Agents Reference
Agents are specialized subagents that perform multi-step MSP workflows autonomously. There are 146 agents across all plugins.
What are Agents?
Agents combine skills, commands, and domain knowledge to execute higher-level tasks — auditing a tenant, reconciling billing, triaging an alert — without you walking Claude through every step. Each agent is scoped to a clear role and a focused set of tools.
/agent identity-auditor "Audit Acme Corp's M365 tenant" Agents by Category
Auditing & Compliance
Agents that audit configurations, identities, devices, and surface compliance gaps.
| Agent | Plugin | Description |
|---|---|---|
compliance-reporter | Blumira | Use this agent when generating compliance-oriented security reports from Blumira SIEM data — not for live incident investigation, but for producing evidence packages, coverage gap assessments, and log source health summaries for frameworks like SOC 2, HIPAA, and CIS. |
tenant-policy-auditor | Checkpoint Avanan | Use this agent when an MSP needs to audit email security policy completeness and correctness across Avanan (Check Point Harmony Email & Collaboration) managed tenants — verifying anti-phishing coverage, attachment sandboxing, impersonation protection, DLP rules, and exception hygiene. |
rmm-health-auditor | Datto RMM | Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet. |
documentation-auditor | Hudu | Use this agent when an MSP technician or vCIO needs to find and fix documentation debt in Hudu. |
runbook-freshness-auditor | Hudu | Use this agent when an MSP needs to audit the currency and coverage of runbooks and SOPs in Hudu. |
documentation-auditor | IT Glue | Use this agent when an MSP needs to audit documentation completeness and freshness across their IT Glue client portfolio. |
identity-auditor | Microsoft 365 | Use this agent when an MSP needs to perform a comprehensive Microsoft 365 tenant security audit. |
license-auditor | Microsoft 365 | Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant. |
device-health-auditor | NinjaOne (NinjaRMM) | Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio. |
patch-compliance-reporter | NinjaOne (NinjaRMM) | Use this agent when an MSP needs dedicated patch compliance reporting across their NinjaOne-managed portfolio — not a general health check, but a focused analysis of OS patch levels, third-party application versions, missing critical patches, devices pending reboot, and patch policy exceptions. |
email-security-auditor | Proofpoint | Use this agent when auditing email security posture across Proofpoint-protected organizations, investigating threats via TAP intelligence, tracing specific emails, analyzing Very Attacked Persons (VAPs), or generating per-org security reports for MSP clients. |
endpoint-hardening-auditor | SentinelOne | Use this agent when an MSP needs to audit and harden SentinelOne endpoint configuration across client sites — not to investigate active threats, but to proactively identify gaps before attackers can exploit them. |
customer-account-auditor | Sherweb | Use this agent when an MSP needs a portfolio-wide health audit of its Sherweb customer accounts — enumerating all customers, checking accounts-receivable standing, correlating each customer's subscription footprint, and flagging accounts that are at financial or provisioning risk. |
billing-auditor | Syncro MSP | Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization. |
compliance-auditor | Immybot | Use this agent when an MSP needs a software-compliance audit across their ImmyBot-managed tenant portfolio — per-tenant compliance scorecards, failing-deployment analysis, software-inventory rollups, and task-queue health for QBR or operational reporting. |
booking-pipeline-auditor | Timezest | Use this agent when reporting on the TimeZest scheduling pipeline — grouping requests by lifecycle state, finding stale requests waiting on customers, measuring booking conversion, and producing a dispatch-queue view across agents and teams. |
fleet-health-auditor | Threatlocker | Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations. |
asset-reconciliation-auditor | Wyre Gateway | Use this agent when an MSP needs to reconcile its asset estate across managed, secured, billed, and documented systems to surface security coverage gaps, revenue leakage, ghost assets, and shadow IT. |
dr-readiness-auditor | Wyre Gateway | Use this agent when an MSP needs to assess the true disaster-recovery readiness of a client — going beyond backup dashboard green lights to evaluate coverage, test-restore history, runbook maturity, and RTO/RPO achievability. |
service-profitability-auditor | Wyre Gateway | Use this agent when an MSP owner, operations leader, or finance lead needs to identify which clients and contracts are losing money or eroding margin across the portfolio. |
meraki-network-auditor | Meraki | Use this agent when an MSP needs a read-only health and security audit of a Cisco Meraki organization — sweeping networks, devices, and appliances to surface offline or alerting hardware, appliances with site-to-site VPN peers down, overly-permissive firewall rules, and SSIDs configured with weak or open authentication. |
device-auditor | Ncentral | Use this agent when the user wants a device audit across N-central customers - inventory sweeps, missing asset data, expired or expiring warranties, untracked lifecycle records, or failed service monitors. |
board-health-auditor | Ops Pack | Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report. |
pipeline-auditor | Sales Pack | Use this agent when a sales manager, deal desk owner, or MSP leadership needs a full cross-vendor sweep of the open sales pipeline — stalled and at-risk deals ranked by value and staleness, with each stall diagnosed against the full quote-to-close chain rather than CRM activity alone. |
network-health-auditor | Cloudops Pack | Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected. |
training-compliance-auditor | Awareness Pack | Use this agent when the MSP needs to verify security-awareness training completion for a single client or across the whole portfolio, and flag overdue users or clients falling behind their expected training cadence. |
backup-health-auditor | Backup Pack | Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity. |
retention-compliance-auditor | Backup Pack | Use this agent when an MSP needs to verify that actual backup retention configuration and cadence meet contracted or required retention/RPO policy, rather than assuming appliance defaults are adequate. |
warranty-status-auditor | Assets Pack | Use this agent when someone needs a portfolio-wide or client-specific view of hardware warranty coverage, pulled and normalized across every connected RMM and documentation tool. |
Health & Monitoring
Agents that watch backups, automation, uptime, and overall customer health.
| Agent | Plugin | Description |
|---|---|---|
customer-health-scorer | Atera | Use this agent when an MSP account manager, service manager, or owner needs to score and rank client health across the Atera portfolio — not live operations management, but a structured assessment of each client based on device health trends, ticket velocity, recurring issues, patch compliance, and alert frequency. |
sla-uptime-reporter | BetterStack | Use this agent when an MSP needs to generate SLA-focused uptime reports for clients, calculate SLA achievement percentages, identify chronic underperforming monitors, or produce client-facing availability summaries. |
uptime-incident-responder | BetterStack | Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report. |
automation-health-checker | ConnectWise Automate | Use this agent when an MSP technician or engineer needs to audit the health of their ConnectWise Automate RMM environment. |
backup-health-monitor | Datto RMM | Use this agent when an MSP needs to audit backup and BC/DR health across their Datto RMM managed client portfolio — not a general fleet health check, but a focused review of backup job success rates, last successful backups per device, retention policy compliance, offsite replication status, and restore test records. |
rmm-health-auditor | Datto RMM | Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet. |
device-health-auditor | NinjaOne (NinjaRMM) | Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio. |
fleet-health-auditor | Threatlocker | Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations. |
pipeline-health-reporter | HubSpot CRM | Use this agent when an MSP sales manager or leadership needs to analyze pipeline health, deal velocity, stage conversion rates, or forecast accuracy in HubSpot. |
board-health-auditor | Ops Pack | Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report. |
network-health-auditor | Cloudops Pack | Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected. |
backup-health-auditor | Backup Pack | Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity. |
Incident & Service Desk
Agents that triage alerts, drive incidents, and run service desk operations.
| Agent | Plugin | Description |
|---|---|---|
uptime-incident-responder | BetterStack | Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report. |
service-desk-ops | ConnectWise PSA | Use this agent when an MSP dispatcher, service manager, or team lead needs to review the current state of the ConnectWise Manage service desk. |
service-desk-ops | HaloPSA | Use this agent when an MSP dispatcher, team lead, or service manager needs to triage and manage the HaloPSA ticket queue. |
incident-responder | Huntress | Use this agent when triaging Huntress incidents, reviewing SOC escalations, approving or rejecting endpoint remediations, investigating security signals, or managing the Huntress agent fleet across MSP client organizations. |
change-detective | Liongard | Use this agent when an MSP needs to detect unauthorized or unexpected configuration changes, audit compliance drift, or surface undocumented systems across their client environments. |
incident-commander | PagerDuty | Use this agent when an MSP engineer, SRE, or incident manager needs to command an active incident or review the state of open PagerDuty incidents. |
soc-alert-investigator | RocketCyber | Use this agent when an MSP needs to investigate and triage RocketCyber SOC alerts and security incidents across their client portfolio. |
incident-commander | Rootly | Use this agent when an MSP engineer, SRE, or incident manager needs to command an active Rootly incident or review open incidents. |
incident-war-room-coordinator | Wyre Gateway | Use this agent when a major incident (P1 or Critical severity) has been declared or is suspected, and the team needs immediate situational awareness across all affected systems and stakeholders. |
incident-timeline-builder | Secops Pack | Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question. |
Client Lifecycle
Agents that handle onboarding, contracts, and renewal tracking.
| Agent | Plugin | Description |
|---|---|---|
contract-renewal-tracker | Autotask PSA | Use this agent when an MSP account manager, service manager, or operations lead needs to track and manage contract renewals in Autotask PSA — surfacing expiring contracts, identifying auto-renewal gaps, tracking MRR/ARR trends, and flagging clients who are still receiving service on expired contracts. |
client-onboarding-validator | Huntress | Use this agent when validating a newly onboarded client in Huntress — checking that agents are deployed and reporting, confirming SOC coverage is active, identifying any endpoints missing agents, and surfacing initial detections that fired during or after deployment. |
contract-tracker | PandaDoc | Use this agent when an MSP sales coordinator or account manager needs to track the status of pending proposals and contracts in PandaDoc. |
renewal-calendar | Pax8 | Use this agent when an MSP needs a proactive view of upcoming Pax8 subscription renewals across all clients, wants to flag month-to-month subscriptions that should move to annual, or needs to identify annual renewals that require a seat count review before they lock in. |
onboarding-completeness-checker | Wyre Gateway | Use this agent when an MSP needs to validate that a newly onboarded client has been fully set up across all MSP tools and systems before transitioning to steady-state support. |
renewal-risk-analyzer | Wyre Gateway | Use this agent when an MSP account manager, sales leader, or operations manager wants to identify clients at risk of not renewing before the renewal conversation happens. |
renewal-calendar-builder | Finance Pack | Use this agent when an MSP account manager, sales leader, or operations manager needs a forward-looking view of every upcoming contract and subscription renewal across the connected PSA and cloud-marketplace distributors, with recommended lead time per renewal. |
Financial Operations
Agents focused on billing, licensing, margins, and procurement.
| Agent | Plugin | Description |
|---|---|---|
procurement-specialist | ConnectWise PSA | Use this agent when an MSP procurement lead, sales engineer, service manager, or owner needs to work against the ConnectWise Manage product catalog and the procurement/quoting workflows it feeds. |
license-auditor | Microsoft 365 | Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant. |
license-optimizer | Pax8 | Use this agent when an MSP needs to analyze license utilization across their Pax8 marketplace subscriptions, identify unused or over-provisioned seats, optimize costs, or plan renewals. |
billing-reconciler | QuickBooks Online | Use this agent when an MSP needs to reconcile billing in QuickBooks Online — matching invoices to contracts, identifying unbilled work, flagging overdue accounts, or auditing revenue recognition. |
margin-analyzer | SalesBuildr | Use this agent when an MSP sales manager or finance lead needs to analyze quote margin health across recent quotes in Salesbuildr. |
billing-reconciler | Sherweb | Use this agent when an MSP needs to reconcile Sherweb distributor billing — reviewing payable charges for a billing period, drilling into individual charge details, separating Setup/Recurring/Usage charge types, verifying that billed quantities match active subscriptions, and calculating MSP margin between Sherweb cost and customer price. |
billing-auditor | Syncro MSP | Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization. |
billing-reconciler | Xero | Use this agent when an MSP needs to reconcile billing in Xero — matching invoices to contracts, tracking outstanding receivables, identifying billing discrepancies, or reviewing cash flow. |
license-true-up-reconciler | Wyre Gateway | Use this agent when an MSP operations manager, account manager, or billing team needs to reconcile subscription license seats across the full provisioning-to-billing chain and quantify waste, leakage, and over-collection. |
billing-drift-detector | Finance Pack | Use this agent when an MSP billing team, controller, or account manager needs to run a portfolio-wide sweep for contract-vs-invoice mismatches — surfacing every client where the PSA agreement and the accounting invoice disagree, ranked by dollar impact. |
Documentation & Insights
Agents that link assets to documentation and surface optimization opportunities.
| Agent | Plugin | Description |
|---|---|---|
asset-documentation-linker | IT Glue | Use this agent when an MSP needs to find and fix broken or missing linkages between IT Glue objects — configurations without passwords, devices without runbooks, organizations without network diagrams, contacts unlinked from assets. |
automation-opportunity-finder | SuperOps.ai | Use this agent when an MSP operations lead, service manager, or technician wants to identify repetitive ticket patterns in SuperOps.ai that should be automated — not live operations management, but a retrospective analysis of ticket history to find recurring issues with the same client, same category, and same resolution, calculate the manual time cost, and recommend runbooks or automation scripts to eliminate the pattern. |
All Agents by Plugin
Abnormal Security
| Agent | Description |
|---|---|
email-threat-analyst | Use this agent when investigating email threats detected by Abnormal Security, analyzing attack chains, assessing user exposure, or managing remediation across client tenants. |
threat-report-generator | Use this agent when generating periodic threat landscape reports from Abnormal Security data across the MSP client portfolio — not for live threat investigation, but for summarizing attack trends, most targeted organizations, most common attack types, BEC attempt volumes, and remediation effectiveness over time. |
Atera
| Agent | Description |
|---|---|
customer-health-scorer | Use this agent when an MSP account manager, service manager, or owner needs to score and rank client health across the Atera portfolio — not live operations management, but a structured assessment of each client based on device health trends, ticket velocity, recurring issues, patch compliance, and alert frequency. |
msp-ops-assistant | Use this agent when an MSP needs combined RMM and PSA operations assistance through Atera — triaging alerts, managing the ticket queue, checking device health, and identifying patterns across the client base. |
Auvik
| Agent | Description |
|---|---|
alert-responder | Use this agent for Auvik alert-related questions - what's open, what matters, what to dismiss, what to escalate. |
capacity-planner | Use this agent for Auvik utilization, saturation, and headroom questions - "is this link maxed out?", "what links need an upgrade?", "where is the bottleneck?". |
network-analyst | Use this agent when the user is asking what's wrong with a tenant's network, investigating broad performance complaints, mapping topology, or doing multi-signal triage across devices, interfaces, alerts, and statistics in Auvik. |
Autotask PSA
| Agent | Description |
|---|---|
contract-renewal-tracker | Use this agent when an MSP account manager, service manager, or operations lead needs to track and manage contract renewals in Autotask PSA — surfacing expiring contracts, identifying auto-renewal gaps, tracking MRR/ARR trends, and flagging clients who are still receiving service on expired contracts. |
ticket-dispatcher | Use this agent when an MSP dispatcher or service manager needs to intelligently manage the Autotask PSA ticket queue — reviewing priorities, suggesting technician assignments, monitoring SLA compliance, and driving dispatch decisions. |
BetterStack
| Agent | Description |
|---|---|
sla-uptime-reporter | Use this agent when an MSP needs to generate SLA-focused uptime reports for clients, calculate SLA achievement percentages, identify chronic underperforming monitors, or produce client-facing availability summaries. |
uptime-incident-responder | Use this agent when an MSP needs to respond to a BetterStack uptime incident, investigate monitor failures, coordinate on-call response, or produce an incident report. |
Blumira
| Agent | Description |
|---|---|
compliance-reporter | Use this agent when generating compliance-oriented security reports from Blumira SIEM data — not for live incident investigation, but for producing evidence packages, coverage gap assessments, and log source health summaries for frameworks like SOC 2, HIPAA, and CIS. |
siem-investigator | Use this agent when investigating Blumira SIEM alerts and findings, tracing attack chains across data sources, resolving detections, auditing security posture across MSP client accounts, or producing threat investigation reports. |
Checkpoint Avanan
| Agent | Description |
|---|---|
cloud-email-defender | Use this agent when investigating quarantined threats, managing email security events, auditing Avanan tenant configuration, or performing cross-tenant threat sweeps in Check Point Avanan (Harmony Email & Collaboration). |
tenant-policy-auditor | Use this agent when an MSP needs to audit email security policy completeness and correctness across Avanan (Check Point Harmony Email & Collaboration) managed tenants — verifying anti-phishing coverage, attachment sandboxing, impersonation protection, DLP rules, and exception hygiene. |
CIPP
| Agent | Description |
|---|---|
security-posture-reviewer | Use this agent when an MSP security lead, vCISO, or service manager needs to sweep the M365 portfolio for security posture issues — Secure Score regressions, MFA enrollment gaps, conditional access drift, BPA failures, and broken domain authentication. |
user-offboarding-runner | Use this agent when an MSP technician, dispatcher, or HR-facing operator needs to run a complete M365 user offboarding through CIPP. |
Freshdesk
| Agent | Description |
|---|---|
freshdesk-triage | Use this agent when an MSP dispatcher, service coordinator, or help-desk lead needs to sweep the Freshdesk open ticket queue, summarize what is waiting, and recommend routing and priority. |
Inforcer
| Agent | Description |
|---|---|
inforcer-drift-reporter | Use this agent when an MSP security lead, vCISO, or service manager needs to sweep the managed Microsoft 365 portfolio for baseline drift and posture using Inforcer — pulling alignment scores, per-policy drift detail, and secure scores across tenants and summarizing them into a prioritized picture. |
ConnectWise Automate
| Agent | Description |
|---|---|
automation-health-checker | Use this agent when an MSP technician or engineer needs to audit the health of their ConnectWise Automate RMM environment. |
ConnectWise PSA
| Agent | Description |
|---|---|
procurement-specialist | Use this agent when an MSP procurement lead, sales engineer, service manager, or owner needs to work against the ConnectWise Manage product catalog and the procurement/quoting workflows it feeds. |
project-tracker | Use this agent when an MSP project manager, service manager, or operations lead needs a review of all open projects in ConnectWise Manage — checking milestone deadlines, budget vs. actuals, overdue phases, and projects at risk of scope creep or delivery failure. |
service-desk-ops | Use this agent when an MSP dispatcher, service manager, or team lead needs to review the current state of the ConnectWise Manage service desk. |
Datto RMM
| Agent | Description |
|---|---|
backup-health-monitor | Use this agent when an MSP needs to audit backup and BC/DR health across their Datto RMM managed client portfolio — not a general fleet health check, but a focused review of backup job success rates, last successful backups per device, retention policy compliance, offsite replication status, and restore test records. |
rmm-health-auditor | Use this agent when an MSP needs a comprehensive health audit of their Datto RMM managed device fleet. |
HaloPSA
| Agent | Description |
|---|---|
service-desk-ops | Use this agent when an MSP dispatcher, team lead, or service manager needs to triage and manage the HaloPSA ticket queue. |
sla-performance-reporter | Use this agent when an MSP service manager, operations lead, or account manager needs SLA compliance reporting and trend analysis in HaloPSA — not live ticket triage, but retrospective reporting on how well the team has met SLA commitments by client, by technician, and by ticket category. |
Hudu
| Agent | Description |
|---|---|
documentation-auditor | Use this agent when an MSP technician or vCIO needs to find and fix documentation debt in Hudu. |
runbook-freshness-auditor | Use this agent when an MSP needs to audit the currency and coverage of runbooks and SOPs in Hudu. |
Huntress
| Agent | Description |
|---|---|
client-onboarding-validator | Use this agent when validating a newly onboarded client in Huntress — checking that agents are deployed and reporting, confirming SOC coverage is active, identifying any endpoints missing agents, and surfacing initial detections that fired during or after deployment. |
incident-responder | Use this agent when triaging Huntress incidents, reviewing SOC escalations, approving or rejecting endpoint remediations, investigating security signals, or managing the Huntress agent fleet across MSP client organizations. |
IT Glue
| Agent | Description |
|---|---|
asset-documentation-linker | Use this agent when an MSP needs to find and fix broken or missing linkages between IT Glue objects — configurations without passwords, devices without runbooks, organizations without network diagrams, contacts unlinked from assets. |
documentation-auditor | Use this agent when an MSP needs to audit documentation completeness and freshness across their IT Glue client portfolio. |
Knowbe4
| Agent | Description |
|---|---|
security-awareness-analyst | Use this agent when analyzing phishing simulation results, identifying high-risk users, tracking training completion, recommending targeted security awareness programs, or responding to user-reported phishing through KnowBe4 PhishER for MSP clients. |
training-enforcer | Use this agent when tracking and enforcing security awareness training completion in KnowBe4 — identifying users who have missed deadlines, finding repeat phishing simulation clickers who represent high-risk users, drafting re-training campaigns, or generating compliance completion reports for clients. |
Liongard
| Agent | Description |
|---|---|
change-detective | Use this agent when an MSP needs to detect unauthorized or unexpected configuration changes, audit compliance drift, or surface undocumented systems across their client environments. |
compliance-drift-reporter | Use this agent when an MSP needs to generate compliance baseline drift reports, produce evidence for compliance frameworks, or identify coverage gaps where inspectors have not checked in. |
Microsoft 365
| Agent | Description |
|---|---|
identity-auditor | Use this agent when an MSP needs to perform a comprehensive Microsoft 365 tenant security audit. |
license-auditor | Use this agent when an MSP needs to audit Microsoft 365 license costs and find savings opportunities across a client tenant. |
NinjaOne (NinjaRMM)
| Agent | Description |
|---|---|
device-health-auditor | Use this agent when an MSP needs a comprehensive device health audit across their NinjaOne-managed organization portfolio. |
patch-compliance-reporter | Use this agent when an MSP needs dedicated patch compliance reporting across their NinjaOne-managed portfolio — not a general health check, but a focused analysis of OS patch levels, third-party application versions, missing critical patches, devices pending reboot, and patch policy exceptions. |
PagerDuty
| Agent | Description |
|---|---|
incident-commander | Use this agent when an MSP engineer, SRE, or incident manager needs to command an active incident or review the state of open PagerDuty incidents. |
on-call-scheduler | Use this agent when an MSP operations lead, SRE manager, or engineering manager needs to review and manage PagerDuty on-call schedules — not incident response, but the health of the schedule system itself: coverage gaps, upcoming holidays without coverage, overloaded individuals, escalation policy misconfigurations, and rotation balance. |
PandaDoc
| Agent | Description |
|---|---|
contract-tracker | Use this agent when an MSP sales coordinator or account manager needs to track the status of pending proposals and contracts in PandaDoc. |
template-standardizer | Use this agent when an MSP needs to audit and standardize their PandaDoc proposal and contract templates — checking for outdated pricing, missing legal clauses, inconsistent formatting, and stale service descriptions. |
Pax8
| Agent | Description |
|---|---|
license-optimizer | Use this agent when an MSP needs to analyze license utilization across their Pax8 marketplace subscriptions, identify unused or over-provisioned seats, optimize costs, or plan renewals. |
renewal-calendar | Use this agent when an MSP needs a proactive view of upcoming Pax8 subscription renewals across all clients, wants to flag month-to-month subscriptions that should move to annual, or needs to identify annual renewals that require a seat count review before they lock in. |
Proofpoint
| Agent | Description |
|---|---|
email-security-auditor | Use this agent when auditing email security posture across Proofpoint-protected organizations, investigating threats via TAP intelligence, tracing specific emails, analyzing Very Attacked Persons (VAPs), or generating per-org security reports for MSP clients. |
vap-reporter | Use this agent when analyzing Very Attacked Persons (VAPs) in Proofpoint — tracking executives and high-value targets who receive the most sophisticated or highest-volume attacks, surfacing patterns over time, and recommending enhanced protections for the highest-risk users across the MSP client portfolio. |
QuickBooks Online
| Agent | Description |
|---|---|
billing-reconciler | Use this agent when an MSP needs to reconcile billing in QuickBooks Online — matching invoices to contracts, identifying unbilled work, flagging overdue accounts, or auditing revenue recognition. |
profitability-reporter | Use this agent when an MSP needs to analyze per-client or per-service-line profitability in QuickBooks Online — calculating gross margin by client, identifying the most and least profitable accounts, tracking profitability trends over time, or surfacing service lines where costs are eroding margin. |
RocketCyber
| Agent | Description |
|---|---|
soc-alert-investigator | Use this agent when an MSP needs to investigate and triage RocketCyber SOC alerts and security incidents across their client portfolio. |
threat-correlation-analyst | Use this agent when an MSP needs to correlate RocketCyber SOC detections with broader security context from across the Kaseya ecosystem — cross-referencing incidents with Datto RMM device data, IT Glue documentation, and Autotask ticket history to build richer threat narratives and identify whether incidents are isolated or part of a broader pattern. |
Rootly
| Agent | Description |
|---|---|
incident-commander | Use this agent when an MSP engineer, SRE, or incident manager needs to command an active Rootly incident or review open incidents. |
post-mortem-writer | Use this agent when an MSP engineer, SRE, or incident manager needs to generate a structured post-incident review (PIR) for a resolved Rootly incident — not live incident command, but a thorough retrospective document covering what happened, why it happened, the full impact timeline, contributing factors, and the concrete action items the team is committing to fix. |
SalesBuildr
| Agent | Description |
|---|---|
margin-analyzer | Use this agent when an MSP sales manager or finance lead needs to analyze quote margin health across recent quotes in Salesbuildr. |
quote-builder | Use this agent when an MSP sales team member needs to build, review, or standardize quotes in Salesbuildr. |
SentinelOne
| Agent | Description |
|---|---|
endpoint-hardening-auditor | Use this agent when an MSP needs to audit and harden SentinelOne endpoint configuration across client sites — not to investigate active threats, but to proactively identify gaps before attackers can exploit them. |
threat-hunter | Use this agent when an MSP needs to autonomously hunt for threats across client endpoints using SentinelOne. |
Sherweb
| Agent | Description |
|---|---|
billing-reconciler | Use this agent when an MSP needs to reconcile Sherweb distributor billing — reviewing payable charges for a billing period, drilling into individual charge details, separating Setup/Recurring/Usage charge types, verifying that billed quantities match active subscriptions, and calculating MSP margin between Sherweb cost and customer price. |
customer-account-auditor | Use this agent when an MSP needs a portfolio-wide health audit of its Sherweb customer accounts — enumerating all customers, checking accounts-receivable standing, correlating each customer's subscription footprint, and flagging accounts that are at financial or provisioning risk. |
subscription-provisioner | Use this agent when an MSP needs to provision, right-size, or audit Sherweb customer subscriptions — listing a customer's active subscriptions, looking up catalog products before ordering, planning seat-quantity changes, and walking quantity adjustments through Sherweb's confirmation flow. |
SuperOps.ai
| Agent | Description |
|---|---|
automation-opportunity-finder | Use this agent when an MSP operations lead, service manager, or technician wants to identify repetitive ticket patterns in SuperOps.ai that should be automated — not live operations management, but a retrospective analysis of ticket history to find recurring issues with the same client, same category, and same resolution, calculate the manual time cost, and recommend runbooks or automation scripts to eliminate the pattern. |
msp-service-ops | Use this agent when an MSP technician, dispatcher, or manager needs a combined PSA and RMM operations review in SuperOps.ai. |
Syncro MSP
| Agent | Description |
|---|---|
billing-auditor | Use this agent when an MSP owner, billing coordinator, or service manager needs a billing completeness and accuracy audit in Syncro — finding tickets that haven't been billed, identifying recurring billing discrepancies, checking invoice accuracy against contracts, and flagging draft invoices overdue for finalization. |
msp-service-ops | Use this agent when an MSP technician, dispatcher, or owner needs an integrated review of tickets, devices, and billing in Syncro. |
Blackpoint
| Agent | Description |
|---|---|
alert-response-coordinator | Use this agent when triaging the Blackpoint Cyber / CompassOne detection queue across one or many tenants — ranking open detections by severity and tenant impact, deciding what needs immediate escalation to the Blackpoint SOC versus routine follow-up, and producing a prioritized response plan. |
detection-investigator | Use this agent when investigating a Blackpoint Cyber / CompassOne MDR detection — reconstructing what fired, drilling from tenant to affected asset, mapping the asset's relationships to estimate blast radius, and cross-referencing vulnerabilities and dark-web exposure for context. |
exposure-analyst | Use this agent when assessing a tenant's attack-surface and exposure posture in Blackpoint Cyber / CompassOne — rolling up vulnerability findings, internet-facing external exposures, dark-web credential leaks, and scan coverage into a prioritized remediation view for QBRs, security reviews, or risk reporting. |
Saas Alerts
| Agent | Description |
|---|---|
saas-alerts-analyst | Use this agent when investigating and triaging SaaS Alerts security alerts across managed M365 / Google Workspace tenants — reconstructing what fired, attributing it to a user/tenant, judging severity, and recommending response. |
Immybot
| Agent | Description |
|---|---|
compliance-auditor | Use this agent when an MSP needs a software-compliance audit across their ImmyBot-managed tenant portfolio — per-tenant compliance scorecards, failing-deployment analysis, software-inventory rollups, and task-queue health for QBR or operational reporting. |
endpoint-remediation-specialist | Use this agent when an MSP needs to diagnose and remediate a problem on ImmyBot-managed endpoints — investigating failed maintenance sessions and tasks, running remediation scripts, and re-reconciling affected computers. |
software-deployment-orchestrator | Use this agent when an MSP needs to plan and execute a software rollout through ImmyBot — staging desired-state deployments, piloting, triggering maintenance sessions, and confirming compliance. |
Timezest
| Agent | Description |
|---|---|
booking-pipeline-auditor | Use this agent when reporting on the TimeZest scheduling pipeline — grouping requests by lifecycle state, finding stale requests waiting on customers, measuring booking conversion, and producing a dispatch-queue view across agents and teams. |
psa-integration-specialist | Use this agent when working with the link between TimeZest and a PSA — building correct associatedEntities payloads for ConnectWise / Autotask / Halo, auditing scheduling requests for missing or wrong PSA associations, reconciling TimeZest bookings against PSA tickets, and choosing pod vs generate_url trigger modes. |
scheduling-dispatcher | Use this agent when booking a technician against a PSA ticket through TimeZest — resolving the right agent or team, picking the correct appointment type, creating the scheduling request with the PSA association, and confirming the customer booking link was issued. |
Threatlocker
| Agent | Description |
|---|---|
approval-triage-analyst | Use this agent when reviewing the ThreatLocker pending approval queue, classifying application requests as high-confidence vs needs-review, recommending approve/deny decisions with documented reasoning, and escalating suspicious patterns. |
fleet-health-auditor | Use this agent when producing ThreatLocker fleet inventory and hygiene reports — computer inventory by OS or group, offline-agent identification with check-in age tiering, computer-group hygiene analysis (orphans, oversized groups, OS-mismatched assignments), and multi-tenant pivots across child organizations. |
threat-investigator | Use this agent when investigating a ThreatLocker security event — reconstructing a timeline around a host/user/file, tracing a file's history across the fleet, identifying repeated denials, and surfacing policy bypasses or audit-only matches that warrant new policy rules. |
HubSpot CRM
| Agent | Description |
|---|---|
client-relationship-manager | Use this agent when an MSP account manager or vCIO needs to review account health across the client portfolio in HubSpot. |
pipeline-health-reporter | Use this agent when an MSP sales manager or leadership needs to analyze pipeline health, deal velocity, stage conversion rates, or forecast accuracy in HubSpot. |
Spamtitan
| Agent | Description |
|---|---|
quarantine-release-reviewer | Use this agent when an MSP technician or client needs to systematically review the SpamTitan quarantine queue for false positives, release legitimate messages, identify patterns of legitimate mail being blocked, or generate a quarantine digest for client review. |
spam-filter-analyst | Use this agent when analyzing spam and phishing patterns in SpamTitan, managing the quarantine queue, tuning allowlist and blocklist rules, investigating held email, or generating email filtering statistics for MSP clients. |
Xero
| Agent | Description |
|---|---|
billing-reconciler | Use this agent when an MSP needs to reconcile billing in Xero — matching invoices to contracts, tracking outstanding receivables, identifying billing discrepancies, or reviewing cash flow. |
cash-flow-analyzer | Use this agent when an MSP needs to analyze cash flow position in Xero — tracking accounts receivable aging trends, forecasting upcoming payables vs. expected inflows, identifying months where collections may fall short of committed expenses, or producing a 90-day cash flow projection. |
Alternative Payments
| Agent | Description |
|---|---|
payment-reconciler | Use this agent when an MSP needs to reconcile Alternative Payments activity — matching transactions to invoices, surfacing unpaid and overdue invoices, summarizing payouts and the transactions that compose them, flagging failed or declined transactions, and tracking outstanding receivables via hosted payment requests. |
Ironscales
| Agent | Description |
|---|---|
crowdsourced-intel-harvester | Use this agent when harvesting and analyzing crowdsourced threat intelligence from IRONSCALES' global network — identifying trending attack types, surfacing indicators seeing increased reports, comparing client threat profiles to industry peers, and generating intelligence briefings from the collective signal. |
phishing-responder | Use this agent when responding to user-reported phishing emails in IRONSCALES, triaging the incident queue, classifying emails, coordinating quarantine and remediation, or reviewing security statistics for MSP clients. |
Mimecast
| Agent | Description |
|---|---|
email-continuity-checker | Use this agent when verifying Mimecast email continuity and archiving health — not for threat investigation, but for checking continuity mode status, verifying archiving is capturing expected mail volumes, auditing connector health, and confirming restore capability. |
email-threat-investigator | Use this agent when investigating email-borne threats, tracing suspicious messages, analyzing TTP click and attachment logs, auditing Mimecast security posture, or managing held email queues for MSP clients on the Mimecast platform. |
Wyre Gateway
| Agent | Description |
|---|---|
asset-reconciliation-auditor | Use this agent when an MSP needs to reconcile its asset estate across managed, secured, billed, and documented systems to surface security coverage gaps, revenue leakage, ghost assets, and shadow IT. |
book-of-business-pulse | Use this agent when an MSP owner, service-delivery manager, or ops lead needs a single operational, commercial, and security heartbeat across the entire client portfolio. |
change-drift-sentinel | Use this agent when an MSP needs to detect unauthorized, undocumented, or security-weakening configuration changes across the client estate and correlate each change against change-control tickets and documentation currency. |
client-360-briefer | Use this agent when an MSP technician, account manager, or vCIO needs a complete, synthesized briefing on a client before a call, meeting, or QBR. |
client-discovery-agent | Use this agent when an MSP is beginning to onboard a new client, conducting a prospect assessment, or performing a takeover from another provider and needs a comprehensive cross-system discovery sweep to establish a baseline of what exists before setup work begins. |
compliance-evidence-packager | Use this agent when a client needs compliance evidence gathered for a formal audit or assessment against a recognized framework. |
dr-readiness-auditor | Use this agent when an MSP needs to assess the true disaster-recovery readiness of a client — going beyond backup dashboard green lights to evaluate coverage, test-restore history, runbook maturity, and RTO/RPO achievability. |
gateway-ops | Use this agent when an MSP administrator needs to review gateway activity, audit tool usage across the team, investigate suspicious access patterns, check permission configurations, or monitor for anomalies in how MSP tools are being accessed through the WYRE MCP Gateway. |
incident-war-room-coordinator | Use this agent when a major incident (P1 or Critical severity) has been declared or is suspected, and the team needs immediate situational awareness across all affected systems and stakeholders. |
license-true-up-reconciler | Use this agent when an MSP operations manager, account manager, or billing team needs to reconcile subscription license seats across the full provisioning-to-billing chain and quantify waste, leakage, and over-collection. |
offboarding-orchestrator | Use this agent when an MSP is ending a client relationship — whether through churn, client acquisition, mutual termination, or non-renewal — and needs to orchestrate a complete, auditable teardown across every connected tool, reclaim all licensed spend, and fulfill contractual data-handover obligations. |
onboarding-completeness-checker | Use this agent when an MSP needs to validate that a newly onboarded client has been fully set up across all MSP tools and systems before transitioning to steady-state support. |
portfolio-threat-sweep | Use this agent when an indicator set — file hashes, domains, IPs, sender addresses, URLs, a CVE, or a MITRE ATT&CK technique — needs to be hunted across every client tenant simultaneously to map blast radius and identify exposure before a campaign spreads. |
qbr-prep-agent | Use this agent when an MSP account manager or vCIO needs to prepare a complete Quarterly Business Review data package for a client. |
renewal-risk-analyzer | Use this agent when an MSP account manager, sales leader, or operations manager wants to identify clients at risk of not renewing before the renewal conversation happens. |
security-posture-scorer | Use this agent when an MSP needs a comprehensive, scored security health assessment for a specific client — acting as a vCISO-style health check by aggregating data across all connected security tools. |
service-profitability-auditor | Use this agent when an MSP owner, operations leader, or finance lead needs to identify which clients and contracts are losing money or eroding margin across the portfolio. |
technician-performance-coach | Use this agent when a service delivery manager or operations lead wants to understand technician performance trends and get actionable coaching recommendations grounded in data. |
ticket-deflection-analyzer | Use this agent when an MSP operations lead or service delivery manager wants to identify recurring ticket patterns that can be eliminated or deflected through automation, self-service, or root-cause remediation — and quantify the labor being silently consumed. |
user-lifecycle-orchestrator | Use this agent when an MSP needs to provision, modify, or deprovision an individual employee's access, identity, licensing, and security posture across all connected systems for a client. |
vulnerability-remediation-prioritizer | Use this agent when an MSP needs a risk-ranked, actionable remediation workplan from raw vulnerability and missing-patch data — going beyond compliance status to tell technicians exactly what to fix first and why. |
Microsoft Graph
| Agent | Description |
|---|---|
entra-reporting-analyst | Use this agent when an MSP technician, service-desk analyst, account manager, or vCISO needs to answer questions about a client's Microsoft Entra (Azure AD) identity and directory data — user and license counts, MFA registration gaps, guest inventory, inactive accounts, app inventory, directory roles, sign-in activity. |
Azure Mcp
| Agent | Description |
|---|---|
azure-ops-analyst | Use this agent when an MSP engineer, service manager, or cloud lead needs a read-only Azure operations investigation — resource health triage, cost and Azure Advisor analysis, quota/capacity headroom checks, and observability-posture reporting across subscriptions. |
Meraki
| Agent | Description |
|---|---|
meraki-network-auditor | Use this agent when an MSP needs a read-only health and security audit of a Cisco Meraki organization — sweeping networks, devices, and appliances to surface offline or alerting hardware, appliances with site-to-site VPN peers down, overly-permissive firewall rules, and SSIDs configured with weak or open authentication. |
Ncentral
| Agent | Description |
|---|---|
device-auditor | Use this agent when the user wants a device audit across N-central customers - inventory sweeps, missing asset data, expired or expiring warranties, untracked lifecycle records, or failed service monitors. |
issue-triager | Use this agent when the user wants active issues triaged across N-central customers - morning sweeps, severity ranking, root-cause grouping, or deciding what to remediate first. |
Ops Pack
| Agent | Description |
|---|---|
board-health-auditor | Use this agent when a service manager, dispatcher, or team lead needs a full cross-board health read on the connected PSA — unassigned aging, SLA-at-risk count, technician load balance, stale/stuck tickets, and duplicate clusters, rolled into a single scored report. |
dispatch-coordinator | Use this agent when the unassigned ticket queue needs to be triaged and assigned to technicians, factoring in SLA pressure, client tier, ticket age, and current technician load. |
stale-ticket-chaser | Use this agent when tickets have gone quiet and someone needs to figure out why and what to do about each one — not just that they're stale. |
Secops Pack
| Agent | Description |
|---|---|
incident-timeline-builder | Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question. |
overnight-alert-summarizer | Use this agent when a technician needs a morning read on everything that fired overnight across the connected EDR/MDR/SIEM stack, normalized into one ranked digest instead of five separate vendor consoles. |
tenant-exposure-ranker | Use this agent when the MSP needs a portfolio-wide read on which clients carry the most current security risk — open critical findings, unpatched or uncontained threats, MFA coverage gaps, and stale EDR/agent coverage — ranked so leadership or the security team can prioritize attention. |
Finance Pack
| Agent | Description |
|---|---|
billing-drift-detector | Use this agent when an MSP billing team, controller, or account manager needs to run a portfolio-wide sweep for contract-vs-invoice mismatches — surfacing every client where the PSA agreement and the accounting invoice disagree, ranked by dollar impact. |
profitability-ranker | Use this agent when an MSP owner, operations leader, or finance lead needs to rank clients from most to least profitable using actual revenue and cost data, flagging any operating at a loss. |
renewal-calendar-builder | Use this agent when an MSP account manager, sales leader, or operations manager needs a forward-looking view of every upcoming contract and subscription renewal across the connected PSA and cloud-marketplace distributors, with recommended lead time per renewal. |
Compliance Pack
| Agent | Description |
|---|---|
control-drift-reporter | Use this agent when an MSP needs to know what has changed in a client's compliance posture since the last known-good baseline, prioritized by how much each change actually matters. |
evidence-packager | Use this agent when an MSP needs to gather and assemble compliance evidence for a client against a named framework or control set, producing a source-cited package an auditor or client can review. |
questionnaire-autofiller | Use this agent when a client needs its cyber-insurance renewal or new-business questionnaire drafted using live tool evidence rather than best-guess answers. |
Sales Pack
| Agent | Description |
|---|---|
pipeline-auditor | Use this agent when a sales manager, deal desk owner, or MSP leadership needs a full cross-vendor sweep of the open sales pipeline — stalled and at-risk deals ranked by value and staleness, with each stall diagnosed against the full quote-to-close chain rather than CRM activity alone. |
proposal-follow-up-tracker | Use this agent when a sales rep, deal desk owner, or sales manager needs to know which proposals and quotes need attention right now, with a drafted follow-up action for each. |
warm-lead-router | Use this agent when a sales manager or rep needs to know which leads are showing real buying intent right now, and who should follow up on each one. |
Devops Pack
| Agent | Description |
|---|---|
oncall-handoff-builder | Use this agent when an on-call engineer needs a structured shift handoff brief — what's currently paging or unresolved, what happened during the last shift, known-flaky alerts to watch, and anything escalated but not yet actioned — assembled from whatever incident-management tool is connected. |
postmortem-drafter | Use this agent when an engineer, SRE, or incident manager needs a full blameless postmortem drafted from a resolved incident — identified by ID or by a rough time window — reconstructed from the incident tool's event log plus correlated observability and deploy data. |
reliability-scorecard | Use this agent when a team lead, SRE, or engineering manager needs a ranked reliability status across connected services — error-budget burn rate where a formal SLO exists, degrading to raw error-rate/uptime trend reporting where it doesn't — worst service first. |
Cloudops Pack
| Agent | Description |
|---|---|
capacity-forecaster | Use this agent when an MSP needs to know whether current cloud resource capacity will hold up under growth, or which resources are already over- or under-provisioned. |
cost-anomaly-detector | Use this agent when an MSP needs to investigate unexpected cloud spend or hunt for orphaned/idle cloud resources that are still costing money. |
network-health-auditor | Use this agent when an MSP needs a portfolio-wide or single-client sweep of network device and link health across whatever network-monitoring tools are connected. |
Awareness Pack
| Agent | Description |
|---|---|
human-risk-scorer | Use this agent when the MSP needs a per-user or per-org "human risk score" built from training completion and phishing-simulation performance, to rank the riskiest users or clients on the human/culture layer of security. |
phishing-simulation-analyst | Use this agent when the MSP needs to analyze phishing-simulation campaign results — click-rate trends over time and repeat-clicker identification — for a single client or across the portfolio. |
training-compliance-auditor | Use this agent when the MSP needs to verify security-awareness training completion for a single client or across the whole portfolio, and flag overdue users or clients falling behind their expected training cadence. |
Backup Pack
| Agent | Description |
|---|---|
backup-health-auditor | Use this agent when an MSP needs a portfolio-wide read on whether backup jobs are actually succeeding across whatever backup/BCDR tools are connected — missed backups, active failure streaks, and storage risk, ranked by severity. |
restore-readiness-checker | Use this agent when an MSP needs to know whether backups have actually been restore-tested, not just whether they're running — flagging clients or systems whose backups have never had a restore, boot-verification, or spot-check drill performed, with a recommended test schedule. |
retention-compliance-auditor | Use this agent when an MSP needs to verify that actual backup retention configuration and cadence meet contracted or required retention/RPO policy, rather than assuming appliance defaults are adequate. |
Assets Pack
| Agent | Description |
|---|---|
eol-risk-assessor | Use this agent when someone needs to know which devices, OS versions, or firmware are approaching or past end-of-life/end-of-support, prioritized by how much it actually matters if left unaddressed. |
refresh-planner | Use this agent when someone needs a forward-looking hardware refresh calendar that combines warranty, EOL/EOS, and device age into a replace-now/plan-this-year/monitor plan. |
warranty-status-auditor | Use this agent when someone needs a portfolio-wide or client-specific view of hardware warranty coverage, pulled and normalized across every connected RMM and documentation tool. |