
I don’t just use AI tools. I build the plumbing that lets them do real work safely across an MSP’s stack: ticketing, RMM, endpoint security, Microsoft 365 and backups.
MCP servers
Model Context Protocol servers that give Claude structured, scoped access to the tools our techs use every day. Most are read-only by design.
| Server | What it does |
|---|---|
| Microsoft 365 Management | Tenant administration with preview-then-execute changes |
| M365 Security Investigation | Read-only sign-in, audit and mailbox forensics for account breach investigations |
| N-sight RMM | Read-only device, check, patch and backup data from N-able N-sight |
| WatchGuard EPDR | Endpoint protection status, security events, risk and patch posture |
| Freshdesk | Ticket triage, private notes and knowledge base access |
Agent skills
- Freshdesk ticket triage (the team’s most-used): investigates alerts across M365, endpoints, EDR and RMM, writes a clean private note and closes informational tickets
- M365 breach report: turns an affected account and a rough timeframe into a structured compromise investigation
- Google Workspace: safe editing of Docs, Sheets and Slides
- Morning brief and inbox sweep: executive-assistant style daily briefs and inbox triage
Automation pipelines
- n8n phishing triage: Freshdesk webhook triggers analysis and filing of reported phishing email
- Weekly backup review: collects the week’s backup alert tickets from Freshdesk, generates a report and flags the backup jobs that need a closer look
- AppSheet approval and filing app
- Composio integration giving each tech’s Claude account API access across the tool stack
Self-hosted agent lab
- Hermes and OpenClaw agents on a Linux host reachable over Tailscale
- Seven scheduled jobs: Entra cleanup, PIM digest cleanup, backup reviews, backups and memory backfill
- GPU-backed memory search and a vault-based portable skill framework
- Local models with LM Studio, Ollama and CUDA builds of llama.cpp, plus ComfyUI workflows
- This WordPress site, run in Docker and managed by AI agents with snapshot, change, verify and rollback on every write
Vendor assessment engine
A reusable engine I built with AI agents to answer vendor security questionnaires: the kind a bank sends as a supplier-controls assessment. Instead of re-answering hundreds of controls from scratch, it drafts answers from a stored knowledge base and cites the evidence behind each one.
- Knowledge base: atomic facts about a client plus a crosswalk mapping any vendor question to the facts that answer it (300+ controls carried over from prior assessments)
- Semantic matching: local sentence embeddings match a brand-new questionnaire to the known controls and draft an answer
- Evidence retrieval: the client’s policies and provider attestations (SOC 2, ISO 27001) are indexed so every answer can quote its source
- Review queue: anything unsupported or unknown is flagged for a person instead of guessed, and reviewer corrections flow back into the knowledge base
- Multi-client: each client’s facts sit beside a shared crosswalk, so one engine serves many organizations
- Outputs: a vendor-ready workbook and a PDF evidence pack for the audit trail
Built in R with local embeddings, so client data never leaves the machine. The rule that governs it: it never claims a control it cannot evidence.
Design rule for every agent I build: read-only by default, and nothing changes without a way to undo it.