INSIDER RISK FOR MSPs

Behavioral visibility across client environments. No surveillance, no shared blast radius.

MSPs need to detect insider risk for a fleet of unrelated client environments, with full tenant isolation, no shared models, no shared blast radius, and no invasive collectors. Vedric was built multi-tenant and metadata-only from the first commit.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

MSP visibility cannot mean MSP surveillance.

An MSP that lights up surveillance-grade collectors across client environments inherits the legal and reputational risk of every client at once. A breach of MSP-collected content data is several breaches in one. Yet MSPs need real visibility into client behavior, not just patch status. The way out is metadata-only behavioral detection, with hard tenant isolation enforced everywhere it matters.

WHY CURRENT APPROACHES FALL SHORT

Why most insider-risk tools do not fit the MSP shape.

SHARED INFRASTRUCTURE

Many "multi-tenant" tools are single-tenant tools with a tenant_id column. Models are shared. Aggregation queries are shared. A noisy client distorts detection for the rest. MSPs need real isolation at every layer.

CONTENT-LEVEL COLLECTORS

Tools that capture screens, keystrokes, or file contents create a liability surface that scales with the number of clients. One MSP-side breach is a multi-client incident.

NOISY ALERTS

Threshold-based stacks generate fatigue at one tenant; multiplied across a fleet they become unreviewable. MSPs need correlated storylines, not raw events.

NO PER-CLIENT BASELINES

A baseline trained across all tenants is not a baseline. It is a smoothed average that catches almost nothing. Per-tenant per-user baselines are the only way to read drift on each client.

HOW VEDRIC HELPS

Built multi-tenant. Built metadata-only. Built audit-first.

Vedric is a multi-tenant platform from the data layer up. Every collected event, every baseline, every storyline, every AI tool call is scoped to one tenant. There is no cross-tenant query path. There is no shared model. The MSP operator sees client environments as separate spaces with separate audit trails.

01 /TENANT ISOLATION

No shared blast radius

Telemetry, baselines, storylines, and AI tool calls are all tenant-scoped. The platform does not run cross-tenant analytics, does not share peer baselines across tenants, and does not allow one client environment to influence another's detection.

02 /METADATA-ONLY

No multi-client liability surface

The agent does not capture screens, keystrokes, audio, or file contents. The MSP operator does not inherit a content-data liability surface that scales with clients.

03 /OPERATOR LAYER

A surface built for fleet workflow

The MSP operator sees a per-tenant storyline view and an aggregate fleet view that shows storyline counts and severity per client without crossing into per-tenant content. Each tenant's admin can read their own audit trail.

EXAMPLE SCENARIO · TIMELINE

A 40-client MSP detects a single concerning storyline.

The MSP runs Vedric across 40 client tenants. Per-client baselines have matured. The fleet view shows quiet activity across most tenants and one storyline that materialized overnight on a specific client.

  1. T+01
    T+01 - fleet dashboard shows one new high-confidence storyline on client tenant 17.
  2. T+02
    T+02 - MSP operator opens the tenant 17 view. Storyline contains scope drift, off-hours activity, and a privileged command not seen in six months on the same primary identity.
  3. T+03
    T+03 - operator reviews the AI verdict and evidence chain. All tool calls are scoped to tenant 17 only; no cross-tenant query was attempted or allowed.
  4. T+04
    T+04 - operator escalates to the client's designated security contact via the platform handoff. The handoff includes the storyline, evidence chain, and audit trail for the client's admin to review.
  5. T+05
    T+05 - client admin reads their own audit trail end-to-end. The chain holds up cleanly because every detection, tool call, and analyst action was signed.
  6. T+06
    T+06 - admin-gated response is taken on the client side. MSP operator does not push action against the client endpoint without the client admin approval flowing through.
OUTCOME

The MSP saw one signal across 40 clients without inheriting any client's content liability. The client got a complete, exportable storyline that survived the handoff intact.

WHAT MSPs GET

A platform that respects the boundary between MSP and client.

VEDRIC SURFACES
  • Per-tenant detection, baselines, storylines, and audit trails
  • Fleet dashboard with storyline counts and severity per client, no cross-tenant content
  • Tenant-isolated AI triage tools that cannot reach across tenants
  • Client admin can read their own audit trail end-to-end
  • Append-only audit trails per tenant, exportable for client review
VEDRIC DOES NOT DO
  • Train models or baselines across tenants
  • Allow cross-tenant queries from MSP operators
  • Capture screens, keystrokes, audio, or file contents
  • Push response actions to a client endpoint without the client admin approval flow
  • Let MSP operators see content from another client tenant under any circumstance
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Insider risk visibility built for the MSP shape.

Early access is offered to MSPs running production Windows fleets across multiple client environments who want behavioral visibility without inheriting a content liability surface.

Request Early AccessTalk to security teamResponse within one business day.