Ngentix Enterprise

Let your clients run AI agents without handing over the keys.

Agents are about to act on your clients' ERPs, CRMs and finance systems. Ngentix Enterprise is the layer in between: every agent gets a name, a rule set, a budget, a human approval step for the risky things, and a tamper-evident record of everything it did — operated from one screen, by you, on behalf of the client.

"Who is accountable when an agent does something it shouldn't?"

Today that question has no good answer. An unidentified agent can call any tool on any connected system, and the log cannot even say which agent did it. No MSP can put their name on that.

The tools you already sell govern human technicians beautifully. None of them govern the client's AI agents — and that gap is the client's risk, and right now yours too.

Every action routes through one screen.

Named agents, rules, approvals, budgets and a record. Every action an agent takes resolves to one of three verdicts.

Verdict
Allowed Acts freely, on budget.
Held Paused for your approval, with the request, reason and cost.
Refused Not permitted, and the refusal is on the record too.

What the layer guarantees.

Identity An agent connects and shows up by name — with what it did, on which systems. Identity is derived by the engine, not self-reported, so "which agent did this" finally has an answer.
Rules Each connected system reads asks first, acts and notifies, or acts freely — with the tools it is allowed and the budget it has. Least-privilege by default, tuned per client, run by a normal operator rather than a security specialist.
Approval An action above the agent’s permission — HR data, a large write, a blown budget — lands in a waiting-for-you queue. Approve and run, or decline. This is what lets you say yes to agentic AI without handing a client's ERP to an unsupervised bot.
Budget Per-system spend caps that hold. The meter climbs as agents act; the moment it hits the cap the next action pauses instead of running. No surprise bills, no runaway loops.
Record Every ask, refusal and approval sits in a cryptographically chained audit the operator can verify — it proves whether anything was altered, and that everything since is clean. This is the artifact you hand the client as compliance evidence.

Nothing you already sell covers this.

RMM Ships AI, but embedded in its own tools. As of mid-2026 it does not govern the client's agents.
Gateways The nearest one points AI at the MSP's own tools — allowlists and log-shipping, with no approvals, no budgets and no evidence.
PAM Governs human technicians brilliantly, and was never built for an AI agent as the principal.

Ngentix Enterprise governs the client's agents in the channel's own language — just-in-time access, propose-and-wait, a ticket-anchored record. A familiar idiom, extended to a new kind of user.

Why an MSP buys it.

Revenue A governance service you bill per client, per month — on top of the systems you already manage for them.
Reach You already hold the client's systems and their trust. This is the next service, not a new sale to a new buyer.
Position Be the MSP in your market who can say yes, we govern your AI agents while competitors are still saying they do not touch it.
Fit Single-tenant, per client, operated from one screen. It matches how you already run managed services.