence briefings from the collective signal.
phishing-responder Use this agent when responding to user-reported phishing emails in IRONSCALES, triaging the incident queue, classifying emails, coordinating quarantine and remediation, or reviewing security statistics for MSP clients.

Mimecast

Agent Description
email-continuity-checker Use this agent when verifying Mimecast email continuity and archiving health — not for threat investigation, but for checking continuity mode status, verifying archiving is capturing expected mail volumes, auditing connector health, and confirming restore capability.
email-threat-investigator Use this agent when investigating email-borne threats, tracing suspicious messages, analyzing TTP click and attachment logs, auditing Mimecast security posture, or managing held email queues for MSP clients on the Mimecast platform.

Wyre Gateway

Agent Description
asset-reconciliation-auditor Use this agent when an MSP needs to reconcile its asset estate across managed, secured, billed, and documented systems to surface security coverage gaps, revenue leakage, ghost assets, and shadow IT.
book-of-business-pulse Use this agent when an MSP owner, service-delivery manager, or ops lead needs a single operational, commercial, and security heartbeat across the entire client portfolio.
change-drift-sentinel Use this agent when an MSP needs to detect unauthorized, undocumented, or security-weakening configuration changes across the client estate and correlate each change against change-control tickets and documentation currency.
client-360-briefer Use this agent when an MSP technician, account manager, or vCIO needs a complete, synthesized briefing on a client before a call, meeting, or QBR.
client-discovery-agent Use this agent when an MSP is beginning to onboard a new client, conducting a prospect assessment, or performing a takeover from another provider and needs a comprehensive cross-system discovery sweep to establish a baseline of what exists before setup work begins.
compliance-evidence-packager Use this agent when a client needs compliance evidence gathered for a formal audit or assessment against a recognized framework.
dr-readiness-auditor Use this agent when an MSP needs to assess the true disaster-recovery readiness of a client — going beyond backup dashboard green lights to evaluate coverage, test-restore history, runbook maturity, and RTO/RPO achievability.
gateway-ops Use this agent when an MSP administrator needs to review gateway activity, audit tool usage across the team, investigate suspicious access patterns, check permission configurations, or monitor for anomalies in how MSP tools are being accessed through the WYRE MCP Gateway.
incident-war-room-coordinator Use this agent when a major incident (P1 or Critical severity) has been declared or is suspected, and the team needs immediate situational awareness across all affected systems and stakeholders.
license-true-up-reconciler Use this agent when an MSP operations manager, account manager, or billing team needs to reconcile subscription license seats across the full provisioning-to-billing chain and quantify waste, leakage, and over-collection.
offboarding-orchestrator Use this agent when an MSP is ending a client relationship — whether through churn, client acquisition, mutual termination, or non-renewal — and needs to orchestrate a complete, auditable teardown across every connected tool, reclaim all licensed spend, and fulfill contractual data-handover obligations.
onboarding-completeness-checker Use this agent when an MSP needs to validate that a newly onboarded client has been fully set up across all MSP tools and systems before transitioning to steady-state support.
portfolio-threat-sweep Use this agent when an indicator set — file hashes, domains, IPs, sender addresses, URLs, a CVE, or a MITRE ATT&CK technique — needs to be hunted across every client tenant simultaneously to map blast radius and identify exposure before a campaign spreads.
qbr-prep-agent Use this agent when an MSP account manager or vCIO needs to prepare a complete Quarterly Business Review data package for a client.
renewal-risk-analyzer Use this agent when an MSP account manager, sales leader, or operations manager wants to identify clients at risk of not renewing before the renewal conversation happens.
security-posture-scorer Use this agent when an MSP needs a comprehensive, scored security health assessment for a specific client — acting as a vCISO-style health check by aggregating data across all connected security tools.
service-profitability-auditor Use this agent when an MSP owner, operations leader, or finance lead needs to identify which clients and contracts are losing money or eroding margin across the portfolio.
technician-performance-coach Use this agent when a service delivery manager or operations lead wants to understand technician performance trends and get actionable coaching recommendations grounded in data.
ticket-deflection-analyzer Use this agent when an MSP operations lead or service delivery manager wants to identify recurring ticket patterns that can be eliminated or deflected through automation, self-service, or root-cause remediation — and quantify the labor being silently consumed.
user-lifecycle-orchestrator Use this agent when an MSP needs to provision, modify, or deprovision an individual employee's access, identity, licensing, and security posture across all connected systems for a client.
vulnerability-remediation-prioritizer Use this agent when an MSP needs a risk-ranked, actionable remediation workplan from raw vulnerability and missing-patch data — going beyond compliance status to tell technicians exactly what to fix first and why.

Microsoft Graph

Agent Description
entra-reporting-analyst Use this agent when an MSP technician, service-desk analyst, account manager, or vCISO needs to answer questions about a client's Microsoft Entra (Azure AD) identity and directory data — user and license counts, MFA registration gaps, guest inventory, inactive accounts, app inventory, directory roles, sign-in activity.

Azure Mcp

Agent Description
azure-ops-analyst Use this agent when an MSP engineer, service manager, or cloud lead needs a read-only Azure operations investigation — resource health triage, cost and Azure Advisor analysis, quota/capacity headroom checks, and observability-posture reporting across subscriptions.

Meraki

Agent Description
meraki-network-auditor Use this agent when an MSP needs a read-only health and security audit of a Cisco Meraki organization — sweeping networks, devices, and appliances to surface offline or alerting hardware, appliances with site-to-site VPN peers down, overly-permissive firewall rules, and SSIDs configured with weak or open authentication.

Ncentral

Agent Description
device-auditor Use this agent when the user wants a device audit across N-central customers - inventory sweeps, missing asset data, expired or expiring warranties, untracked lifecycle records, or failed service monitors.
issue-triager Use this agent when the user wants active issues triaged across N-central customers - morning sweeps, severity ranking, root-cause grouping, or deciding what to remediate first.

Ops Pack

Agent Description
board-health-auditor Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report.
dispatch-coordinator Use this agent when the unassigned ticket queue needs to be triaged and assigned to technicians, factoring in SLA pressure, client tier, ticket age, and current technician load.
stale-ticket-chaser Use this agent when tickets have gone quiet and someone needs to figure out why and what to do about each one — not just that they're stale.

Secops Pack

Agent Description
incident-timeline-builder Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question.
overnight-alert-summarizer Use this agent when a technician needs a morning read on everything that fired overnight across the connected EDR/MDR/SIEM stack, normalized into one ranked digest instead of five separate vendor consoles.
tenant-exposure-ranker Use this agent when the MSP needs a portfolio-wide read on which clients carry the most current security risk — open critical findings, unpatched or uncontained threats, MFA coverage gaps, and stale EDR/agent coverage — ranked so leadership or the security team can prioritize attention.

Finance Pack

Agent Description
billing-drift-detector Use this agent when an MSP billing team, controller, or account manager needs to run a portfolio-wide sweep for contract-vs-invoice mismatches — surfacing every client where the PSA agreement and the accounting invoice disagree, ranked by dollar impact.
profitability-ranker Use this agent when an MSP owner, operations leader, or finance lead needs to rank clients from most to least profitable using actual revenue and cost data, flagging any operating at a loss.
renewal-calendar-builder Use this agent when an MSP account manager, sales leader, or operations manager needs a forward-looking view of every upcoming contract and subscription renewal across the connected PSA and cloud-marketplace distributors, with recommended lead time per renewal.

Compliance Pack

Agent Description
control-drift-reporter Use this agent when an MSP needs to know what has changed in a client's compliance posture since the last known-good baseline, prioritized by how much each change actually matters.
evidence-packager Use this agent when an MSP needs to gather and assemble compliance evidence for a client against a named framework or control set, producing a source-cited package an auditor or client can review.
questionnaire-autofiller Use this agent when a client needs its cyber-insurance renewal or new-business questionnaire drafted using live tool evidence rather than best-guess answers.

Sales Pack

Agent Description
pipeline-auditor Use this agent when a sales manager, deal desk owner, or MSP leadership needs a full cross-vendor sweep of the open sales pipeline — stalled and at-risk deals ranked by value and staleness, with each stall diagnosed against the full quote-to-close chain rather than CRM activity alone.
proposal-follow-up-tracker Use this agent when a sales rep, deal desk owner, or sales manager needs to know which proposals and quotes need attention right now, with a drafted follow-up action for each.
warm-lead-router Use this agent when a sales manager or rep needs to know which leads are showing real buying intent right now, and who should follow up on each one.

Devops Pack

Agent Description
oncall-handoff-builder Use this agent when an on-call engineer needs a structured shift handoff brief — what's currently paging or unresolved, what happened during the last shift, known-flaky alerts to watch, and anything escalated but not yet actioned — assembled from whatever incident-management tool is connected.
postmortem-drafter Use this agent when an engineer, SRE, or incident manager needs a full blameless postmortem drafted from a resolved incident — identified by ID or by a rough time window — reconstructed from the incident tool's event log plus correlated observability and deploy data.
reliability-scorecard Use this agent when a team lead, SRE, or engineering manager needs a ranked reliability status across connected services — error-budget burn rate where a formal SLO exists, degrading to raw error-rate/uptime trend reporting where it doesn't — worst service first.

Cloudops Pack

Agent Description
capacity-forecaster Use this agent when an MSP needs to know whether current cloud resource capacity will hold up under growth, or which resources are already over- or under-provisioned.
cost-anomaly-detector Use this agent when an MSP needs to investigate unexpected cloud spend or hunt for orphaned/idle cloud resources that are still costing money.
network-health-auditor Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected.

Awareness Pack

Agent Description
human-risk-scorer Use this agent when the MSP needs a per-user or per-org "human risk score" built from training completion and phishing-simulation performance, to rank the riskiest users or clients on the human/culture layer of security.
phishing-simulation-analyst Use this agent when the MSP needs to analyze phishing-simulation campaign results — click-rate trends over time and repeat-clicker identification — for a single client or across the portfolio.
training-compliance-auditor Use this agent when the MSP needs to verify security-awareness training completion for a single client or across the whole portfolio, and flag overdue users or clients falling behind their expected training cadence.

Backup Pack

Agent Description
backup-health-auditor Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity.
restore-readiness-checker Use this agent when an MSP needs to know whether backups have actually been restore-tested, not just whether they're running — flagging clients or systems whose backups have never had a restore, boot-verification, or spot-check drill performed, with a recommended test schedule.
retention-compliance-auditor Use this agent when an MSP needs to verify that actual backup retention configuration and cadence meet contracted or required retention/RPO policy, rather than assuming appliance defaults are adequate.

Assets Pack

Agent Description
eol-risk-assessor Use this agent when someone needs to know which devices, OS versions, or firmware are approaching or past end-of-life/end-of-support, prioritized by how much it actually matters if left unaddressed.
refresh-planner Use this agent when someone needs a forward-looking hardware refresh calendar that combines warranty, EOL/EOS, and device age into a replace-now/plan-this-year/monitor plan.
warranty-status-auditor Use this agent when someone needs a portfolio-wide or client-specific view of hardware warranty coverage, pulled and normalized across every connected RMM and documentation tool.