Skip to content
ECZ‑IDfor MSPs & MSSPs

ECZ-ID for MSPs & MSSPs

Know which AI can act for which customer.

Prove the authority behind it.

Give every client a current, independently checkable record of which machine actors are associated with them, who operates them, what authority exists, what state applies, and what evidence can be re-checked.

No signup. Seventeen questions, about three minutes, and your answers never leave your browser.

Designed to work alongside your RMM, PSA, IAM, OAuth and security controls — not replace them.

Why now

Machine actors arrived inside MSP tooling, and a UK Bill moved to bring MSPs into cyber regulation, in the same quarter.

Not a trend argument — a calendar. Each entry below is a dated public fact from the organisation that made it, with a link so you can check it yourself rather than take our word for it.

  1. 28 April 2026

    Kaseya introduced an agentic IT management platform, powered by its Kaseya Intelligence engine, at Kaseya Connect Global.

    Why it matters — Autonomous execution arrived inside a platform many MSPs already run. Nobody had to choose to adopt it.

    Kaseya describes it as “the first agentic IT management platform”; that superlative is the vendor's and is not independently established, so it is not repeated as fact here.

    Source: Kaseya press release, “Kaseya Unveils the First Agentic IT Management Platform”, 28 April 2026 · verified 2026-08-13

  2. April 2026

    The Microsoft Entra Agent ID platform reached general availability. It provides the identity foundation for AI agents inside an organisation's own Microsoft Entra tenant: an agent identity is a service principal that, in Microsoft's words, “can only be issued tokens in the Microsoft Entra tenant where they're created” and “can't access resources or APIs in other tenants”.

    Why it matters — Agent identity became a first-class object with a vendor behind it. Identity is not authority, and a tenant-scoped identity does not travel across the customers you manage.

    Agent ID works with agents built on Microsoft and non-Microsoft platforms — the boundary is the tenant, not the vendor. Agent identity blueprints can be multitenant, but each tenant gets its own tenant-local identity and the identities themselves always remain single-tenant.

    Source: Microsoft Learn — Microsoft Entra releases and announcements (April 2026 entry); Overview of agent identities in Microsoft Entra · verified 2026-08-13

  3. As at 13 August 2026

    The Cyber Security and Resilience (Network and Information Systems) Bill would, if enacted, extend the UK's Network and Information Systems Regulations 2018 to certain managed service providers for the first time. The Bill calls them “relevant managed service providers” and excludes micro and small enterprises, so on the Government's own account only some medium and large providers would come into scope. The Commons passed the Bill on 16 June 2026; it was introduced in the Lords on 17 June 2026 as HL Bill 32 and completed second reading there on 14 July 2026, with committee stage due to begin on 1 September 2026. It has not received Royal Assent and is not yet law.

    Why it matters — Legislators are reasoning out loud about providers who hold privileged access into many client estates at once. Whatever the Bill's final shape, that is the same structural fact this product is built around.

    Position as at 13 August 2026 — a Bill mid-passage. Check the live record at bills.parliament.uk before relying on it. Nothing in the Bill requires ECZ-ID or any named product.

    Source: UK Parliament — Bill 4035 stages record; HL Bill 32 as brought from the Commons; Commons Hansard, 16 June 2026 · verified 2026-08-13

  4. 9 July 2026

    The ITU announced the ITU-T Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA), established by ITU-T Study Group 17 in June 2026. It held its first meeting online on 29 July 2026, with a face-to-face kick-off scheduled for 1–4 December 2026 in Paris.

    Why it matters — The question of who a machine acts for is now on the international standards agenda. That makes it a legitimate engineering question rather than a vendor talking point — and it constrains what any single vendor, including us, can claim to own.

    An ITU focus group is exploratory pre-standardisation work. It is not an adopted ITU standard and imposes no obligation on anyone.

    Source: ITU — ITU-T FG-TIDA official page and ITU Media Centre · verified 2026-08-13

  5. 16 July 2026

    ConnectWise announced the general availability of the ConnectWise Platform, which unifies ConnectWise PSA, ConnectWise RMM, ScreenConnect, ConnectWise SIEM, automation, orchestration and ConnectWise AI Agents into a single platform.

    Why it matters — Machine actors are now in production inside the channel's largest PSA and RMM stack. If you run it, they are in your clients' estates whether or not you deployed them yourself.

    Source: ConnectWise press release, 16 July 2026 · verified 2026-08-13

  6. 2 August 2026

    The transparency obligations in Article 50 of the EU AI Act (Regulation (EU) 2024/1689) have applied since 2 August 2026. They were not postponed by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), which deferred the high-risk requirements in Chapter III to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.

    Why it matters — A live obligation, frequently misreported as delayed. It is a transparency duty, not a high-risk one, and it does not name any product.

    One transitional exception: for AI systems generating synthetic content placed on the market before 2 August 2026, providers have until 2 December 2026 to comply with the machine-readable marking obligation in Article 50(2). Article 50 sets outcome duties and is technology- and vendor-neutral.

    Source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Official Journal of the European Union · verified 2026-08-13

What is deliberately not on this page

There are striking statistics in this market. We have left them out, because each one reached us through a citation of a citation and we have not read the original.

  • Survey figures on how many organisations lack visibility of AI agents, or grant agents more access than humans Available to us only through secondary citation. §21 requires the primary report, its sample and its method before publication.
  • Proportion of professionals who cannot say how fast an AI system could be halted The strongest single statistic available for this argument, and still secondary. Withheld until the primary report is obtained.
  • MSP channel profitability and market-growth figures Analyst material behind licensing, and definitions of the market vary widely enough that the number changes with the definition.
  • Machine-to-human identity ratios Published ratios differ by roughly an order of magnitude depending on who counts and what they count. The disagreement is the honest finding; a single ratio would misrepresent it.
  • Return on investment, payback period, attach rate or margin for this service No validated data exists for this category. Any figure would be invented, and inventing one is the fastest way to lose a technical reader.
  • Customer counts, partner counts, member counts or waitlist numbers We are early and will not manufacture traction.

The structural difference

Your accountability surface multiplies by customer count.

Enterprise governance frameworks assume one organisation governing its own machines. You are not that shape. You hold privileged access into many client estates at once, so when machine actors enter your tooling, they enter every client estate you touch — and the question “who authorised this?” arrives once per client, not once.

Fig. 1One operator, many customer authorities
One MSP holds a separate authority record for each customerA single MSP node connects to four separate client nodes. Each connection is a distinct customer authority. The client nodes are not connected to one another: no client can see another client's record.Your MSPaccountable operatorAUTHORITYClient Aown record · own state · own proofAUTHORITYClient Bown record · own state · own proofAUTHORITYClient Cown record · own state · own proofAUTHORITYClient Down record · own state · own proofclientre-check
Each client has their own authority record, their own current state and their own proof. No client can see another client's record — the absence of a line between them is the isolation boundary, and it is enforced in the product, not drawn here for effect.

The four questions

Four questions the accountability chain has to be able to answer.

When someone asks who let a machine act for a client — a client themselves, their insurer, or an auditor working on their behalf — these are the four things an answer has to contain.

  1. 01

    What machine is acting?

    Which agents, automations and integrations are associated with this client — named, with the identifier they carry in the system they run in.

    Answered by · Machine Trust Register

  2. 02

    Who authorised it?

    What this client has actually authorised, recorded separately from what a system happens to permit. A platform permission is not a customer's authority.

    Answered by · Customer Authority

  3. 03

    Can it be revoked?

    How fast the authority can be withdrawn, what state applies right now, and whether the withdrawal is something anyone else can confirm.

    Answered by · Lifecycle state

  4. 04

    What evidence exists?

    What was referenced, when, and by whom — kept so that what was true at an earlier time is still answerable later.

    Answered by · Evidence references

We call the resulting capability Machine Trust.

It is not a new tool in your stack. It is the record of who authorised what, which machine holds that authority right now, and what a client can check for themselves — kept current across every customer you manage, and across the vendors you use.

Alongside, not instead of

Your stack does what it was built to do. This is a different question.

Nothing below is a criticism of tools you have already bought. Each one does its job. None of them was designed to hold a per-customer record of who authorised a machine to act on that customer's behalf — because until recently nobody needed one.

Fig. 2What your existing stack does
LayerWhat it does
RMMN-able, NinjaOne, Datto, KaseyaManages and executes on endpoints.
PSAConnectWise, HaloPSA, AutotaskRuns the service desk, contracts and billing.
IAM / IdPEntra ID, Okta, OAuthAuthenticates identities and issues tokens.
SIEM / SOARSentinel, SplunkCollects telemetry and orchestrates response.
EDR / MDRDefender, SentinelOne, CrowdStrikeDetects and contains threats on the endpoint.
Gateways / orchestrationMCP gateways, workflow enginesRoutes and executes machine calls.
Fig. 3What ECZ-ID adds
  • Customer authority — what this client authorised, recorded as its own object.
  • Operator delegation — what you, as the accountable operator, passed to the machine.
  • Cross-vendor machine relationships — one record across the tools, not one per tool.
  • Current lifecycle state — active, suspended, revoked, superseded, expired.
  • Evidence references — what was referenced and when, kept for later.
  • Customer-checkable proof — the client confirms it without going through you.

What ECZ-ID is not

ECZ-ID does not replace your RMM, PSA, IAM, identity provider, OAuth, Entra, SIEM, SOAR, EDR, MDR, MCP gateway, workflow engine or orchestration platform.

  • ECZ-ID does not execute anything in your customers' systems.
  • ECZ-ID does not authenticate users or machines.
  • ECZ-ID does not monitor, detect or alert on threats.
  • ECZ-ID does not block, throttle or intercept a machine action.
  • ECZ-ID does not manage endpoints, tickets, contracts or billing.
  • ECZ-ID does not certify you as compliant with anything, and buying it does not make you compliant with anything.

ECZ-ID records identity, authority, delegation, state and evidence, and projects a proof your customer can check independently.

How the model works in detail

The model

Every link is recorded, and the customer can check the last one.

The chain runs from the customer to the machine and back to the customer. The two links in the middle are the ones you are accountable for, and the two at the end are the ones your client can verify without going through you.

  1. 01CustomerThe business the work is done for
  2. 02Customer AuthorityWhat the customer has authorised
  3. 03MSP / accountable operatorWho is answerable for the machine
  4. 04Operator DelegationWhat the MSP passed to the machine
  5. 05Machine actorThe agent, automation or integration
  6. 06Native identityIts identifier in the system it runs in
  7. 07Action surfaceThe MCP server, API or console it reaches
  8. 08EvidenceWhat was referenced, and when
  9. 09Current stateActive, suspended, revoked, superseded, expired
  10. 10Independent re-checkThe customer confirms it themselves

The question that lands

How fast can you turn it off, and who can independently verify you did?

Suspension and revocation are recorded events with a time, not a silent change to a permission somewhere. A revoked grant is terminal — it is never resurrected, and a replacement is a new record with a new identifier. Your client can check the current state themselves without asking you and without taking your word for it.

Fig. 4Lifecycle states and what each one means
StateMeaningReversibleRule
ACTIVEAuthority stands and the machine actor may act within it.YesCan be suspended or revoked at any time.
SUSPENDEDAuthority is paused. Nothing is deleted and the history stays.YesReinstatement is a recorded event, not a silent restore.
REVOKEDAuthority is withdrawn.NoTerminal. A revoked grant is never resurrected — a new grant is a new record with a new identifier.
SUPERSEDEDA newer grant replaced this one.NoThe superseded record is retained so that what was true at an earlier time is still answerable.
EXPIREDThe grant reached the end of its term.NoExpiry is recorded as an event with its time, not inferred from a missing row.
Revocation is terminal by design. A revoked grant is never reinstated — a replacement is a new record with a new identifier, so the history of what was true at an earlier time stays answerable.

See what the product produces, and what is not proven yet

The commercial shape

A line item you own, not a tool you absorb

The work this productises is work most MSPs already do — assembled by hand, after the fact, by the most expensive people in the business.

Quarterly review preparation

Assembling what changed in the client's estate, from several systems, by hand.

Security and insurance questionnaires

Answering control and third-party questions with evidence attached for each answer.

Supplier assurance requests

Responding when a client's own enterprise customers assess their supply chain — which routes to you.

Post-incident reconstruction

Establishing what acted, when, and under whose authority, after the fact.

Why that work arrives at your desk. Under Article 21(3) of the NIS 2 Directive (Directive (EU) 2022/2555), essential and important entities must, when considering which supply chain security measures are appropriate, take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of products and cybersecurity practices of their suppliers and service providers.

The duty falls on the in-scope entity and applies through national transposing law. Article 21(3) does not itself bring a supplier into scope — but note that Annex I lists managed service providers and managed security service providers as a sector of high criticality, so an MSP may be in scope in its own right under Articles 2 and 3.

Source: Directive (EU) 2022/2555, Article 21(3), Official Journal L 333/80, 27.12.2022

How the commercial structure works

  • You own the client relationship. ECZ-ID is never the retail brand.
  • You set the retail price. We do not publish what you should charge.
  • Partner of Record is structural — every downstream record carries exactly one.
  • Customer-facing surfaces read “operated by your firm, verified via ECZ-ID”. Never white-label: the independence is the product.

What we will not show you

We do not publish an ROI figure, a payback period or an attach rate for this service. We have no validated data for this category, and we are not going to model one and present it as evidence. If you are shown such a figure — by us or by anyone — ask what it was measured on, and how many customers were in the sample.

The recurring service in full

Fit

Who this is for — and who it is not for yet

This is for you if

  • You provide recurring managed services to businesses you do not own.
  • AI agents, automations or integrations act inside your clients' systems — whether you introduced them or your platform vendor did.
  • You hold privileged access across more than one client estate.
  • Someone — a client, an insurer, a client's enterprise customer — has asked, or will ask, who authorised a machine to act.
  • You would rather sell an accountable service than absorb the accountability quietly.

Not yet for you if

These are genuine exclusions, not a filter designed to make the programme look selective. If one of these describes you, applying now would waste your time and ours.

You do not provide recurring managed services
The model is built on an ongoing operator relationship. Project and break/fix work has no place to put a standing authority record.
You have no machine, AI or automation activity, and no near-term requirement
There is nothing yet to record. Run the free Machine Trust Check — if it returns “not yet”, that is a real answer and we will not sell past it.
You want a badge or a certificate
ECZ-ID does not certify anyone. There is no logo that means you passed. If a certificate is what you need, this is the wrong product.

The full list of exclusions

Commercial access

ECZ-ID Founding Partner Programme

Public category, private activation. Everything on this site is open to anyone. Commercial activation is by application, because the first partners shape the product and we would rather take a small number of firms properly than a large number badly.

There is no countdown, no seat count and no waitlist number. The criteria are published in full. Accepted partners begin with a £395 Client-Estate Machine Trust Audit — a working step, not a report you buy and file.