Cloud Sentry
For MSPs

Keep the client. Add security and compliance.

Some of your clients are hitting SOC 2, HIPAA, or an enterprise security review, and the work sits outside what your team is staffed to carry. You do not have to lose the account to solve it.

The work that shows up uninvited

Most MSPs we talk to are good at what they were hired to do. The pressure comes from work their clients did not have two years ago.

A client landed an enterprise questionnaire

The questionnaire asks for a current pentest, a documented incident response process, and evidence of continuous monitoring. Answering it well is a program, not a ticket, and the deal is waiting on it.

A client committed to a framework

SOC 2, HIPAA, or HITRUST arrives with a scope, an auditor, and a calendar. Someone has to own control operation and evidence between now and the report, every month, not just at audit time.

Staffing a security and compliance practice to serve two or three clients rarely pays for itself. Handing the account to a competitor costs more.

Two ways to work together

Which one fits depends on the client, not on which is worth more to us. We will say which we think it is on the first call.

Co-managed

You hold the client. We run the layer underneath.

You keep the agreement, the helpdesk, and the relationship. We operate the security and compliance function beneath it as a named subcontractor: identity hardening, managed detection and response, control operation, and the evidence that proves it. Escalations route through you rather than around you, and your client knows exactly who is doing what, because the split is written down before anything starts.

  • Your agreement, your invoice, your account manager
  • A written scope split, drawn per client rather than per template
  • Named operators on our side, so your team knows who to call
See where the line sits

Referral

When the whole function needs one operator.

Sometimes the honest answer is that the client needs IT, security, and compliance run as a single function, and splitting it two ways would add a seam rather than remove one. Refer them to us and we will tell you plainly what we took on. We are not looking for your end-user support work, and if a referred client asks us for it, we will point them back to you.

  • Referral terms agreed in writing before an introduction is made
  • We tell you what we scoped, and what we declined
  • No approach to the rest of your client base
The operated partnership

Where the line sits

Co-managed arrangements fail at the seams, not in the middle.

This is the default split we start from. The real one is written down per client before any work begins, and it is the first thing we hand your account manager.

What you keep

Everything the client thinks of as their IT provider stays yours. We are not building a shadow relationship underneath you.

  • The agreement, the renewal, and the account conversation
  • End-user support and the service desk
  • Day-to-day identity, device, and tenant administration
  • First word to the client when something changes

What we run

The layer that needs analysts, a framework calendar, and someone awake for it. Staffed once by us, rather than twice by both of us.

  • Managed detection and response across endpoint, identity, cloud, and email
  • Control operation and the monthly framework work between audits
  • Audit evidence, with scoped, time-bound access for the client's auditor
  • Security review of the changes you make, on an agreed path

Security-relevant changes, Conditional Access among them, sit on the line rather than on one side of it. Those go through an agreed change path, so neither of us assumes the other watched it.

What we commit to

Bringing in a security partner means letting someone else near your client. These are the terms that make that a reasonable risk.

We do not go around you

In a co-managed engagement we do not solicit your clients for the work you already do. If one of them asks us to take it on, we tell you before we answer.

Scope is written before work starts

Including the work we do not take. We publish our refusals on the operated partnership page, and the same list applies when we are working underneath you.

The client owns their environment

Credentials, configuration, and documentation live in accounts the client owns. Nothing gets locked inside a system of ours, which means a co-managed engagement can end without a hostage negotiation.

Offboarding is included

Ours as well as theirs. What a clean exit looks like, in both directions, is written up on the switching page.

Partner commercial terms are agreed per engagement rather than published. This page describes how we work, not the terms of any particular arrangement, which are governed by the agreement you sign.

How it starts

01

One call about one client

Not a partner program pitch. Bring the client with the framework deadline or the questionnaire, and we will tell you whether co-managed or referral is the honest answer.

02

A written scope split

Who owns what, where escalation goes, and what we will not touch. Your account manager gets it in a form they can put in front of the client.

03

Run it on that client first

One engagement, operating for a full cycle, before anyone talks about the rest of your base. If the seams hold, we do it again.

Bring us one client.

Start with the account that has a deadline, or read how we operate before you introduce anyone.

One call about one client, and a straight answer on whether co-managed or referral is the better fit.

How we scope, what we make visible, and the engagements we refuse, laid out section by section.