INSIDER RISK FOR MSPs

Behavioral visibility across client environments with explicit tenant boundaries.

MSPs need insider-risk detection across unrelated client environments without sharing raw tenant data or invasive surveillance collectors. Vedric keeps customer records and primary baselines tenant-scoped; an optional, thresholded global fallback uses aggregate statistics only and can be disabled per tenant.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

MSP visibility cannot mean MSP surveillance.

An MSP that lights up surveillance-grade collectors across client environments inherits the legal and reputational risk of every client at once. A breach of MSP-collected content data is several breaches in one. Yet MSPs need real visibility into client behavior, not just patch status. Vedric minimizes collection to behavioral telemetry, explicitly discloses the bounded PowerShell script-preview exception, and enforces tenant boundaries around customer records.

WHY CURRENT APPROACHES FALL SHORT

Why most insider-risk tools do not fit the MSP shape.

SHARED INFRASTRUCTURE

Many "multi-tenant" tools expose raw data or unconstrained models across client boundaries. MSPs need customer records, ordinary baselines, queries, and response actions bound to one tenant, with any aggregate fallback narrowly thresholded and opt-out capable.

CONTENT-LEVEL COLLECTORS

Tools that capture screens, keystrokes, or file contents create a liability surface that scales with the number of clients. One MSP-side breach is a multi-client incident.

NOISY ALERTS

Threshold-based stacks generate fatigue at one tenant; multiplied across a fleet they become unreviewable. MSPs need correlated storylines, not raw events.

NO PER-CLIENT BASELINES

A baseline trained across all tenants is not a baseline. It is a smoothed average that catches almost nothing. Per-tenant per-user baselines are the only way to read drift on each client.

HOW VEDRIC HELPS

Built multi-tenant. Built collection-minimized. Built audit-first.

Vedric is a multi-tenant platform from the data layer up. Customer telemetry, personal and tenant peer baselines, storylines, and AI tool calls are tenant-scoped. A global fallback can use aggregate statistics only after at least five tenants qualify, with at least three verified users per contributing tenant cohort; a tenant can opt out of contribution and use. The MSP operator sees client environments as separate spaces with separate audit trails.

01 /TENANT ISOLATION

Raw tenant records stay tenant-bound

Telemetry, personal and tenant peer baselines, storylines, and AI tool calls are tenant-scoped. Only thresholded aggregate baseline statistics can feed the optional global fallback; raw telemetry and user identifiers do not cross tenant boundaries.

02 /COLLECTION-MINIMIZED

A narrower multi-client content surface

The agent does not capture screens, keystrokes, audio, or document/file bodies. When PowerShell Script Block Logging is available, it can collect a best-effort credential-scrubbed preview with up to 2,048 bytes of script text plus a fixed truncation marker; that bounded content exception belongs in every client notice.

03 /OPERATOR LAYER

A surface built for fleet workflow

The MSP operator sees a per-tenant storyline view and an aggregate fleet view that shows storyline counts and severity per client without crossing into per-tenant content. Each tenant's admin can read their own audit trail.

EXAMPLE SCENARIO · TIMELINE

A 40-client MSP detects a single concerning storyline.

The MSP runs Vedric across 40 client tenants. Per-client baselines have matured. The fleet view shows quiet activity across most tenants and one storyline that materialized overnight on a specific client.

  1. T+01
    T+01 - fleet dashboard shows one new high-confidence storyline on client tenant 17.
  2. T+02
    T+02 - MSP operator opens the tenant 17 view. Storyline contains scope drift, off-hours activity, and a privileged command not seen in six months on the same primary identity.
  3. T+03
    T+03 - operator reviews the AI verdict and evidence chain. All tool calls are scoped to tenant 17 only; no cross-tenant query was attempted or allowed.
  4. T+04
    T+04 - operator escalates to the client's designated security contact via the platform handoff. The handoff includes the storyline, evidence chain, and audit trail for the client's admin to review.
  5. T+05
    T+05 - client admin reads and exports their own append-only application audit trail. The record shows the detection, tool calls, and analyst action without claiming public-key signatures on every row.
  6. T+06
    T+06 - admin-gated response is taken on the client side. MSP operator does not push action against the client endpoint without the client admin approval flowing through.
OUTCOME

The MSP saw one signal across 40 clients without access to another client's raw tenant records. The client got an exportable storyline and audit record for the handoff.

WHAT MSPs GET

A platform that respects the boundary between MSP and client.

VEDRIC SURFACES
  • Per-tenant detection, baselines, storylines, and audit trails
  • Fleet dashboard with storyline counts and severity per client, no cross-tenant content
  • Tenant-isolated AI triage tools that cannot reach across tenants
  • Client admin can read their own audit trail end-to-end
  • Append-only audit trails per tenant, exportable for client review
VEDRIC DOES NOT DO
  • Share raw telemetry or user identifiers across tenants; aggregate fallback statistics are thresholded and tenant-opt-out capable
  • Allow cross-tenant queries from MSP operators
  • Capture screens, keystrokes, audio, or document/file bodies; bounded PowerShell script previews are the disclosed exception
  • Grant response authority from the fleet view alone; action requires an admin role inside the client tenant and deployment-level enablement
  • Let MSP operators see content from another client tenant under any circumstance
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Insider risk visibility built for the MSP shape.

Early access is offered to MSPs running production Windows fleets across multiple client environments who want behavioral visibility without inheriting a content liability surface.

Request Early AccessTalk to security teamResponse within one business day.