MSPs need insider-risk detection across unrelated client environments without sharing raw tenant data or invasive surveillance collectors. Vedric keeps customer records and primary baselines tenant-scoped; an optional, thresholded global fallback uses aggregate statistics only and can be disabled per tenant.
THE PROBLEM
An MSP that lights up surveillance-grade collectors across client environments inherits the legal and reputational risk of every client at once. A breach of MSP-collected content data is several breaches in one. Yet MSPs need real visibility into client behavior, not just patch status. Vedric minimizes collection to behavioral telemetry, explicitly discloses the bounded PowerShell script-preview exception, and enforces tenant boundaries around customer records.
Many "multi-tenant" tools expose raw data or unconstrained models across client boundaries. MSPs need customer records, ordinary baselines, queries, and response actions bound to one tenant, with any aggregate fallback narrowly thresholded and opt-out capable.
Tools that capture screens, keystrokes, or file contents create a liability surface that scales with the number of clients. One MSP-side breach is a multi-client incident.
Threshold-based stacks generate fatigue at one tenant; multiplied across a fleet they become unreviewable. MSPs need correlated storylines, not raw events.
A baseline trained across all tenants is not a baseline. It is a smoothed average that catches almost nothing. Per-tenant per-user baselines are the only way to read drift on each client.
Vedric is a multi-tenant platform from the data layer up. Customer telemetry, personal and tenant peer baselines, storylines, and AI tool calls are tenant-scoped. A global fallback can use aggregate statistics only after at least five tenants qualify, with at least three verified users per contributing tenant cohort; a tenant can opt out of contribution and use. The MSP operator sees client environments as separate spaces with separate audit trails.
Telemetry, personal and tenant peer baselines, storylines, and AI tool calls are tenant-scoped. Only thresholded aggregate baseline statistics can feed the optional global fallback; raw telemetry and user identifiers do not cross tenant boundaries.
The agent does not capture screens, keystrokes, audio, or document/file bodies. When PowerShell Script Block Logging is available, it can collect a best-effort credential-scrubbed preview with up to 2,048 bytes of script text plus a fixed truncation marker; that bounded content exception belongs in every client notice.
The MSP operator sees a per-tenant storyline view and an aggregate fleet view that shows storyline counts and severity per client without crossing into per-tenant content. Each tenant's admin can read their own audit trail.
EXAMPLE SCENARIO · TIMELINE
The MSP runs Vedric across 40 client tenants. Per-client baselines have matured. The fleet view shows quiet activity across most tenants and one storyline that materialized overnight on a specific client.
The MSP saw one signal across 40 clients without access to another client's raw tenant records. The client got an exportable storyline and audit record for the handoff.
Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.
Read the full privacy stance →Early access is offered to MSPs running production Windows fleets across multiple client environments who want behavioral visibility without inheriting a content liability surface.