PatchMortem automates the diagnosis and the rollback across a mixed client book — and produces the compliance evidence your clients' audit teams ask for.
An MSP managing infrastructure for a dozen regulated clients absorbs every patch failure across every estate. The deployment tools are automated. The failure handling is not — it is senior engineers reading servicing logs at 2am, once per client, once per incident.
That work is where the margin goes, and it is the work that does not scale with headcount. PatchMortem automates the diagnosis and the rollback, and produces the compliance evidence your clients' audit teams ask for as a by-product.
The audit evidence is the part clients cannot get anywhere else. It converts a support obligation into something you can show an audit committee.
Tenant isolation is enforced at the database layer, not by a filter in the UI.
PostgreSQL row-level security enforces separation between client estates. Per-tenant key isolation means no shared credentials between customer environments — a misconfiguration cannot expose one client's data to another.
Each client estate gets its own HMAC-SHA256 chained audit trail, exportable independently. Your client's inspector verifies their chain without seeing anything belonging to another customer.
RBAC is enforced at the API level. Assign engineers to the clients they support, and keep the approval gate on any action that changes a host — per estate, per policy.
| Today | Failure alert → engineer logs in → reads servicing logs → searches vendor KB → decides rollback → executes → writes up the incident |
| With PatchMortem | Failure detected → classified against 215 patterns → risk tier and cluster role checked → rollback executed or frozen for approval → audit record written |
| Engineer involvement | Approval where policy requires it, and the cases the classifier flags as unsafe to automate |
| Client deliverable | Compliance export generated from the chain, not assembled by hand at quarter end |
MSP estates are rarely uniform. PatchMortem detects cluster topology before taking action, across the platforms a mixed book actually contains.
No rip-and-replace across a client book. PatchMortem connects to the tools each client already uses — Intune, SCCM/MECM, ManageEngine, NinjaOne, vSphere, Ansible, Puppet, Chef, with ServiceNow and Jira bidirectional sync.
MSPs managing multiple client estates are priced separately from single-enterprise plans, because the endpoint counts and the support model are different. Bring us your client book and estate sizes and we will scope it directly.
Standard plan detail is on the pricing page. On-premise deployment is available where a client's policy does not permit telemetry to leave their data centre.
Pick one client estate with a known failure history — typically 25 to 50 servers. Deploy the agent read-only. We triage every failure in their next patch window against their own servicing logs and hand you the root causes, with the rollback we would have run and why.
Compare it against the hours your team billed or absorbed on that window. That number is the whole business case.
30 minutes with an engineer. We will scope a pilot on one estate and price the rest honestly.