AI & Automation

Glowing blue fiber optic strands

I don’t just use AI tools. I build the plumbing that lets them do real work safely across an MSP’s stack: ticketing, RMM, endpoint security, Microsoft 365 and backups.

MCP servers

Model Context Protocol servers that give Claude structured, scoped access to the tools our techs use every day. Most are read-only by design.

ServerWhat it does
Microsoft 365 ManagementTenant administration with preview-then-execute changes
M365 Security InvestigationRead-only sign-in, audit and mailbox forensics for account breach investigations
N-sight RMMRead-only device, check, patch and backup data from N-able N-sight
WatchGuard EPDREndpoint protection status, security events, risk and patch posture
FreshdeskTicket triage, private notes and knowledge base access

Agent skills

  • Freshdesk ticket triage (the team’s most-used): investigates alerts across M365, endpoints, EDR and RMM, writes a clean private note and closes informational tickets
  • M365 breach report: turns an affected account and a rough timeframe into a structured compromise investigation
  • Google Workspace: safe editing of Docs, Sheets and Slides
  • Morning brief and inbox sweep: executive-assistant style daily briefs and inbox triage

Automation pipelines

  • n8n phishing triage: Freshdesk webhook triggers analysis and filing of reported phishing email
  • Weekly backup review: collects the week’s backup alert tickets from Freshdesk, generates a report and flags the backup jobs that need a closer look
  • AppSheet approval and filing app
  • Composio integration giving each tech’s Claude account API access across the tool stack

Self-hosted agent lab

  • Hermes and OpenClaw agents on a Linux host reachable over Tailscale
  • Seven scheduled jobs: Entra cleanup, PIM digest cleanup, backup reviews, backups and memory backfill
  • GPU-backed memory search and a vault-based portable skill framework
  • Local models with LM Studio, Ollama and CUDA builds of llama.cpp, plus ComfyUI workflows
  • This WordPress site, run in Docker and managed by AI agents with snapshot, change, verify and rollback on every write

Vendor assessment engine

A reusable engine I built with AI agents to answer vendor security questionnaires: the kind a bank sends as a supplier-controls assessment. Instead of re-answering hundreds of controls from scratch, it drafts answers from a stored knowledge base and cites the evidence behind each one.

  • Knowledge base: atomic facts about a client plus a crosswalk mapping any vendor question to the facts that answer it (300+ controls carried over from prior assessments)
  • Semantic matching: local sentence embeddings match a brand-new questionnaire to the known controls and draft an answer
  • Evidence retrieval: the client’s policies and provider attestations (SOC 2, ISO 27001) are indexed so every answer can quote its source
  • Review queue: anything unsupported or unknown is flagged for a person instead of guessed, and reviewer corrections flow back into the knowledge base
  • Multi-client: each client’s facts sit beside a shared crosswalk, so one engine serves many organizations
  • Outputs: a vendor-ready workbook and a PDF evidence pack for the audit trail

Built in R with local embeddings, so client data never leaves the machine. The rule that governs it: it never claims a control it cannot evidence.

Design rule for every agent I build: read-only by default, and nothing changes without a way to undo it.