You absorb every patch failure, across every client.

PatchMortem automates the diagnosis and the rollback across a mixed client book — and produces the compliance evidence your clients' audit teams ask for.

Your margin is patch failure handling

An MSP managing infrastructure for a dozen regulated clients absorbs every patch failure across every estate. The deployment tools are automated. The failure handling is not — it is senior engineers reading servicing logs at 2am, once per client, once per incident.

That work is where the margin goes, and it is the work that does not scale with headcount. PatchMortem automates the diagnosis and the rollback, and produces the compliance evidence your clients' audit teams ask for as a by-product.

The audit evidence is the part clients cannot get anywhere else. It converts a support obligation into something you can show an audit committee.

Built for multi-tenant operations

One console, many estates

Tenant isolation is enforced at the database layer, not by a filter in the UI.

Hard tenant isolation

PostgreSQL row-level security enforces separation between client estates. Per-tenant key isolation means no shared credentials between customer environments — a misconfiguration cannot expose one client's data to another.

Row-level security · per-tenant keys

Per-client audit chains

Each client estate gets its own HMAC-SHA256 chained audit trail, exportable independently. Your client's inspector verifies their chain without seeing anything belonging to another customer.

Independent export per tenant

Role-based access across estates

RBAC is enforced at the API level. Assign engineers to the clients they support, and keep the approval gate on any action that changes a host — per estate, per policy.

SAML · OIDC · RBAC

What changes on an MSP shift

TodayFailure alert → engineer logs in → reads servicing logs → searches vendor KB → decides rollback → executes → writes up the incident
With PatchMortemFailure detected → classified against 215 patterns → risk tier and cluster role checked → rollback executed or frozen for approval → audit record written
Engineer involvementApproval where policy requires it, and the cases the classifier flags as unsafe to automate
Client deliverableCompliance export generated from the chain, not assembled by hand at quarter end

Cluster awareness across mixed estates

MSP estates are rarely uniform. PatchMortem detects cluster topology before taking action, across the platforms a mixed book actually contains.

  • Windows Failover Clustering — ACTIVE and PASSIVE roles identified before remediation
  • Pacemaker on Linux — cluster state validated before any package action
  • SQL Server Always On availability groups — replica health confirmed
  • Network Load Balancing — membership checked before a node leaves service

Integrations you already run

No rip-and-replace across a client book. PatchMortem connects to the tools each client already uses — Intune, SCCM/MECM, ManageEngine, NinjaOne, vSphere, Ansible, Puppet, Chef, with ServiceNow and Jira bidirectional sync.

Commercials

MSPs managing multiple client estates are priced separately from single-enterprise plans, because the endpoint counts and the support model are different. Bring us your client book and estate sizes and we will scope it directly.

Standard plan detail is on the pricing page. On-premise deployment is available where a client's policy does not permit telemetry to leave their data centre.

How to evaluate it

Pick one client estate with a known failure history — typically 25 to 50 servers. Deploy the agent read-only. We triage every failure in their next patch window against their own servicing logs and hand you the root causes, with the rollback we would have run and why.

Compare it against the hours your team billed or absorbed on that window. That number is the whole business case.

Bring us your client book

30 minutes with an engineer. We will scope a pilot on one estate and price the rest honestly.