By Connector
Browse the Magic Library grouped by the integration each agent or skill needs, from PSA and RMM to documentation, chat, and monitoring connectors.
Thread
1Password Business
Run 1Password Business admin work: vault and group structure, sharing discipline, the Emergency Kit, recovery groups, and suspend-then-recover offboarding.
Abnormal Security
Triage Abnormal Security email cases: read ATO and BEC behavioral signals, treat account takeover as an identity incident, finish auto-remediation gaps.
Access Request Handling
Work an access request for a folder, calendar, DL, or shared mailbox with approval checked, least privilege applied, and expiry on temporary grants.
Access Request Intent Design
Design an access-request intent for folders, distribution lists, and shared mailboxes — capture resource, justification, and approver on intake.
After-Hours Coverage Handoff
Build the end-of-business handoff to on-call or after-hours coverage — open urgent work, expected client callbacks, and site notes the night crew needs.
After-Hours Voicemail Digest
Build a morning digest of overnight voicemails and after-hours calls — urgent items first, callbacks owed with deadlines, and which tickets were created.
Aging, SLA & Follow-Up
Sweep open tickets for real staleness by last client-facing update, separate MSP stalls from legitimate waits, nudge techs, and drive clean closure.
Agreement Profitability
Compute the effective hourly rate on an all-you-can-eat fixed-fee agreement — agreement revenue divided by logged hours — or scan for loss-making clients.
Alert Storm Merge
Collapse a burst of identical alert tickets fired within a few hours into the earliest ticket as parent, so a flapping monitor does not flood the queue.
Alert Title Normalization
Classify a monitoring or security alert ticket and rewrite its title into the desk's standard format using a controlled vocabulary, with an internal note.
APC UPS Alerts
Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.
Apology With Remedy
Draft the message when the desk genuinely failed — specific acknowledgment, concrete remedy, and one prevention step, without groveling or overreach.
Approval Request Email
Draft an email to an approver requesting authorization for a password reset, install, purchase, or access change — what/why/risk/expiry in one read.
Approver Self-Skip
Before firing an approval, check if the ticket submitter is the client's designated approver — if so, skip send_approval and advance with an audit note.
Arctic Wolf MDR
Work Arctic Wolf MDR escalations: pick up where their SOC investigation ended and split response authority between Arctic Wolf and the MSP correctly.
Atera Workflow
Atera-synced desk playbook: ticket lifecycle, resolved-vs-closed nuance, contract types (retainer, block hours, monitoring, project), labor pricing.
Auto Priority Classification
Set a ticket's priority from its title and description against the partner's own priority definitions — built for alert boards and intake flows.
Automation Completion Auto-Close
When note evidence shows an intent or external automation finished the work, verify and auto-close the ticket — abort if any human message arrives after.
Automation Opportunity Finder
Mine recent tickets for repetitive manual work, estimate hours burned per pattern, and route each finding to a flow, intent, RMM policy, or training fix.
Automation ROI Report
Judge whether live automations earn their keep with tickets touched per flow, estimated time saved, noise created, and a keep, kill, or tune verdict each.
Autotask Contract Categories
Read Autotask contract type at triage (recurring, block, retainer, T&M, fixed) to label covered vs billable and add burn-down notes on hourly deals.
Autotask Contracts Blocks
Autotask contract mechanics: block-hour burn tracking, retainer-threshold alerts, and exclusions, overlapping contracts, and expired-contract edge cases.
Autotask Merge Simulation
Autotask has no merge API: dedupe tickets via a 5-step manual sequence — verify, pick survivor, cross-note, carry history, complete the source last.
Autotask Queue Management
Autotask queue model: queues are work pools, not workflow containers — route by moving tickets between queues with correct ownership semantics.
Autotask Service Call Scheduling
Autotask Service Calls: know when work is a scheduled visit object vs a plain ticket, and follow dispatch scheduling conventions so calendars stay right.
Autotask SLA Workflow
Autotask SLA event model — First Response, Resolution Plan, Resolved — with clock-pausing statuses and breach-risk assessment for synced desks.
Autotask Ticket Categories
Classify Autotask tickets with configured Issue Type + Sub-Issue Type pairs and ticket category/type — never invent classification values not in the board.
Auvik Network Monitoring
Triage Auvik network alerts: separate device-down, interface-down, and config-change events, and use the topology map to spot cascades early.
Bad Review Response Prep
After a poor CSAT score or negative review, prepare internal talking points plus an external response draft — facts only, zero defensiveness.
Billable Analysis
When someone asks how billable hours break down by technician, client, or period, or wants to see unbilled-work exposure from time entries.
Bitdefender GravityZone
Triage Bitdefender GravityZone alerts: identify the detection layer (AV, ATC, HyperDetect, EDR) and use Risk Analytics, quarantine, and rollback safely.
Bitwarden Business
Run Bitwarden Teams/Enterprise admin work: organization and collection structure, group-based sharing, account recovery, and offboarding vault handover.
Blackpoint SOC Response
Work Blackpoint MDR SOC calls: confirm what analysts contained (host isolation, account disable), finish the response, and merge companion ticket storms.
Board Routing Rules Engine
Route catch-all tickets to the right board (NOC, procurement, security, help desk) by walking a prioritized keyword-and-signal rule list to a result.
Breached Credential Response
Handle exposed user credentials: notify the user, drive password rotation across reused sites, and verify MFA is enabled before standing down.
Bulk Onboarding Coordinator
Coordinate a multi-hire onboarding wave with one parent ticket, child ticket per hire, and a consolidated status table kept current through cutover.
Bulk Ticket Operations
Safe procedure for bulk close, reassign, or update ticket operations: enumerate, eligibility check, chunked writes, audit notes, abort on anomaly.
Business Email Compromise Recovery
Recover from confirmed BEC: kill sessions and tokens, sweep mail rules and forwarding, notify downstream victims, and trace the fraudulent funds.
Business Value Summary
Summarize value delivered to a client this period in business terms — outcomes achieved, time saved, incidents prevented — as a client-facing story spine.
CAB Brief Builder
Build the weekly change advisory board pack: pending changes ranked by risk, collision flags, and last week's change outcomes for 20-minute CAB decisions.
Catchall Routing
Identify the correct client and contact for a ticket that landed in a catchall or no-company mailbox, including forwarded mail and vendor alert routing.
CEO Service Desk Brief
An owner or CEO asks for a review of the service desk — a business-level readout with trends, risks, and a decision to make, no ticket IDs.
Change Approval Sender
Flow that fires on Change Approval status: resolve the client's Change Approver and send_approval with the change summary — note-and-stop if unresolved.
Change Calendar Management
Check a proposed change window against freeze windows, client calendars, and other scheduled changes so collisions surface before the maintenance email.
Change Request Intake
Normalize a prose change request into a structured record (what, why, scope, when, rollback, risk) and route it to the right approval track before work.
Change Request Prerequisites
Validate a change request against the prerequisites template — justification, scope, rollback, window, approver — and bounce incomplete requests itemized.
Change Risk Assessment
Classify a change request as standard, normal, or emergency by scoring blast radius and rollback confidence so approval effort matches actual risk.
Chat-to-Ticket Conversion
Capture a live Messenger chat's context into a real ticket with title, description, contact, priority, and steps tried — no repeating for the user.
Churn Save Deep Dive
Analyze a client's churn intent using full ticket history to surface what went wrong, what worked, and honest talking points for win-back calls.
Client Health Report
Summarize a client's support health for a period — volume trend, recurring issues, noisy assets, SLA performance, and a few concrete recommendations.
Client RCA Summary
Draft a client-safe root-cause summary for a resolved issue — what happened, impact, cause, and prevention — written defensively for one ticket.
Client Reply
Draft an external client reply in your house voice and format — resolution updates, status notes, closing messages, or any client-facing email on a ticket.
Client Risk Scan
Scan the client portfolio for at-risk accounts using declining sentiment, aging tickets, recurring issues, and unresolved high-priority incidents; ranked.
Closure Note Completeness
Check a ticket's closure note against the house standard — issue, cause, actions, outcome, confirmation — and draft the compliant version when it's short.
Closure Recategorization
At resolution, re-read the thread and correct the ticket's type/subtype/item and category to match the actual work, using only configured board values.
Co-Managed Reference Exchange
Keep ticket references straight across a co-managed IT boundary — recognize the other side's number format, preserve foreign refs, and audit both-way links.
Compromised Account Containment
Rapid containment checklist for a compromised account: block sign-in, revoke sessions, reset password, sweep MFA and inbox rules, timestamp steps.
Conditional Access Exception
Exclude a user, app, or location from a conditional access policy with written risk note, approval, expiry date, and revert plan documented up front.
Connector Degradation
Base skill defining how a skill behaves when an integration it wants isn't connected — do the job with what's native, name the gap, never fake the missing source.
Contract Renewal Routing
Catch renewal and expiry notices in the service queue and route them to the right sales or account manager, retitled and moved with context attached.
COO Ops Review
An ops leader asks what the team is doing well and not so well — an honest, evidence-backed operations review of the service desk.
Cork Protection Posture
Handle Cork cyber-warranty posture signals: identify the required control that slipped and restore it to compliance before warranty coverage lapses.
Courtesy Reply Status Revert
When a thanks-only client reply flips a resolved ticket back to open, revert it to the correct status per a fixed per-board map — the only permitted write.
Cove Data Protection Alerts
Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.
Credential Stuffing Response
Investigate password spraying and credential stuffing patterns: scope the attack across tenants, lock down accounts, and rotate the ones that fell.
Cross-Client Outage Detector
Spot the same symptom appearing across multiple clients within a short window, flag a possible vendor or major incident, and propose a parent incident ticket.
CrowdStrike Falcon Alerts
Triage CrowdStrike Falcon detections: parse detection anatomy, decide when Network Contain is warranted, and spot mass endpoint failures as vendor-side.
CSAT Trends Report
Track CSAT scores over time by client, technician, or ticket category with honest treatment of response rates so a 3-response month isn't shown as 300.
CSM Weekly Ritual
A CSM or vCIO weekly account runbook: proactive outreach, sentiment-decline watch, meeting prep for the week's calls, and an expansion-scan skim.
Custom Time Entry Writer
Summarize thread activity within the active timer window using a recap template, preview the draft, then log the time entry on confirm.
CW Agreement-Aware Triage
ConnectWise Manage triage: read the client's CW agreement type at intake and route or label the work as covered vs billable before anyone touches it.
CW Project Tickets
Recognize ConnectWise Manage project tickets, understand the project → phase → ticket structure, and work within what Thread sees of the Projects module.
CW Service Board Conventions
ConnectWise Manage multi-board desks: pick which board work belongs on and execute cross-board moves without losing status, classification, or history.
CW Status Workflow Mapping
ConnectWise Manage status mapping: align Thread statuses with CW board statuses, take safe transitions, reconcile closed-in-CW-but-open-in-Thread drift.
CW Sync Lag Audit
Sweep Thread ↔ ConnectWise Manage divergence — status, owner, board mismatches — separate real drift from sync lag, and reconcile with CW as the master.
CW Time Entry Conventions
ConnectWise Manage time entries that survive sync: correct work role/type, deliberate billable flag, agreement application, and plain-text notes.
CW Type / Subtype / Item Classification
Classify ConnectWise Manage tickets with the three-level Type → Subtype → Item taxonomy using only values configured on the board — never invented ones.
Dagelijkse samenvatting (Dutch)
Dagelijkse samenvatting van openstaande tickets van een technicus: wat wacht op antwoord, wat is urgent, wat staat vandaag gepland, met 3-regelvariant.
Daglig oversikt (Norwegian)
Daglig oversikt over en teknikers åpne saker: hva som trenger svar, hva som haster, hva som er planlagt i dag, med ultrakort 3-linjers variant.
Daily Digest
Summarize a technician's open tickets in under a minute with what needs a reply, what's urgent, what's scheduled today, plus a 3-line ultra-short option.
Daily Leadership Digest
A service leader asks what needs their attention today — escalations, SLA breaches, at-risk clients, and staffing flags in one short daily view.
Dark Web Alert Lifecycle
Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.
Day Planner
Plan a technician's day around calendar and queue, honoring shift end and timezone, producing a realistic time-blocked plan and not just priorities.
De-escalation Reply
Draft the response to an angry client message — acknowledge, own what's ours, commit to a concrete next step with a time, without matching their tone.
Dead-Air Call Filter
Detect and close voice sessions that were dead air, instant hangups, or robocalls so they don't pollute the queue — human speech means it isn't dead air.
Deep Recap
Build a full ticket recap covering messages, notes, time entries, related sibling tickets, timeline, and current blockers — beyond the default summary.
Default Contact Autofill
When a ticket arrives with no contact, look up the company's documented default contact, confirm with a search, and assign under a confidence gate.
Defender M365 Alerts
Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.
Defender Quarantine Ops
Review Microsoft 365 Defender quarantine items and release requests using Defender portal paths, verdict types, and disciplined release mechanics.
Defensive Writing Standard
Language standard for security writing: use when drafting client notifications, incident updates, postmortems, and alert closures to avoid overstatement.
Delay Apology
Draft an honest acknowledgment that a ticket has taken too long or a commitment slipped — apology without excuses, new commitment only if confirmed.
Delegate Access Forensics
Investigate mailbox audit logs to identify Send As, Send on Behalf, and owner actions in delegation disputes and unauthorized-email claims.
Difficult News Delivery
Draft the message no one wants to send — data loss, unrecoverable state, security exposure — factual, empathetic, and pointed at the path forward.
Dispatch & Workload
Give a dispatcher the full queue picture: unassigned tickets by priority and age, open work per tech, lightest-load proposals, and a daily audit.
Dispatch Control Tower
The dispatcher's live picture in one view — unassigned queue, at-risk tickets, today's scheduled work, and which technicians are free to pick up right now.
Dispatcher Morning Ritual
A dispatcher's board-open runbook: morning dispatch report, clear unassigned via workload balancing, SLA-risk check, and yesterday's assignment audit.
Distribution List Management
Add or remove distribution list members with owner approval and a documented reason logged on the ticket, keeping email groups clean and auditable.
DLP Alert Triage
Triage a DLP alert: separate business-process false positives from real data exfiltration signals, investigating with respect for employee privacy.
DNS Filtering Alerts
Handle DNS-filter block events from Cisco Umbrella, DNSFilter, and similar tools: separate security blocks from category blocks, keep bypass discipline.
Duo MFA Anomalies
Work Duo MFA events: fraudulent pushes, push-fatigue patterns, device re-enrollment, bypass codes. Verify identity and time-box every bypass grant.
Duplicate Hunter
Check whether a ticket duplicates an existing open ticket for the same client, contact or asset, and symptom — and merge only on an exact reference match.
Easy Win Finder
Surface quick-win ticket candidates from the queue that match the requesting technician's skills, with a short reason each one is fast to close.
Email Baseline Standard
The base client-email standard other communication skills build on — structure, tone rules, and placeholder discipline for every outbound message.
Email Header Analysis
Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.
Emergency Change Handling
Run break-glass discipline for an emergency change: minimal in-flight record, act-then-document, then chase full retro documentation to done in 24 hours.
Employee Offboarding
Securely disable a departing employee in the right order: sign-in and sessions first, mailbox before licenses, then reclaim access, assets, and MFA.
End-of-Day Wrap-Up
End-of-day sweep for a technician: stale tickets over 24h, awaiting-client with no follow-up, status mismatches, and tomorrow's first moves lined up.
EOD Closed Ticket Audit
End-of-day quality sweep of every ticket closed today against the closure rubric: resolution, docs, classification, time, message, with pass/fail summary.
Escalation Advisor
Sweep active tickets against L2/L3, management, and project-conversion trigger lists and recommend which should escalate — before they age into problems.
Escalation Completeness Gate
Review tickets entering Escalation Requested status against the escalation checklist and bounce incomplete ones back to the tech with itemized feedback.
Escalation Prep
Build a complete escalation package so a senior engineer, TAM, or third party can pick the ticket up cold, or recommend whether a ticket should escalate at all.
Escalation Risk Radar
Scan open tickets for the early signs of a blow-up — negative sentiment, an SLA deadline closing in, and threads that have gone quiet — score and rank them, so a senior tech can step in before a client escalates.
ESET PROTECT
Triage ESET PROTECT detections by engine, interpret LiveGuard sandbox verdicts, and recognize when a protection-disabled alert is really a policy conflict.
ESL Drafting Assistant
Grammar and idiom cleanup for technicians writing in non-native English — "fix my English" or "mejorar ingles," technical content untouched.
Exec Weekly Ritual
An owner or exec's 20-minute weekly runbook: exec scorecard, resolve one decision ask, and review what has been escalated to me across the service desk.
Expansion Opportunity Scan
Mine a client's ticket history for expansion signals — recurring issues that justify a project or upsell, and training gaps that justify a service offering.
Expectation-Setting Acknowledgment
Draft the first-touch acknowledgment on a new ticket — what we understood, how seriously we're treating it, next steps, and when the client hears back.
Field Visit Scheduler
Schedule an onsite visit and make the trip count: sweep other open onsite-worthy tickets at the same site, group travel, book, confirm the client.
First Contact Resolution Report
Report the desk's FCR rate, the share of tickets resolved by first assignee with no handoffs, with the definition stated to prevent later disputes.
Flow Backup Export
Dump every flow definition to a JSON or markdown snapshot for archive and diffing — a read-only point-in-time backup of the desk's automation, no restore.
Flow Builder
Design an automation flow from a plain-English ask — trigger, filters, actions, notification channels — with a dry-run description before it is created.
Flow Bulk Editor
List the desk's flows, present the target set, then bulk enable, disable, or rename them in one confirmed pass — no editing each flow by hand.
Flow Debugger
Diagnose why a flow or intent didn't fire on a ticket — filters vs actual attributes, flow ordering, board scoping, and trigger-event mismatch.
Flow Note Personalizer
Replace a Flow's static "add note" text with an AI step that resolves the real owner and ticket context to compose a note with actual names and specifics.
Follow-up Chaser
Draft a polite, escalating follow-up when a client hasn't replied on a ticket — first nudge, second nudge, or final pre-closure attempt with tone.
Group Membership Request
Handle a security group membership change by stating what the group actually grants, getting the right approver, and setting a review date on the change.
Halo Actions & Workflows
HaloPSA actions and workflows beyond status changes: approval actions, multi-step workflows, and which action is valid at the ticket's current step.
Halo Agent Teams
HaloPSA team and section routing: team selects the pool, agent selects the person, and unassigned-within-team is a legitimate state — not an error.
Halo Recurring Tickets
HaloPSA recurring tickets and parent/child structures: work the generated instance, never the template, and respect parent/child closure rules on sync.
Halo SLA and Priorities
HaloPSA SLA and priority interplay: priority sets response and fix targets within the client's SLA, and configured hold statuses pause the clock.
Halo Status Actions
HaloPSA transitions run through configured Actions, not raw status edits — pick the action that fires the right status, note visibility, and notifications.
Halo Sync Audit
Sweep Thread ↔ HaloPSA divergence — especially the known pattern of statuses not carrying over — and reconcile toward Halo as the master system.
Health Score Reconciliation
Reconcile a client's own health or satisfaction scores against our ticket reality — where their perception and our data agree, and where they diverge and why.
How-Do-I Self-Help Router Intent Design
Design the catch-all "how do I" self-help router intent: classify the how-to, serve the matching end-user guide or KB article, escalate only if no match.
Huntress ITDR Alerts
Work Huntress ITDR identity reports: unwanted access, rogue apps, mail-rule anomalies. Verify with the user and drive the remediation-approval flow closed.
Inbox Rule Alert Runbook
An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.
Incident Commander Brief
Assemble a handoff brief for an incoming incident commander: timeline, workstream states, comms state, and the next decision point in a single read.
Incident Comms Cadence
Draft internal and client updates on a fixed clock during a major incident from ticket evidence, tracking the next-due time so the cadence never lapses.
Intake Classification Tree
Walk a new ticket through the Incident, Request, or Problem decision tree and recommend a matching type, subtype, and item for consistent classification.
Intent Builder
Build or update a customer-facing intent — trigger phrases, arguments, replies, and per-client variations — with a test plan before anything goes live.
Intent Bulk Variation Update
Apply a shared argument or reply block across every client variation of an intent at once, with per-variation diff preview and explicit write confirmation.
Intent Mining
Analyze recent tickets to find top customer-facing intents worth building, ranked by volume and automatability, with draft trigger phrases for each pick.
Intent Setup Walkthrough
Walk through building a new Triage Agent intent from scratch — check it doesn't already exist, then set the name, description, trigger variations, replies, and any arguments — so a new automatic response is set up cleanly and without duplicates.
Invoice Dispute Investigation
When a client disputes an invoice line, reconstruct the work evidence from tickets and time entries, then draft a factual response backed by the record.
IRONSCALES Phishing
Work IRONSCALES phishing incidents and user banner reports: mailbox-level detection, automated remediation, and correct model-training feedback.
JSON API Response Pattern
Base skill for machine integrations: when an external system calls Super Magic and parses the reply, respond with only a raw JSON object matching schema.
Kaseya BMS Workflow
Kaseya BMS-synced desks: navigate the status/queue/location model, respect the service-desk vs projects split, and audit Thread ↔ BMS drift regularly.
Kaseya Dark Web Monitoring
Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.
Keeper Password Manager
Run Keeper Security admin work: vault and shared-folder structure, role-enforced sharing, break-glass access, and offboarding via Account Transfer.
Klantantwoord (Dutch)
Extern klantantwoord opstellen in de huisstijl: oplossingsupdates, statusberichten, afsluitende berichten of elke klantgerichte e-mail op een ticket.
KnowBe4 Awareness & PhishER
Run a KnowBe4 program: awareness training, phishing simulations, and triage user reports through PhishER and the Phish Alert Button without collisions.
Known Error Database
Maintain the KEDB with every known error in one findable symptom, cause, and workaround format — deduplicated on arrival and retired when the fix ships.
Kundenantwort (German)
Kundengerichtete Ticket-Antwort in der Hausstimme entwerfen: Statusupdates, Zwischenstand, Abschlussnachricht oder jede E-Mail an den Kunden.
Kundesvar (Norwegian)
Utkast til eksternt kundesvar i husets stemme og format: løsningsoppdateringer, statusmeldinger, avslutninger eller enhver kunderettet e-post på en sak.
Laptop Return Logistics
Get a company laptop back from a departing or remote user with prepaid return label, templated email, deadline tracking, wipe verification, and escalation.
LastPass Migration
Run a LastPass migration-away: export, import to a new vault, rotate every secret, decommission the account, and handle the breach-history talk with facts.
Lead Daily Ritual
A service manager's daily runbook: leadership digest, escalation queue pass, silent-ticket sweep, and one coaching observation captured for the team.
License Cost Optimization
When someone wants to find unused, duplicate, or oversized licenses for a client and get downgrade/reclaim recommendations with a savings estimate.
License Lifecycle
Assign or reclaim software licenses by checking for unused seats before buying and leaving a billing note on every change so client spend stays accurate.
Litigation Hold
Place or manage a legal hold on a user mailbox and data with scope confirmed by an authorized requester and no user notification unless counsel approves.
Live Call Transfer Brief
One-minute brief for transferring a live in-progress call to another technician — caller context, what's been tried, sentiment alert, and a verbal opener.
Live Chat Etiquette
House rules for working a live Messenger chat — response cadence, holding messages, handoff phrasing, and ending the chat cleanly for the desk playbook.
Lost or Stolen Device Response
Respond to a lost or stolen laptop or phone: decide lock or wipe, assess exposed data and access, and drive carrier or police steps with approval gates.
M365 SaaS Backup
Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.
Mail Flow Reports
Produce periodic Exchange Online mail flow health summaries: volume trends, spam/malware catch rates, top senders, connector health, forwarding.
Mail Forwarding Audit
Inventory every mail forwarding path in a tenant or mailbox: mailbox forwarding, inbox rules, and transport rules, treating external forwarding as risk.
Mail Trace Investigation
Run disciplined Exchange Online message traces with tight timeframes, sender/recipient pairs, verdict reading, and historical traces beyond 10 days.
Mailbox Permissions Audit
Inventory Exchange mailbox access grants: Full Access, Send As, Send on Behalf, and folder-level permissions, flagging unexpected delegations.
Maintenance Freeze Windows
Record and enforce client freeze calendars (tax season, go-lives, retail peak) so freezes block change scheduling unless a documented exception is signed.
Maintenance Window Notice
Draft a planned-work client notice — what's happening, when, expected impact, duration, and rollback promise — for patching, upgrades, or migrations.
Major Incident Declaration
Run the criteria check, declare or explicitly decline a major incident, assign incident roles, and start the comms clock from one declaration checklist.
Management Escalation Brief
When a client requests escalation to management, prep the leader taking the call with a timeline, an honest account of our misses, and a recovery plan.
Meeting Prep Brief
Rapid pre-meeting brief on a client — open items, recent wins and misses, sentiment, likely topics, and landmines — for meetings starting in 30 minutes.
Merge Duplicate Tickets
Find duplicate tickets — a client who wrote in twice, a re-forwarded alert, the same issue split across threads — confirm they're really the same, and merge them into one so the desk works a single thread.
Messenger Deployment Audit
Report which clients use Messenger versus which are entitled — deployed and active vs. silent — surfacing adoption gaps worth a rollout conversation.
Messenger Outage Banner
Draft, update, and retire the Messenger client-facing incident banner with factual wording, no cause speculation, and hard expiry for stale text.
MFA Fatigue Attack Response
Respond to MFA push bombing and fatigue attacks: treat the password as known, contain the account, and enforce number-matching so approval spam fails.
Mimecast Email Gateway
Work Mimecast gateway events: held-message release requests, URL Protect click alerts, and impersonation-protect hits. Treat allowed clicks as incidents.
Monitoring Companion Merge
Merge companion tickets that multiple monitoring tools opened for the same event on one device, folding them into a single parent within a time buffer.
Morning Briefing
A start-of-day briefing across your tiered support boards — every open human ticket grouped and flagged (unassigned, aging, SLA risk), with the alert/automation noise filtered out, a quick-stats table per board, and the day's key follow-up actions, all in one scannable report.
Morning Dispatch Report
The dispatcher's start-of-day briefing: overnight arrivals, P1/P2 status, unassigned aging, today's scheduled work, and a top-10 priority work list.
Morning Huddle Builder
Build the daily standup or morning huddle message — yesterday's P1s, overnight items, today's SLA risks, and shout-outs — ready to read out or paste.
MSA Change Management
Work through what an MSA change in tier, scope, seats, or sites means operationally: desk updates, notifications, and how effective dating is handled.
Multi-Issue Ticket Splitter
Detect when one ticket bundles two or more distinct problems and split it into cross-linked sibling tickets, one purpose each, with tech confirmation.
Multilingual Reply
Draft the client reply in the client's own language — detect it from their messages, write natively, and provide an English back-translation to verify.
My Queue Summary
Summarize a technician's assigned tickets showing what needs replies, what is urgent, and what to work next, with a clear next step attached to each item.
New Client 30-Day Review
Friction check on a new client's first 30 days — early recurring issues, expectation mismatches, and onboarding gaps — fixed while the relationship forms.
New Hire Intent Design
Design the new-hire onboarding intake intent: collect the full checklist up front so the ticket arrives complete and routes into the onboarding workflow.
New Hire Onboarding
Run a new-hire onboarding end to end with role-based accounts, licenses, groups, hardware, and MFA driven from the client's own onboarding checklist.
New Ticket Approval Gate
Configured clients require the designated approver to authorize work on every new ticket — fire send_approval on intake, hold, and record the outcome.
New Ticket First Touch
One-pass first touch on a new ticket: classify it, check duplicates, pull similar resolved tickets, and draft an acknowledgment for the tech to review.
New User Created Alert
Investigate an unexpected user or admin account creation in a client tenant: check for an authorizing ticket and contain if no one can claim it.
No-Response Closure Sequence
Close a ticket after a client goes silent following three documented contact attempts: send the templated final message, close with a reopen-invite note.
Noise Auto-Close
Close pure-noise tickets — bounce-backs, vendor auto-replies, thanks-only messages, reconnected offline alerts — behind independent stop conditions.
Note Format Standard
Base skill defining the house format, tone, and plain-text PSA-sync rules for internal ticket notes. Other documentation skills reference this standard.
OAuth Consent Grant Abuse
Remove a malicious or over-privileged OAuth consent grant from a client tenant: identify the grant, revoke it, and tighten tenant consent policy.
Offboarding Completeness Audit
Post-offboarding sweep for licenses still assigned, live delegations, unreturned devices, lingering MFA methods and sessions, and external share links.
Offboarding Intent Design
Design the employee-termination intake intent with an authorized-requester check and urgency handling built in from the start for offboarding tickets.
Onboarding Plan Builder
Draft a new tech's onboarding curriculum from the desk's own resolved tickets — the request types they'll actually face, in real volume order, with practice tickets per phase.
One-on-One Prep
A manager is preparing for a 1:1, 30-day check-in, or coaching conversation with a technician and wants a candid brief on their recent work.
One-Shot Ticket Workup
Get fully caught up on an in-flight ticket with a recap, suggested next step, drafted reply, and drafted time entry, previewed before anything is posted.
Out-of-Office on Behalf
Set automatic replies on an absent user's mailbox by request: manager or HR authorization verified, message kept minimal, and an end date set.
Out-of-Scope Billing Flag
Flag a ticket that looks like work outside the client's agreement — projects, installs, non-covered users — with a quote path, not silent free work.
Outage Notification
Draft a major-incident or mass-outage client notice — known impact, what we're doing, when the next update comes — without speculating on cause.
Password & MFA Recovery
Reset a password or recover MFA with an identity verification ladder, locked-versus-disabled account check, and secure delivery of the new credential.
Password Reset Intent Design
Design the password-reset intent — the top deflection target on most desks — with an SSPR-first reply path and a strict identity-verification handoff.
Phishing Simulation Program
Plan a client phishing-awareness simulation: scope, cadence, lure difficulty, a no-shame reporting culture, and desk triage that doesn't collide.
Phishing Triage
Triage a reported phishing email without touching the payload: check blast radius, contain if malicious, and reply to the reporter with a verdict.
Phishing-Triage (German)
Phishing-Triage einer verdächtigen E-Mail: Bewertung ohne Nutzlast, Streuradius prüfen, bei Böserkennung eindämmen, Melder mit Urteil antworten.
Phishing-triage (Norwegian)
Phishing-triage av en mistenkelig e-post: vurder uten å røre nyttelasten, sjekk spredningsradius, inneslutt hvis skadelig, svar melderen med konklusjon.
Phishingtriage (Dutch)
Phishingtriage van een verdachte e-mail: beoordelen zonder payload aan te raken, verspreiding controleren, isoleren bij kwaadaardigheid, oordeel geven.
Pod-Based Dispatch
Route a ticket to the least-loaded technician in the client's assigned service pod: read the pod from company record, load-balance, assign, and note it.
Post-Churn Autopsy
After a client terminates, reconstruct causes from ticket evidence, extract lessons, and identify early-warning signals so the next churn is caught early.
Post-Incident Action Tracking
Turn post-incident review action items into real tickets with owners and due dates, then run the follow-through audit that catches ones dying in backlog.
Post-Mortem & RCA Author
Write a structured post-mortem or root-cause analysis from an incident ticket — executive summary, event timeline, impact, root cause, and action items.
Premature Confirmation Detector
Catch tickets closed on assumption without customer confirmation — work summaries treated as sign-off, closes minutes after last change — then reopen.
Price Increase Letter
Draft the client notice for an agreement price change — value-first framing, effective date, honest rationale — gated behind account-manager approval.
Printer Issues Intent Design
Design the printer-problems intent: three top self-help fixes first, then an escalated ticket that already carries the diagnostics collected from the user.
Priority Downgrade Guard
On a priority change, if AI triage lowered a priority a human or client explicitly set higher, restore the higher priority — deterministic, restore only.
Problem Record Lifecycle
Drive a problem record through its states — opened from an incident cluster, investigating, known error, then fixed or accepted-risk closure.
Problem Ticket Creation
When an incident recurs past threshold, create a problem/RCA ticket linking the incidents and documenting the workaround so the pattern gets a real owner.
Procurement Quote Request
When a ticket needs hardware or software purchased and you want a structured quote-request note (specs, quantity, budget, needed-by) plus a vendor email draft.
Project Conversion Inbox Cleanup
When a ticket is converted to a project or moved to a project board, set the attribute that removes it from live inbox and queue views so dispatch is tidy.
Project Profitability
Check whether a fixed-fee project is on budget — logged hours versus budgeted hours, burn alerts at 70% and 90%, and documented evidence of scope creep.
Proofpoint Email Security
Work Proofpoint email security events: TAP click alerts, attachment-sandbox verdicts, quarantine-digest release requests, and VAP-driven priority triage.
PSA Billing Cycle Prep
Month-end PSA billing readiness sweep: find unposted time, done-but-open tickets, and agreement anomalies before finance runs invoices — clean handoff.
PSA Closed Status Taxonomy
PSA closed-status taxonomy (ConnectWise, Autotask, HaloPSA): find every closed-family status leaking into open searches and maintain the exclusion list.
PSA Field Mapping Doc
Build and maintain a Thread ↔ PSA field-mapping cheat sheet — statuses, boards, priorities, classification values — from observed tickets, not assumptions.
PSA Migration Hygiene
PSA migrations (ConnectWise, Autotask, HaloPSA): enforce dual-running discipline — one master per phase, no orphaned tickets, clean cutover evidence.
PSA New Board Setup
New PSA board or queue setup checklist: statuses, ticket types, SLA mapping, and Thread View plus Flow implications so it syncs cleanly from day one.
PSA Note Discipline
Base skill defining how a note or reply is written when it may sync to a PSA — plain text, internal vs client-visible, and what never goes in a permanent record.
PSA Note Visibility Rules
PSA internal-vs-external note semantics (ConnectWise, Autotask, HaloPSA) with a leak-prevention checklist — a wrong-visibility note goes to the client.
PSA Taxonomy Cleanup
Rationalize PSA ticket type/subtype/category sprawl: census real usage from tickets, propose merges and retirements, enforce migration discipline first.
PSA-Is-Master Reconciliation
Generic Thread ↔ PSA reconciliation pattern (ConnectWise, Autotask, HaloPSA): rule out sync lag first, then move Thread to match PSA, never the reverse.
Quarantine Release Request
Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.
Queue Hygiene Score
Scan a queue for hygiene defects — missing contacts, stale statuses, empty notes, unassigned owners, blank classifications — with score and fix list.
Queue Scoring Triage
Produce a ranked triage order for the queue using two-layer scoring — a per-queue baseline plus per-ticket modifiers — so techs work the right ticket next.
Quote Preparation
Prepare a client quote with structured options like 1-year vs 3-year or good, better, best tiers, plus explicit assumptions ready for the sales owner.
RE/FW Reopen Detection
When a new ticket subject starts with RE: or FW: on a recently closed subject, find the closed parent and flag it as a reopen instead of working new.
Reassign Contact Submitted On Behalf Of
Catch tickets one person opened for a colleague ("submitting this on behalf of Jane") and move the ticket's contact to the person the request is actually for — so it's attributed, notified, and reported against the right end user.
Recurring Issue Report
Someone asks which issues keep coming back — chronic problems hitting the same client or device repeatedly — and whether each has a root-cause fix underway.
Rehire Reactivation
Safely restore a disabled account for a returning employee with authorization verified, old group memberships reviewed, and credentials reset fresh.
Renewal Prep
Build a pre-renewal readout for a client — service record over the term, open risks, the value story, and prep for the pricing conversation.
Reopen Forensics
Analyze why tickets reopen: patterns by technician, client, and issue type over a window, distinguishing premature closure, recurrence, and client reopens.
Resolution Closing Email
Draft the closure email for a resolved ticket — what was wrong, what we did, how to reopen — built from the ticket's actual evidence, not memory.
Respuesta al cliente (Spanish)
Redactar una respuesta externa al cliente con voz y formato de la casa: actualizaciones, notas de estado, cierre o cualquier correo del ticket.
Resumen diario (Spanish)
Resumen diario de los tickets abiertos de un técnico: qué espera respuesta, qué es urgente, qué está agendado hoy, con variante ultracorta.
RFO Letter
Draft the reason-for-outage letter a client receives after a major incident (facts, impact, remediation, prevention) written defensively for legal review.
Round-Robin Assignment
Distribute incoming tickets fairly across a named technician roster in rotation, honoring exclusion rules — runnable unattended inside a Flow.
Réponse client (French)
Rédiger une réponse client dans la voix maison: point d'avancement, note de statut, message de clôture ou tout e-mail client sur un ticket.
SaaS Alerts MDR
Triage SaaS Alerts events in M365 and Google tenants: login anomalies, mail-rule creation, file-activity spikes, privilege changes as identity-plane EDR.
Scope Pushback
Draft the reply when a client requests something outside their agreement — a helpful no showing the path to yes (quote or agreement change) with AM loop.
ScreenConnect Access
Troubleshoot ScreenConnect / ConnectWise Control access: unattended-agent health, session connectivity, and console handoff for the technician on duty.
Screenshot OCR Translate
Extract the text from a pasted screenshot — an error dialog, email, or app screen — translate it to English if needed, and summarize what it actually says.
Security Incident Postmortem
Build a security incident postmortem: executive summary, timeline, impact, root cause, and action items drawn from ticket evidence in defensible language.
Security Noise Tuning
Reduce recurring false-positive security alerts: quantify the FP rate, build an evidence pack, and recommend a retune at the source tool.
Security Vendor Generic
Handle security alerts from any vendor without a dedicated runbook: extract alert anatomy, map severity to desk tiers, build a vendor escalation package.
Sentiment Closure Report
Bucket closed tickets by sentiment score per client, tech, or period, with driver messages cited so a low score is explainable, not just a number.
Sentiment Decline Watch
Find clients whose sentiment is trending down, show the evidence and the specific conversations driving it, and draft suggested outreach for each.
Sentiment Score Explainer
Explain why a ticket thread received its sentiment score by citing the exact messages that drove it — no hand-waving, no re-scoring.
Session Token Theft Response
Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user's password.
Shared Mailbox Delegation
Set up or change shared mailbox access (Full Access, Send As, Send on Behalf) with owner approval and an audit note recorded on the delegation ticket.
Shift Handoff
Produce a skimmable end-of-shift or end-of-day one-pager of open work, grouped by status, for the next shift or a single named receiving technician.
Silent Ticket Detector
Find tickets where the client replied but no technician responded within threshold — surface each with wait time, @mention the tech, and draft a reply.
Single Ticket Handoff Card
Hand one ticket to another technician with a compact card — status table, watch points, overdue-task detection, and a one-sentence next action.
Site-Aware Approval Routing
Resolve a ticket's site, look up the per-site approver from a documented mapping, and send the approval request to that contact — not one hardcoded name.
Skill Authoring Coach
Help a member write a good Super Magic skill: sharpen the description into a real trigger, structure the workflow, and add the guardrails it needs.
Skill-Based Routing
Route a ticket to the technician with demonstrated expertise — who resolved similar issues for this client or this stack — not just whoever is free.
SLA Analytics
Someone asks how the desk is doing against SLA — first-response and resolution performance versus targets, and which tickets breached and why.
Smart Dispatch
Composite dispatcher skill: classify a new ticket, consult a routing matrix of tech specialties and client familiarity, then assign and schedule.
SOC Classification Tree
Classify a security ticket down the Incident, Request, and Problem tree and set type, subtype, and item consistently for reporting and routing.
SOC Client Email Pack
Pick the right client-outreach template for a security event (leaked credentials, BEC, inbox rule, lookalike domain) and draft with verified facts only.
SOC Shift Handoff
Hand off open security investigations at shift change: evidence state, containment progress, and watch items so the next shift can act immediately.
SOW Drafting
Draft a brief scope-of-work from ticket or project context with deliverables, assumptions, exclusions, and a T&M vs fixed pricing recommendation attached.
Spam Sender Triage
Close tickets from known-spam senders and patterns after verifying a human did not forward the message in for investigation or phishing analysis.
Staffing Model Analysis
Someone asks whether the desk is staffed right — ticket arrival patterns by hour and day versus coverage, and where the desk is under- or over-staffed.
Stakeholder Map
Map who matters at a client — contacts organized by role and influence as evidenced in ticket interactions — and where our relationship coverage has gaps.
Stale Ticket Follow-Up Cadence
Drive a configurable 24/48/72 follow-up cadence on tickets awaiting client reply: draft each friendly nudge, count attempts, skip legitimate waits.
Status Check Intent Design
Design the "any update on my ticket?" intent: answer from real ticket status and last client-visible update, escalating only when the trail has gone cold.
Status Nudger
Chase tickets stuck in a waiting status — re-send the pending approval or post the templated client nudge, never nudging twice inside one window.
Status Update Messenger
One command sets the ticket status and posts the matching templated client message from a per-status map, so status and note change together.
Super Magic Enablement
Prep a show-and-tell of the highest-value Super Magic use cases for a specific team, grounded in their own recent tickets so every example is recognizable.
Sweep Honesty
Base skill defining how a skill reports on a search or bulk sweep — result caps, what it could not see, and never presenting a partial pass as a complete one.
Syncro Workflow
Syncro PSA-RMM idioms: tenant-configured ticket statuses, worksheets as embedded checklists, ever-running timer culture, and RMM alerts inside the desk.
Synology NAS Alerts
Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.
Synthèse quotidienne (French)
Synthèse quotidienne des tickets ouverts d'un technicien: qui attend réponse, ce qui est urgent, ce qui est planifié aujourd'hui, variante 3 lignes.
Tagesübersicht (German)
Tagesübersicht offener Tickets eines Technikers: was auf Antwort wartet, was dringend ist, was heute geplant ist — inklusive 3-Zeilen-Variante.
TeamViewer Access
Troubleshoot TeamViewer remote access: host and agent health, unattended access, session connectivity, and the commercial-use-detected flag on handoff.
Tech End-of-Day Ritual
A technician's close-of-day runbook: EOD wrap-up, time-entry compliance self-check, and lining up tomorrow's first move before logging off for the day.
Tech Morning Ritual
A technician's 15-minute start-of-day runbook: digest, schedule check, easy-win pick, and a first-response sweep before diving into ticket work.
Tech Performance Review
A manager asks to evaluate a technician's performance over a period — closed, assigned, reopened, time logged, sentiment — with coaching angles, not a verdict.
Tech Utilization Report
Report billable utilization per technician — logged billable hours against capacity — with role-aware targets and framing as workload economics, not worth.
Technical to Plain English
Translate a technical resolution, diagnosis, or explanation into language a non-technical stakeholder can understand — "make this client-friendly."
Technician Availability Check
Answer who is the next available technician by combining today's schedules, priority-weighted open load, and shift or PTO context into a ranked answer.
ThreatDown Malwarebytes
Triage ThreatDown (Malwarebytes) detections by class — malware, PUP, PUM, exploit — and run the remediation-verification pass the remediated status skips.
ThreatLocker Allowlisting
Work ThreatLocker approval and elevation requests: triage daily allowlisting safely, keep Learning vs Secured mode straight, protect zero-trust posture.
Three Strikes Final Email
Draft the final "we're closing this ticket" email after three documented contact attempts with no client response — only when evidence exists.
Ticket Export for LLM
Produce a clean, sanitized, self-contained export of a ticket for pasting into another AI tool — credentials and PII stripped, context preserved.
Ticket Intake & Formatting
Build a clean ticket title and description from a raw report, voicemail, email, form submission, or rough technician notes, following the house intake standard.
Ticket QA Review
Grade a completed ticket against the closure rubric — resolution, classification, owner, time logged, title, client message — pass or bounce it back.
Ticket Review Training
Turn a real resolved ticket into a sanitized teaching case with what was done well, what could improve, and the transferable lesson for team review.
Ticket Summary & Closure Note
Produce a clean ticket summary as a resolution note, closure note, or templated P1/P2 handoff — in the requested format and point of view.
Ticket Triage
Classify a new or unassigned ticket, gauge severity, catch duplicates, and route it to the right board, status, and priority for the queue.
Tickets to Opportunities
Mine recent service tickets for expansion signals, surfacing work that became or should become a sales opportunity, in a per-client opportunity report.
Tier Dispatcher
Dispatch a new ticket by support tier: classify T1/T2/senior, check that tier's technicians against today's schedule, then assign and book the work around the customer's deadline.
Time Entry Cleanup
Turn raw, rough time notes into clean, standardized time entries with client-facing and internal versions, recording only work explicitly stated as done.
Time Entry Revenue Audit
When someone wants to find tickets that were worked with no time logged — revenue leakage by technician or period — and get the gaps fixed the right way.
Todyl Platform
Route Todyl alerts by plane: SASE network, endpoint EDR, or identity and SIEM detection. Each plane needs a different runbook from the same platform.
Tone Polish Rewrite
Rewrite rough technician text into a polished, client-ready version — "write this nicely," "clean this up" — preserving every fact exactly.
Travel Access Window
Open a temporary conditional access exception for a traveling user with automatic expiry and a tracked revert task so location policies stay in place.
Trend Micro Worry-Free
Triage Trend Micro Worry-Free alerts by engine (signature, ML, behavior, web reputation) and know when a client is on Apex Central or Vision One instead.
Trend Root-Cause Mining
Find what is driving ticket volume and making the desk busy by mining recent tickets for top recurring issues and root causes across a chosen period.
Triage Agent Tuning
Tune Triage Agent custom rules from observed misses — wrong boards, wrong priorities, tickets it should have left alone — plus bypass-word usage analysis.
Triage d'hameçonnage (French)
Triage d'hameçonnage d'un e-mail suspect: évaluer sans toucher la charge, mesurer le rayon d'exposition, contenir si malveillant, répondre au déclarant.
Triaje de phishing (Spanish)
Triaje de phishing de un correo sospechoso: evaluar sin tocar la carga, medir radio de impacto, contener si es malicioso y responder al reportante.
Unattended Output Discipline
Base skill defining the output contract for any prompt or skill that runs unattended inside a flow, where the agent's entire reply is posted verbatim.
Vacation Handoff Pack
Pre-PTO handoff prep listing which tickets need transferring, which need watching, and a per-ticket one-liner brief so cover techs can act fast.
Variation Author
Interview the admin on client-specific troubleshooting differences (printers, VPN, LOB apps), then encode them as intent variations with a test plan.
vCIO Weekly Proactive
Pick the three highest-leverage clients to proactively contact this week from live ticket signals, with a reason and a suggested opener for each outreach.
Vendor Fraud BEC Alert
Respond to a BEC or payment-fraud attempt (fake invoice, banking-change request, exec impersonation): freeze payments and run callback verification.
Vendor Outage Checker
Check vendor status pages and outage reports for M365, ISPs, and SaaS apps, then post sourced findings to the ticket to confirm is it down for everyone.
View Builder
Create or duplicate an inbox view from a plain-English spec — "open P1s", "the dispatch view filtered to a client" — saved filters and view variants.
VIP Priority Handling
Detect VIP contacts and VIP clients at ticket intake, apply the configured priority bump, and fire notify rules without letting VIP status skew triage.
Voice Call QA Review
Review AI-handled voice calls against a rubric — caller identified, issue captured, commitments accurate, clean handoff — with transcript evidence cited.
Voice Catchall Identification
Identify the client and contact behind an unknown caller on a voice ticket with only a phone number, using number, name, and company clues from transcript.
Voice Transcript Intake
Turn a pasted call transcript into ticket action — extract caller, client, issue, and commitments, then create or update the ticket with a time entry.
Voicemail to Ticket
Convert a voicemail transcription into a ticket with a callback commitment — urgency read from what the caller actually said, not from tone guesses.
VPN Issues Intent Design
Design the VPN connectivity intent: a short self-help ladder plus environment capture — client, location, error text — so escalations arrive diagnosable.
Waiting-on-Client Audit
Audit every ticket parked in a waiting status: how long, whether a follow-up was sent, and the correct next action — nudge, reschedule, unpark, close.
Weekly Ops Report
A service manager wants the weekly service-desk report — team volume, closures, sentiment, aging, and anything anomalous versus the prior week.
Wire Fraud Verification Protocol
Callback verification for any payment change request: banking updates, new wire instructions, or payroll redirects — verify out-of-band, no exceptions.
Workaround Documentation
Document a workaround in the standard format (steps, hold time, cost, expiry review) and label the ticket workaround-only so nobody mistakes it for a fix.
Workload-Balancing Assignment
Assign a ticket to the tech with the best availability score — base capacity minus open tickets minus scheduled blocks — with math shown, runs in Flows.
Write Guardrails
Base skill defining the gates that sit in front of any action that changes something — confidence bar, show-me-before-send, when-in-doubt-do-nothing, and never invent data.
XLA Breach Risk Tiering
Tier every open ticket by XLA exposure — Breached, Critical, High, Watch — from remaining time to target with escalation factors and a next move.
Zero-Touch Opportunity Mining
Someone asks where the biggest opportunities are to increase zero-touch resolution, or which ticket patterns should become intents or flows.
IT Glue
Account Takeover Runbook
Respond to a confirmed account takeover: disable sign-in, revoke sessions, reset MFA, sweep inbox rules and OAuth consents, and notify users.
AD CS / Internal PKI Issues
Troubleshoot AD CS internal PKI issues — enrollment and template failures, CRL revocation-check errors, and certificate expiry cascades before reissuing.
AD Replication Issues
Fix Active Directory replication failures using repadmin — GPO version mismatches, password changes not propagating, and event IDs 1311/1388/1988.
Adobe Creative Cloud Licensing
Fix Adobe Creative Cloud sign-in loops, access-denied errors, and Admin Console entitlement gaps between named-user and shared-device licensing.
Anti-Spam Policy Tuning
Tune Exchange Online Protection and Defender anti-spam policies from verdict evidence with scoped overrides and time-limited exceptions.
App Protection Policies
Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.
Archive Mailbox Enablement
Enable Exchange Online In-Place Archive mailboxes to solve quota issues, with license checks, move-policy expectations, and archive caveats.
Audit Prep Review
Run a pre-audit sweep for unresolved prior findings, doc gaps, and stale evidence, and return a ranked readiness report before the auditor arrives.
AutoCAD / Revit Issues
Troubleshoot Autodesk AutoCAD and Revit — FlexNet network license checkout failures, drawing corruption, and BIM central-model worksharing sync.
Autopilot Deployment
Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.
B2B Collaboration Setup
Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.
Backup Failure Triage
Classify a backup failure by alert text and device state, check for recurrence, and decide whether to fix locally or escalate to the backup vendor.
Backup Missed vs Failed Alert
Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.
Backup Restore Request
Intake backup restore requests — deleted files, prior versions, mailboxes, servers — pinning down what, when, RPO limits, and verifying with requester.
BitLocker Key Retrieval
Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.
Break-Glass Account Audit
Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.
Browser Issues
Diagnose browser problems — one broken site, SSO loops, crashes, extension conflicts — using profile isolation and extension bisect, not clear-everything.
BSOD Analysis
Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.
Calendar Permissions
Grant or review Exchange calendar sharing and delegation with least-privilege folder roles, owner consent, and private-items handling.
Certificate Expiry Alert
Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.
Certificate Inventory
Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.
Circuit Inventory
Refresh a client circuit inventory — internet, WAN/MPLS/SD-WAN, POTS-replacement — with carrier, circuit ID, site, bandwidth, and renewal dates.
Citrix Basics
First-line playbook for Citrix Virtual Apps and Desktops (CVAD/DaaS) — VDA registration, StoreFront vs Workspace, hung sessions — before escalating.
Client Offboarding
Run a clean client exit checklist covering data handover, mutual access revocation, final billing notes, and the documentation package for both parties.
Client Onboarding Runbook
Take a newly signed client from MSA to service-desk readiness: boards, routing, contacts, docs intake, monitoring, and welcome comms as tracked tickets.
CMMC Readiness Brief
Produce a CMMC level-readiness snapshot for a defense-adjacent client with likely standing and obvious gaps — never a certification or formal assessment.
Compliance Questionnaire Assist
Draft answers to a client's security or compliance questionnaire from documented facts only, cite each source, and flag unknowns instead of guessing.
Conditional Access Review
Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.
Conference Room AV
Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.
CW Configurations Assets
ConnectWise Manage configurations (assets): link tickets to the right config, follow the desk's config-type taxonomy, and flag stale or duplicate configs.
Cyber Insurance Form Prep
Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.
Device Health Check
Diagnose one device via the RMM — alerts, activities, services, disk, reboot, and patch posture — then propose remediation with a deep-link handoff.
Device Offline Runbook
Work a device-offline alert or "won't connect" ticket — site-wide check first, maintenance windows, last activities, and clear escalate criteria.
Device Wipe Workflows
Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.
Device-to-User Mapping
Answer "who uses this device" by combining RMM last-logged-on data with contact records, ticket history, and documentation when a ticket names only one.
DFS Namespace and Replication
Fix DFS-N referral failures and DFS-R replication backlog, conflicts, and staging-quota issues using health reports and backlog counts, not blind reinit.
DHCP Server Issues
Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.
Dispatcher Intake
Attended chat intake for dispatchers: describe the issue and get back a ticket with board, type, priority, summary, and first-touch note attached.
Distribution vs M365 Groups
Pick between distribution lists, Microsoft 365 Groups, mail-enabled security groups, and dynamic groups, and handle DL-to-M365-Group upgrades.
DKIM Enablement
Enable DKIM signing for a custom domain in Exchange Online: publish selector CNAMEs, activate signing, verify records, and plan key rotation.
DMARC / SPF / DKIM Setup
Diagnose email authentication failures and build correct SPF, DKIM, and DMARC DNS records — new sending sources, alignment, and propagation expectations.
DNS & Domain Issues
Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.
Doc Gap Detector
Find tickets where a security- or configuration-impacting change (firewall, MFA, DNS, admin access) was made with no linked or matching documentation update.
Email Connector Setup
Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.
Endpoint Encryption Audit
Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.
Enrollment Restrictions
Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.
Entra Connect Sync Errors
Fix Entra Connect (Azure AD Connect) sync errors — export failures, duplicate attributes, quarantined objects, users missing in the cloud — no blind runs.
Entra PIM Requests
Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.
Environment Facts Updater
When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.
EOL Product Notice
Draft the client notice that a product or OS is reaching end-of-life — verified EOL date, honest risk framing, upgrade paths, decision deadline.
Exchange Hybrid Issues
Troubleshoot Exchange hybrid — mail stuck on-prem/cloud, blank free-busy, stalled migrations, user-not-found after moves — starting from mailbox ownership.
Exchange On-Prem Mail Flow
Diagnose on-prem Exchange transport — stuck queues, send/receive connector faults, TLS/cert failures, backpressure — using Queue Viewer and protocol logs.
Fax & eFax
Work fax tickets — dead analog lines, ATA fax page corruption, eFax cloud portals not sending or receiving — across the line, ATA, and portal matrix.
File Share Permissions
Diagnose access-denied file share tickets by laddering effective permissions across share vs NTFS vs inheritance and group membership, at least privilege.
Firewall Config Backup Audit
Verify every firewall config backup is current — via Liongard change history or the vendor state — and flag any device whose backup is missing or stale.
Firewall Rule Change Request
Shepherd a firewall change from vague ask to change-ready spec — justification, source/destination/port/protocol, expiry, and routing to the approver.
GDAP Relationship Review
Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.
Group Policy Troubleshooting
Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.
Guest Access Audit
Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.
Hardware Diagnostics
Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.
Hardware Refresh Forecast
Build a 4–5 year hardware refresh workbook per client — devices crossing the age threshold each period and the per-client refresh budget for planning.
HIPAA Safeguards Checklist
Walk a healthcare client's environment against the HIPAA Security Rule technical safeguards, returning a checklist of what's in place versus missing.
Hyper-V Clustering
Troubleshoot Hyper-V failover clusters — quorum loss, CSV redirected or offline, failed live migrations, stuck node drains — from cluster and event logs.
Hypervisor Alert Triage
Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.
IIS Web App
Diagnose IIS web app failures — app pool crashes, rapid-fail protection, binding and SSL problems, HTTP 500/502/503 codes — using HTTP.sys and FREB logs.
Impossible Travel Runbook
Investigate an impossible-travel or atypical-location sign-in alert: check VPN and travel, verify with the user by phone, and contain on confirmed ATO.
Industry Pack Frame
Base skill defining how a vertical pack works — the client's calendar first, then blast radius against it, the desk-vs-vendor boundary, and the regulator's data rules.
Insider Risk Basics
Handle insider-risk signals like data staging, sabotage, or access abuse: preserve evidence quietly, escalate to client HR, and keep it confidential.
Internal DNS Server Issues
Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.
Internal IT Offboarding
Offboard departing MSP staff with client-credential rotation first, then tool deprovisioning, ticket reassignment, and client-facing transition notes.
Internal IT Onboarding
Onboard the MSP's own new hire, technician, dispatcher, or back-office, with accounts, PSA/RMM/docs licenses, role-scoped client access, and shadowing.
Intune App Deployment
Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.
Intune Compliance Policies
Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.
Intune Enrollment Troubleshooting
Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
ISP Outage Tracking
Manage a circuit outage while the carrier owns the fix — capture the carrier ticket reference, run the escalation clock, and keep the client informed.
IT Glue Asset & Contact Lookup
On demand, pull IT Glue contacts, credentials, and flex-asset configs into a plain-text ticket summary, degrading to KB or ticket history if unavailable.
Journaling & Compliance Mail
Handle Exchange journaling and compliance-copy requests with legal justification, external journal targets, cost impact, and retention alternatives.
KB Article Draft
Turn a resolved ticket into a reusable knowledge-base article draft with title, symptoms, cause, numbered resolution, and stripped client specifics.
Knowledge Base Taxonomy
Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.
Label and Receipt Printers
Troubleshoot Zebra thermal label and ESC/POS receipt printers — ZPL/EPL print language, driver mode, spooler, and network faults — distinct from MFPs.
Large File Share Guide
Draft reply-ready instructions for an end user to send a file too big for email using the client's approved method — attachment bounced, big file.
LOB Application Framework
Generic playbook for any line-of-business app failure — dental, legal, accounting, ERP — identify vendor and version, pull logs, build escalation packets.
LOB Database Locks
Clear record-locked-by-another-user tickets in LOB apps — find the locking session in the vendor admin console and release it approved-only, never kill DB.
M365 Group Lifecycle
Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.
M365 License Optimization
Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.
M365 Sign-in Issues
Diagnose Microsoft 365 and Entra sign-in failures — blocked sign-ins, MFA loops, repeated password prompts, device-trust errors — from the sign-in log.
M365 Tenant Health Report
Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.
Mac Fleet Management
Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.
Mac Support
The Windows tech's ladder for Mac tickets — keychain prompts, MDM enrollment, TCC app permissions, FileVault — mapping macOS causes vs Windows reflexes.
Mail Flow & Delivery
Diagnose email delivery — NDR bounces, mail not arriving, stuck outbound, one sender blocked — by decoding the bounce and tracing the actual mail path.
Mailbox Migration Prep
Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.
Mailbox Quota Management
Investigate full or filling Exchange mailboxes and choose targeted cleanup, archive enablement, or license upgrade based on where size lives.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
MFA Methods Audit
Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.
MFA New Phone Guide
Draft reply-ready instructions for an end user who got a new phone and needs to move or re-enroll their MFA safely to approve sign-ins again.
MFA Setup Guide
Draft reply-ready instructions for an end user to enroll in multi-factor authentication using the client's actual MFA product for account sign-in.
Mobile Device & MDM
Work mobile MDM tickets — enrollment failures, missing mail profiles, compliance blocks, lost/stolen device response — destructive actions need approval.
Mobile Email Setup
Set up corporate mail on a phone — new-device config, sync failures, MDM enrollment prompts, native Mail vs Outlook — holding the BYOD consent boundary.
Mobile Fleet Review
Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.
Mobile Mail Setup Guide
Draft reply-ready instructions for an end user to get work email on their phone — Outlook mobile app first, matched to the client's mobile policy.
NAS / File Share Provisioning
Plan and document a new network share — folder structure, permission model, quota, backup inclusion — with an approval gate on the access model first.
NetSuite ERP
Support NetSuite ERP tickets as an MSP — roles and permissions, saved-search visibility, SuiteScript/REST/CSV integration errors — no financial edits.
Network Device Inventory
Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.
Network Outage Triage
Triage a suspected site-down — all-devices-offline vs single dead device, ISP vs internal, who to call, and set a comms cadence for the client updates.
Network Share Slowness
Diagnose slow SMB file shares — sluggish copies, crawling folder listings, one office fine — through SMB version, signing, AV filters, and DFS referrals.
New Computer First Day Guide
Draft reply-ready instructions for an end user receiving a new or replacement computer — what to expect, what to do first, and what NOT to do.
New Workstation Imaging Checklist
Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff.
NIST CSF Gap Brief
Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.
Office Activation & Licensing
Fix Office / Microsoft 365 Apps activation — Product Deactivated, unlicensed mode, repeated prompts, shared-computer/RDS errors — detect the license type.
On-Prem to Cloud File Migration
Fix file-server to SharePoint Online and OneDrive migration issues: NTFS permission translation, path length, illegal characters, and sync errors.
OneDrive / SharePoint Sync
Diagnose OneDrive and SharePoint sync — stuck processing changes, missing files, red X icons — separating client state, library limits, and permissions.
OneDrive Known Folder Move
Work OneDrive Known Folder Move rollout tickets — missing Desktop, sync conflicts, path-length and invalid-character legacy files — without unhooking KFM.
OneDrive Restore Guide
Draft reply-ready instructions for an end user to recover a deleted file or roll back a previous version themselves in OneDrive or SharePoint.
OneDrive Storage Governance
Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.
Out of Office Guide
Draft reply-ready instructions for an end user to set their own out-of-office reply correctly — dates, internal versus external messages for OOO.
Outlook Client Issues
Diagnose Outlook desktop crashes, hangs, broken search, password prompts, and crash-on-send using profile, data-file, and add-in isolation branches.
Outlook Profile Setup Guide
Draft reply-ready instructions for an end user to add their work account to Outlook on Windows or Mac — "send the user steps to set up Outlook."
Outlook Search Issues
Fix Outlook search returning nothing or incomplete results by isolating local index vs server search and cached-mode window before rebuilding the index.
PaperCut / PrinterLogic
Diagnose PaperCut and PrinterLogic print-management issues: release stations, driver deployment failures, and quota/account problems from platform logs.
Password Expiry Change Guide
Draft reply-ready instructions for an end user to change a password that's about to expire (or just did) before it locks them out of their account.
PCI DSS Scope Review
Help a client understand PCI DSS scope — what counts as the cardholder data environment (CDE), what's in versus out — not a QSA assessment or AOC.
Plus Addressing & Aliases
Handle requests for extra mailbox addresses: plus addressing for self-service tagging, proxy aliases, and the send-from-alias caveats stated.
POS System Issues
Work POS tickets — frozen terminals, failed card payments, back-office sync — by splitting terminal, payment gateway, and back-office with a PCI boundary.
Power Automate Governance
Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.
Print Server Management
Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.
Printer Connect Guide
Draft reply-ready instructions for an end user to add or reconnect the office printer, matched to the client's actual print setup and drivers.
Printer Fleet Review
Cluster a client printer-related tickets to find chronic devices, quantify the time they burn, and recommend replace-vs-repair per problem printer.
Printer Troubleshooting
Diagnose printing problems — nothing prints, stuck queues, garbled output, wrong printer, scan-to-email fails — via a spooler, driver, and network matrix.
Purview DLP Policy
Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.
QuickBooks Desktop Multi-User
Fix QuickBooks Desktop multi-user errors: H202/H505 hosting, -6000 series company file, stuck locks, via hosting mode and Database Server Manager checks.
QuickBooks Online Issues
Fix QuickBooks Online browser problems: bank-feed failures, multi-user role errors, cache and extension issues; distinguish QBO from Desktop before acting.
RADIUS / NPS Authentication
Diagnose 802.1X and RADIUS authentication failures on Windows NPS: Wi-Fi, wired, VPN rejects, certificates, and shared-secret issues via NPS event logs.
RAID Degradation Alert
Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.
Ransomware Response
Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.
RD Gateway Issues
Fix Remote Desktop Gateway and RD Web Access problems: external RDP failures, certificate errors, CAP/RAP policy mismatches, and MFA integration failures.
RDS / AVD Troubleshooting
Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.
Report Phishing Guide
Draft reply-ready instructions telling an end user what to do with a suspicious email — the client's report-button path, never forwarding around.
Resource Mailbox Setup
Create Exchange room and equipment mailboxes with booking policies, auto-accept or delegate approval, and recurring-meeting and duration limits.
Retention Policy Requests
Change Microsoft Purview retention and deletion policies with scope confirmed, legal-hold interaction flagged, and authorization documented.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
Roaming Profiles & FSLogix
Fix FSLogix and roaming-profile failures on session hosts: cannot attach VHD, temp profiles, sign-in hangs, and settings loss via FSLogix log codes.
Safe Attachments and Links Policy
Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.
Safe File Sharing Guide
Draft reply-ready instructions for an end user to share files the approved way — links over attachments, right audience, external-sharing rules.
Sage 50 / Sage 100
Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.
SCADA / OT Awareness
Support OT-adjacent tickets safely: hard IT vs SCADA/PLC/HMI/ICS boundary, never touching controllers, and routing to the correct OT or vendor owner.
Scanner & Copier Fleet
Fix MFP and copier scan-to-folder failures after SMB or credential changes, address-book cleanup, firmware quirks, and panel errors on leased fleets.
Screen Share Help Guide
Draft reply-ready instructions for an end user to start a remote-support screen share with the desk using the client's actual remote tool.
SD-WAN / Multi-Circuit Monitoring
Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.
Security Advisory Broadcast
Draft a security advisory going to many clients — new threat, vendor breach, or vulnerability — from verified facts with per-client relevance check.
Security Alert Response
Work an inbound security alert ticket: extract the facts, route to the right client, tier severity, and contain or close with documented reasoning.
Security Defaults vs Conditional Access
Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
Security Questionnaire Vendor DDQ
Draft responses to an inbound vendor security questionnaire or DDQ from documented facts only, cite evidence for each, and flag every unknown for review.
Sensitivity Labels
Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.
Server Decommission Runbook
Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.
Server Patch Windows
Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.
Shared Mailbox Access Guide
Draft reply-ready instructions for an end user to open a shared mailbox they've been granted access to — desktop, web, and mobile paths covered.
Shared Mailbox Creation
Create Exchange Online shared mailboxes: naming, licensing at the 50GB threshold, initial delegation, and documentation for team inboxes.
SharePoint On-Prem
Diagnose on-premises SharePoint Server: search crawl failures, stale results, content-database mounting, and permission inheritance via ULS crawl logs.
SharePoint Site Provisioning
Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.
Slow Computer
Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.
SOC2 Evidence Collection
Map an auditor's SOC 2 evidence request list to ticket, change, and access evidence, packaging it with citations and honestly flagged gaps.
SOP Builder
Write a standard operating procedure — scope, prerequisites, numbered steps, validation, escalation — from a ticket, a rough doc, or a described process.
SOP Candidate Finder
Sweep recently resolved tickets for documentation-worthy resolutions like recurring fixes and vendor workarounds, ranking SOP and KB article candidates.
SQL Backup and Maintenance
Fix SQL Server backup issues: runaway log growth, FULL vs SIMPLE recovery model, missing log backups, VSS conflicts, and broken point-in-time recovery.
SQL Server Performance
Diagnose SQL Server slowness: blocking, deadlocks, missing indexes, stale statistics, tempdb contention, and parameter sniffing via live wait stats.
SSL Certificate Renewal
Handle SSL and TLS certificate renewals: browser warnings, service certificate expiry, issuer-specific renewal paths, and required service restarts.
SSL Inspection Issues
Diagnose TLS/SSL inspection breakage: pinned apps failing, firewall certificate warnings, apps broken only on corporate networks, and bypass routing.
SSPR Password Reset Guide
Draft reply-ready instructions an end user can follow to reset their own password via self-service password reset without calling the help desk.
SSPR Rollout
Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.
Stale Device Cleanup
Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.
Stale Doc Hygiene
Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.
Storage Capacity Planning
Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.
Supporting Accounting Firms
CPA and accounting firm pack covering Lacerte, ProSeries, and UltraTax software, tax-season freeze windows, and IRS Pub 4557 WISP safeguards.
Supporting Architecture and Engineering Firms
AEC firm pack for AutoCAD, Revit, and Civil 3D support, network license servers, GPU workstations, and submittal-deadline urgency.
Supporting Auto Dealerships
Auto dealership pack covering DMS platforms (CDK, Reynolds, Tekion), OEM tooling, F&I data under FTC Safeguards, and month-end urgency.
Supporting Construction and Field Services
Construction and field-service pack for Procore, Bluebeam, and ServiceTitan, plus rugged tablets, jobsite connectivity, and crew clocks.
Supporting Dental Practices
Dental practice pack covering Dentrix, Eaglesoft, and Open Dental PMS, Dexis-class x-ray sensors, HIPAA, and morning-huddle downtime.
Supporting Financial Services Clients
RIA, broker-dealer, and bank pack covering FINRA/SEC email archiving retention, Orion and Redtail advisory tools, and market-hours urgency.
Supporting Insurance Agencies
Independent insurance agency pack for Applied Epic, EZLynx, and HawkSoft AMS, carrier portals, IVANS downloads, ACORD forms, and E&O trails.
Supporting Legal Firms
Law firm pack covering iManage and NetDocuments DMS, Clio practice management, ethical walls, litigation holds, and court-deadline urgency.
Supporting Logistics and Trucking Clients
Trucking and 3PL pack covering McLeod and Trimble TMS, Samsara and Motive ELDs, DOT/HOS compliance, EDI, and 24/7 dispatch operations.
Supporting Manufacturing Clients
Manufacturing client pack covering the OT/IT boundary, PLC and SCADA hands-off rules, ERP/MES stacks, shift patterns, and line-down urgency.
Supporting Medical Clinics
Medical clinic pack for eClinicalWorks and Athenahealth EMR, e-prescribing, lab interfaces, telehealth, and HIPAA PHI ticket hygiene.
Supporting Municipal Government
City, county, and special-district pack covering public-records email retention, CJIS for PD systems, procurement cycles, and council AV.
Supporting Nonprofits
Nonprofit client pack covering Blackbaud donor CRM, TechSoup and Microsoft grant licensing, board access hygiene, and year-end giving.
Supporting Property Management Clients
Property management pack covering Yardi, AppFolio, and Buildium platforms, tenant portals, owner-tenant data separation, and trust accounting.
Supporting Real Estate Clients
Real estate brokerage and title pack covering Dotloop, SkySlope, MLS and lockboxes, wire-fraud and BEC defense, and agent BYOD sprawl.
Supporting Schools and Education
K-12 school and district pack covering PowerSchool SIS, Canvas LMS, FERPA data hygiene, CIPA filtering, E-Rate, and 1:1 device programs.
Supporting Senior Living Communities
Senior living and skilled-nursing pack covering PointClickCare and MatrixCare EHR/eMAR, nurse-call systems, resident wifi split, and HIPAA.
Switch VLAN and Port Change
Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.
Teams Call Quality
Fix Microsoft Teams call quality: choppy audio, robotic voice, frozen video, and drops via CQD-style device, machine, and network path layer isolation.
Teams Issues
Diagnose Microsoft Teams sign-in loops, meeting join failures, no audio or video, stuck presence, and guest access, with cache reset used sparingly.
Teams Meeting Guide
Draft reply-ready instructions for an end user to join and run a Teams meeting — audio and camera checks, screen sharing, recording basics.
Teams Phone Admin
Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.
Teams Rooms AV
Fix Microsoft Teams Rooms devices: room account sign-in, camera, mic, display, touch console health, calendar join failures, and restart discipline.
Tenant Onboarding Checklist
Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.
Ticket Research Copilot
Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.
Transport Rule Management
Inspect, add, or change Exchange Online transport rules safely: document current state, test mode before enforce, and disable instead of delete.
Troubleshooting Ladder
Base skill defining the order every troubleshooting playbook works in — history, documentation, blast radius, versions, verbatim evidence, then branch — and how it closes out.
Veeam Restore Operations
Run Veeam restores end to end: pick file-level, application-item, full-VM, or Instant Recovery, choose the right point, target a safe location, verify.
Vendor Escalation Package
Assemble a third-party vendor support package — environment, repro steps, timeline, diagnostics, contract or entitlement reference — credentials stripped.
VMware vSAN and vMotion
Diagnose VMware vSphere: vSAN health warnings, resync storms, vMotion and DRS migration failures, datastore latency, and APD or PDL via vCenter events.
VoIP Phone Matrix
Diagnose VoIP problems: inbound calls failing, ring group misbehavior, one-way audio, dead phones, provisioning fails, by splitting phone vs site vs trunk.
VPN Connect Guide
Draft reply-ready instructions for an end user to connect to their company VPN using the client's actual VPN software and login flow.
VPN Troubleshooting
Diagnose VPN issues: won't connect, authenticates then no traffic, drops while remote, or can't reach resources by name via a client and DNS matrix.
Vulnerability Report Triage
Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.
Warranty and EOL Report
Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.
Wi-Fi & Network Troubleshooting
Diagnose Wi-Fi and LAN issues: slow or dropping Wi-Fi, connection failures, dead zones, and internet-down reports by laddering user to AP to site scope.
WiFi Connect Guide
Draft reply-ready instructions for an end user connecting a work device to wifi — office network, home network, and captive-portal awareness.
WiFi Heatmap / Site Survey Request
Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.
WiFi Infrastructure Audit
Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.
Windows 11 Migration Issues
Handle post-upgrade Windows 11 migration tickets: driver regressions, reset default apps, missing printers, moved features, with rollback window checked.
Windows Hello for Business
Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.
Windows Profile Corruption
Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.
Windows Update Client Failures
Diagnose Windows Update client failures: 0x8024xxxx and 0x800Fxxxx errors, update loops and rollbacks, and stuck scans across WU, WSUS, and Intune sources.
Working From Home Checklist
Draft a reply-ready remote-work setup checklist for an end user — connectivity, VPN, phone, and how to get help — tailored to the client's stack.
WSUS Patching Infrastructure
Diagnose WSUS server-side issues: clients not checking in, 0% downloads, console crashes, unapproved-but-never-arriving updates, and database bloat.
Zero-Day Emergency Response
Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.
Hudu
AD CS / Internal PKI Issues
Troubleshoot AD CS internal PKI issues — enrollment and template failures, CRL revocation-check errors, and certificate expiry cascades before reissuing.
AD Replication Issues
Fix Active Directory replication failures using repadmin — GPO version mismatches, password changes not propagating, and event IDs 1311/1388/1988.
Adobe Creative Cloud Licensing
Fix Adobe Creative Cloud sign-in loops, access-denied errors, and Admin Console entitlement gaps between named-user and shared-device licensing.
App Protection Policies
Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.
AutoCAD / Revit Issues
Troubleshoot Autodesk AutoCAD and Revit — FlexNet network license checkout failures, drawing corruption, and BIM central-model worksharing sync.
Autopilot Deployment
Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.
B2B Collaboration Setup
Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.
Backup Restore Request
Intake backup restore requests — deleted files, prior versions, mailboxes, servers — pinning down what, when, RPO limits, and verifying with requester.
BitLocker Key Retrieval
Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.
Break-Glass Account Audit
Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.
Browser Issues
Diagnose browser problems — one broken site, SSO loops, crashes, extension conflicts — using profile isolation and extension bisect, not clear-everything.
BSOD Analysis
Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.
Certificate Expiry Alert
Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.
Certificate Inventory
Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.
Circuit Inventory
Refresh a client circuit inventory — internet, WAN/MPLS/SD-WAN, POTS-replacement — with carrier, circuit ID, site, bandwidth, and renewal dates.
Citrix Basics
First-line playbook for Citrix Virtual Apps and Desktops (CVAD/DaaS) — VDA registration, StoreFront vs Workspace, hung sessions — before escalating.
Client Offboarding
Run a clean client exit checklist covering data handover, mutual access revocation, final billing notes, and the documentation package for both parties.
Client Onboarding Runbook
Take a newly signed client from MSA to service-desk readiness: boards, routing, contacts, docs intake, monitoring, and welcome comms as tracked tickets.
CMMC Readiness Brief
Produce a CMMC level-readiness snapshot for a defense-adjacent client with likely standing and obvious gaps — never a certification or formal assessment.
Conditional Access Review
Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.
Conference Room AV
Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.
CW Configurations Assets
ConnectWise Manage configurations (assets): link tickets to the right config, follow the desk's config-type taxonomy, and flag stale or duplicate configs.
Device Wipe Workflows
Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.
DFS Namespace and Replication
Fix DFS-N referral failures and DFS-R replication backlog, conflicts, and staging-quota issues using health reports and backlog counts, not blind reinit.
DHCP Server Issues
Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.
Dispatcher Intake
Attended chat intake for dispatchers: describe the issue and get back a ticket with board, type, priority, summary, and first-touch note attached.
DMARC / SPF / DKIM Setup
Diagnose email authentication failures and build correct SPF, DKIM, and DMARC DNS records — new sending sources, alignment, and propagation expectations.
DNS & Domain Issues
Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.
Doc Gap Detector
Find tickets where a security- or configuration-impacting change (firewall, MFA, DNS, admin access) was made with no linked or matching documentation update.
Email Connector Setup
Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.
Endpoint Encryption Audit
Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.
Enrollment Restrictions
Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.
Entra Connect Sync Errors
Fix Entra Connect (Azure AD Connect) sync errors — export failures, duplicate attributes, quarantined objects, users missing in the cloud — no blind runs.
Entra PIM Requests
Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.
Environment Facts Updater
When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.
EOL Product Notice
Draft the client notice that a product or OS is reaching end-of-life — verified EOL date, honest risk framing, upgrade paths, decision deadline.
Exchange Hybrid Issues
Troubleshoot Exchange hybrid — mail stuck on-prem/cloud, blank free-busy, stalled migrations, user-not-found after moves — starting from mailbox ownership.
Exchange On-Prem Mail Flow
Diagnose on-prem Exchange transport — stuck queues, send/receive connector faults, TLS/cert failures, backpressure — using Queue Viewer and protocol logs.
Fax & eFax
Work fax tickets — dead analog lines, ATA fax page corruption, eFax cloud portals not sending or receiving — across the line, ATA, and portal matrix.
File Share Permissions
Diagnose access-denied file share tickets by laddering effective permissions across share vs NTFS vs inheritance and group membership, at least privilege.
Firewall Rule Change Request
Shepherd a firewall change from vague ask to change-ready spec — justification, source/destination/port/protocol, expiry, and routing to the approver.
GDAP Relationship Review
Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.
Group Policy Troubleshooting
Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.
Guest Access Audit
Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.
Hardware Diagnostics
Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.
HIPAA Safeguards Checklist
Walk a healthcare client's environment against the HIPAA Security Rule technical safeguards, returning a checklist of what's in place versus missing.
Hyper-V Clustering
Troubleshoot Hyper-V failover clusters — quorum loss, CSV redirected or offline, failed live migrations, stuck node drains — from cluster and event logs.
Hypervisor Alert Triage
Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.
IIS Web App
Diagnose IIS web app failures — app pool crashes, rapid-fail protection, binding and SSL problems, HTTP 500/502/503 codes — using HTTP.sys and FREB logs.
Industry Pack Frame
Base skill defining how a vertical pack works — the client's calendar first, then blast radius against it, the desk-vs-vendor boundary, and the regulator's data rules.
Internal DNS Server Issues
Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.
Internal IT Offboarding
Offboard departing MSP staff with client-credential rotation first, then tool deprovisioning, ticket reassignment, and client-facing transition notes.
Internal IT Onboarding
Onboard the MSP's own new hire, technician, dispatcher, or back-office, with accounts, PSA/RMM/docs licenses, role-scoped client access, and shadowing.
Intune App Deployment
Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.
Intune Compliance Policies
Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.
Intune Enrollment Troubleshooting
Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
ISP Outage Tracking
Manage a circuit outage while the carrier owns the fix — capture the carrier ticket reference, run the escalation clock, and keep the client informed.
KB Article Draft
Turn a resolved ticket into a reusable knowledge-base article draft with title, symptoms, cause, numbered resolution, and stripped client specifics.
Knowledge Base Taxonomy
Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.
Label and Receipt Printers
Troubleshoot Zebra thermal label and ESC/POS receipt printers — ZPL/EPL print language, driver mode, spooler, and network faults — distinct from MFPs.
Large File Share Guide
Draft reply-ready instructions for an end user to send a file too big for email using the client's approved method — attachment bounced, big file.
LOB Application Framework
Generic playbook for any line-of-business app failure — dental, legal, accounting, ERP — identify vendor and version, pull logs, build escalation packets.
LOB Database Locks
Clear record-locked-by-another-user tickets in LOB apps — find the locking session in the vendor admin console and release it approved-only, never kill DB.
M365 Group Lifecycle
Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.
M365 License Optimization
Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.
M365 Sign-in Issues
Diagnose Microsoft 365 and Entra sign-in failures — blocked sign-ins, MFA loops, repeated password prompts, device-trust errors — from the sign-in log.
M365 Tenant Health Report
Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.
Mac Fleet Management
Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.
Mac Support
The Windows tech's ladder for Mac tickets — keychain prompts, MDM enrollment, TCC app permissions, FileVault — mapping macOS causes vs Windows reflexes.
Mail Flow & Delivery
Diagnose email delivery — NDR bounces, mail not arriving, stuck outbound, one sender blocked — by decoding the bounce and tracing the actual mail path.
Mailbox Migration Prep
Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.
MFA Methods Audit
Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.
MFA New Phone Guide
Draft reply-ready instructions for an end user who got a new phone and needs to move or re-enroll their MFA safely to approve sign-ins again.
MFA Setup Guide
Draft reply-ready instructions for an end user to enroll in multi-factor authentication using the client's actual MFA product for account sign-in.
Mobile Device & MDM
Work mobile MDM tickets — enrollment failures, missing mail profiles, compliance blocks, lost/stolen device response — destructive actions need approval.
Mobile Email Setup
Set up corporate mail on a phone — new-device config, sync failures, MDM enrollment prompts, native Mail vs Outlook — holding the BYOD consent boundary.
Mobile Fleet Review
Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.
Mobile Mail Setup Guide
Draft reply-ready instructions for an end user to get work email on their phone — Outlook mobile app first, matched to the client's mobile policy.
NetSuite ERP
Support NetSuite ERP tickets as an MSP — roles and permissions, saved-search visibility, SuiteScript/REST/CSV integration errors — no financial edits.
Network Device Inventory
Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.
Network Share Slowness
Diagnose slow SMB file shares — sluggish copies, crawling folder listings, one office fine — through SMB version, signing, AV filters, and DFS referrals.
New Computer First Day Guide
Draft reply-ready instructions for an end user receiving a new or replacement computer — what to expect, what to do first, and what NOT to do.
NIST CSF Gap Brief
Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.
Office Activation & Licensing
Fix Office / Microsoft 365 Apps activation — Product Deactivated, unlicensed mode, repeated prompts, shared-computer/RDS errors — detect the license type.
On-Prem to Cloud File Migration
Fix file-server to SharePoint Online and OneDrive migration issues: NTFS permission translation, path length, illegal characters, and sync errors.
OneDrive / SharePoint Sync
Diagnose OneDrive and SharePoint sync — stuck processing changes, missing files, red X icons — separating client state, library limits, and permissions.
OneDrive Known Folder Move
Work OneDrive Known Folder Move rollout tickets — missing Desktop, sync conflicts, path-length and invalid-character legacy files — without unhooking KFM.
OneDrive Restore Guide
Draft reply-ready instructions for an end user to recover a deleted file or roll back a previous version themselves in OneDrive or SharePoint.
OneDrive Storage Governance
Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.
Out of Office Guide
Draft reply-ready instructions for an end user to set their own out-of-office reply correctly — dates, internal versus external messages for OOO.
Outlook Client Issues
Diagnose Outlook desktop crashes, hangs, broken search, password prompts, and crash-on-send using profile, data-file, and add-in isolation branches.
Outlook Profile Setup Guide
Draft reply-ready instructions for an end user to add their work account to Outlook on Windows or Mac — "send the user steps to set up Outlook."
Outlook Search Issues
Fix Outlook search returning nothing or incomplete results by isolating local index vs server search and cached-mode window before rebuilding the index.
PaperCut / PrinterLogic
Diagnose PaperCut and PrinterLogic print-management issues: release stations, driver deployment failures, and quota/account problems from platform logs.
Password Expiry Change Guide
Draft reply-ready instructions for an end user to change a password that's about to expire (or just did) before it locks them out of their account.
PCI DSS Scope Review
Help a client understand PCI DSS scope — what counts as the cardholder data environment (CDE), what's in versus out — not a QSA assessment or AOC.
POS System Issues
Work POS tickets — frozen terminals, failed card payments, back-office sync — by splitting terminal, payment gateway, and back-office with a PCI boundary.
Power Automate Governance
Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.
Print Server Management
Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.
Printer Connect Guide
Draft reply-ready instructions for an end user to add or reconnect the office printer, matched to the client's actual print setup and drivers.
Printer Troubleshooting
Diagnose printing problems — nothing prints, stuck queues, garbled output, wrong printer, scan-to-email fails — via a spooler, driver, and network matrix.
Purview DLP Policy
Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.
QuickBooks Desktop Multi-User
Fix QuickBooks Desktop multi-user errors: H202/H505 hosting, -6000 series company file, stuck locks, via hosting mode and Database Server Manager checks.
QuickBooks Online Issues
Fix QuickBooks Online browser problems: bank-feed failures, multi-user role errors, cache and extension issues; distinguish QBO from Desktop before acting.
RADIUS / NPS Authentication
Diagnose 802.1X and RADIUS authentication failures on Windows NPS: Wi-Fi, wired, VPN rejects, certificates, and shared-secret issues via NPS event logs.
RD Gateway Issues
Fix Remote Desktop Gateway and RD Web Access problems: external RDP failures, certificate errors, CAP/RAP policy mismatches, and MFA integration failures.
RDS / AVD Troubleshooting
Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.
Report Phishing Guide
Draft reply-ready instructions telling an end user what to do with a suspicious email — the client's report-button path, never forwarding around.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
Roaming Profiles & FSLogix
Fix FSLogix and roaming-profile failures on session hosts: cannot attach VHD, temp profiles, sign-in hangs, and settings loss via FSLogix log codes.
Route, Assign and Document
Take a ticket off the intake board end to end: send it to the right queue, assign the best-suited available technician, explain both choices with supporting docs, and log the time.
Safe Attachments and Links Policy
Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.
Safe File Sharing Guide
Draft reply-ready instructions for an end user to share files the approved way — links over attachments, right audience, external-sharing rules.
Sage 50 / Sage 100
Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.
SCADA / OT Awareness
Support OT-adjacent tickets safely: hard IT vs SCADA/PLC/HMI/ICS boundary, never touching controllers, and routing to the correct OT or vendor owner.
Scanner & Copier Fleet
Fix MFP and copier scan-to-folder failures after SMB or credential changes, address-book cleanup, firmware quirks, and panel errors on leased fleets.
Screen Share Help Guide
Draft reply-ready instructions for an end user to start a remote-support screen share with the desk using the client's actual remote tool.
Security Advisory Broadcast
Draft a security advisory going to many clients — new threat, vendor breach, or vulnerability — from verified facts with per-client relevance check.
Security Defaults vs Conditional Access
Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.
Security Questionnaire Vendor DDQ
Draft responses to an inbound vendor security questionnaire or DDQ from documented facts only, cite evidence for each, and flag every unknown for review.
Sensitivity Labels
Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.
Server Patch Windows
Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.
Shared Mailbox Access Guide
Draft reply-ready instructions for an end user to open a shared mailbox they've been granted access to — desktop, web, and mobile paths covered.
SharePoint On-Prem
Diagnose on-premises SharePoint Server: search crawl failures, stale results, content-database mounting, and permission inheritance via ULS crawl logs.
SharePoint Site Provisioning
Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.
Slow Computer
Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.
SOP Builder
Write a standard operating procedure — scope, prerequisites, numbered steps, validation, escalation — from a ticket, a rough doc, or a described process.
SOP Candidate Finder
Sweep recently resolved tickets for documentation-worthy resolutions like recurring fixes and vendor workarounds, ranking SOP and KB article candidates.
SQL Backup and Maintenance
Fix SQL Server backup issues: runaway log growth, FULL vs SIMPLE recovery model, missing log backups, VSS conflicts, and broken point-in-time recovery.
SQL Server Performance
Diagnose SQL Server slowness: blocking, deadlocks, missing indexes, stale statistics, tempdb contention, and parameter sniffing via live wait stats.
SSL Certificate Renewal
Handle SSL and TLS certificate renewals: browser warnings, service certificate expiry, issuer-specific renewal paths, and required service restarts.
SSL Inspection Issues
Diagnose TLS/SSL inspection breakage: pinned apps failing, firewall certificate warnings, apps broken only on corporate networks, and bypass routing.
SSPR Password Reset Guide
Draft reply-ready instructions an end user can follow to reset their own password via self-service password reset without calling the help desk.
SSPR Rollout
Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.
Stale Device Cleanup
Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.
Stale Doc Hygiene
Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.
Storage Capacity Planning
Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.
Supporting Accounting Firms
CPA and accounting firm pack covering Lacerte, ProSeries, and UltraTax software, tax-season freeze windows, and IRS Pub 4557 WISP safeguards.
Supporting Architecture and Engineering Firms
AEC firm pack for AutoCAD, Revit, and Civil 3D support, network license servers, GPU workstations, and submittal-deadline urgency.
Supporting Auto Dealerships
Auto dealership pack covering DMS platforms (CDK, Reynolds, Tekion), OEM tooling, F&I data under FTC Safeguards, and month-end urgency.
Supporting Construction and Field Services
Construction and field-service pack for Procore, Bluebeam, and ServiceTitan, plus rugged tablets, jobsite connectivity, and crew clocks.
Supporting Dental Practices
Dental practice pack covering Dentrix, Eaglesoft, and Open Dental PMS, Dexis-class x-ray sensors, HIPAA, and morning-huddle downtime.
Supporting Financial Services Clients
RIA, broker-dealer, and bank pack covering FINRA/SEC email archiving retention, Orion and Redtail advisory tools, and market-hours urgency.
Supporting Insurance Agencies
Independent insurance agency pack for Applied Epic, EZLynx, and HawkSoft AMS, carrier portals, IVANS downloads, ACORD forms, and E&O trails.
Supporting Legal Firms
Law firm pack covering iManage and NetDocuments DMS, Clio practice management, ethical walls, litigation holds, and court-deadline urgency.
Supporting Logistics and Trucking Clients
Trucking and 3PL pack covering McLeod and Trimble TMS, Samsara and Motive ELDs, DOT/HOS compliance, EDI, and 24/7 dispatch operations.
Supporting Manufacturing Clients
Manufacturing client pack covering the OT/IT boundary, PLC and SCADA hands-off rules, ERP/MES stacks, shift patterns, and line-down urgency.
Supporting Medical Clinics
Medical clinic pack for eClinicalWorks and Athenahealth EMR, e-prescribing, lab interfaces, telehealth, and HIPAA PHI ticket hygiene.
Supporting Municipal Government
City, county, and special-district pack covering public-records email retention, CJIS for PD systems, procurement cycles, and council AV.
Supporting Nonprofits
Nonprofit client pack covering Blackbaud donor CRM, TechSoup and Microsoft grant licensing, board access hygiene, and year-end giving.
Supporting Property Management Clients
Property management pack covering Yardi, AppFolio, and Buildium platforms, tenant portals, owner-tenant data separation, and trust accounting.
Supporting Real Estate Clients
Real estate brokerage and title pack covering Dotloop, SkySlope, MLS and lockboxes, wire-fraud and BEC defense, and agent BYOD sprawl.
Supporting Schools and Education
K-12 school and district pack covering PowerSchool SIS, Canvas LMS, FERPA data hygiene, CIPA filtering, E-Rate, and 1:1 device programs.
Supporting Senior Living Communities
Senior living and skilled-nursing pack covering PointClickCare and MatrixCare EHR/eMAR, nurse-call systems, resident wifi split, and HIPAA.
Switch VLAN and Port Change
Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.
Teams Call Quality
Fix Microsoft Teams call quality: choppy audio, robotic voice, frozen video, and drops via CQD-style device, machine, and network path layer isolation.
Teams Issues
Diagnose Microsoft Teams sign-in loops, meeting join failures, no audio or video, stuck presence, and guest access, with cache reset used sparingly.
Teams Meeting Guide
Draft reply-ready instructions for an end user to join and run a Teams meeting — audio and camera checks, screen sharing, recording basics.
Teams Phone Admin
Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.
Teams Rooms AV
Fix Microsoft Teams Rooms devices: room account sign-in, camera, mic, display, touch console health, calendar join failures, and restart discipline.
Tenant Onboarding Checklist
Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.
Ticket Research Copilot
Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.
Troubleshooting Ladder
Base skill defining the order every troubleshooting playbook works in — history, documentation, blast radius, versions, verbatim evidence, then branch — and how it closes out.
Veeam Restore Operations
Run Veeam restores end to end: pick file-level, application-item, full-VM, or Instant Recovery, choose the right point, target a safe location, verify.
Vendor Escalation Package
Assemble a third-party vendor support package — environment, repro steps, timeline, diagnostics, contract or entitlement reference — credentials stripped.
VMware vSAN and vMotion
Diagnose VMware vSphere: vSAN health warnings, resync storms, vMotion and DRS migration failures, datastore latency, and APD or PDL via vCenter events.
VoIP Phone Matrix
Diagnose VoIP problems: inbound calls failing, ring group misbehavior, one-way audio, dead phones, provisioning fails, by splitting phone vs site vs trunk.
VPN Connect Guide
Draft reply-ready instructions for an end user to connect to their company VPN using the client's actual VPN software and login flow.
VPN Troubleshooting
Diagnose VPN issues: won't connect, authenticates then no traffic, drops while remote, or can't reach resources by name via a client and DNS matrix.
Wi-Fi & Network Troubleshooting
Diagnose Wi-Fi and LAN issues: slow or dropping Wi-Fi, connection failures, dead zones, and internet-down reports by laddering user to AP to site scope.
WiFi Connect Guide
Draft reply-ready instructions for an end user connecting a work device to wifi — office network, home network, and captive-portal awareness.
WiFi Infrastructure Audit
Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.
Windows 11 Migration Issues
Handle post-upgrade Windows 11 migration tickets: driver regressions, reset default apps, missing printers, moved features, with rollback window checked.
Windows Hello for Business
Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.
Windows Profile Corruption
Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.
Windows Update Client Failures
Diagnose Windows Update client failures: 0x8024xxxx and 0x800Fxxxx errors, update loops and rollbacks, and stuck scans across WU, WSUS, and Intune sources.
Working From Home Checklist
Draft a reply-ready remote-work setup checklist for an end user — connectivity, VPN, phone, and how to get help — tailored to the client's stack.
WSUS Patching Infrastructure
Diagnose WSUS server-side issues: clients not checking in, 0% downloads, console crashes, unapproved-but-never-arriving updates, and database bloat.
Liongard
Backup Missed vs Failed Alert
Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.
Certificate Expiry Alert
Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.
Certificate Inventory
Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.
Cyber Insurance Form Prep
Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.
Cyber Risk Posture Review
Review a client's security posture using the cyber risk dashboard, identity data, open detections, and incident history, ranking the top risks.
DHCP Server Issues
Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.
DMARC SPF Failure Triage
Diagnose SPF, DKIM, and DMARC email authentication failures: distinguish real spoofing attempts from sender misconfiguration and explain to the client.
DNS & Domain Issues
Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.
Domain Expiry Alert Lifecycle
Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.
Endpoint Encryption Audit
Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.
Firewall Config Backup Audit
Verify every firewall config backup is current — via Liongard change history or the vendor state — and flag any device whose backup is missing or stale.
Global Admin Audit
Audit a client tenant's global administrator accounts and recent admin-role changes, flagging unexpected admins, missing MFA, and unauthorized grants.
Group Policy Troubleshooting
Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.
Identity MFA Health Check
Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.
Inspector Read Discipline
Base skill defining how any Liongard inspector is read — resolve the environment, date the dataprint, verify field angles live, and state data age in every answer.
Internal DNS Server Issues
Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
IT Roadmap Builder
Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.
Liongard Access Pattern
Base pattern for reading any system's config through Liongard: resolve environment, find inspector by systemType, verify run, query dataprint.
Liongard Active Directory Read
Answer on-prem Active Directory questions via Liongard AD inspector: privileged groups, stale accounts, password policy, GPOs, FSMO, and DC health.
Liongard AWS Read
Answer AWS account questions via Liongard AWS inspector: IAM users, access-key age, root/MFA posture, S3 exposure, security groups, resource census.
Liongard Azure Read
Answer Azure subscription questions via Liongard Azure inspector: resource inventory, spend signals, NSG changes, public exposure, unattached resources.
Liongard Bitdefender Read
Interrogate a client's Bitdefender GravityZone tenant via Liongard: protected endpoints, agent/module status, threat detections, policies, admins.
Liongard Change Review
Answer "what changed recently" from Liongard detections and timelines, correlating environment changes with new tickets after breakage or incidents.
Liongard Cisco ASA Read
Interrogate a client's Cisco ASA firewall via Liongard: software version, interfaces, ACLs/NAT, IPsec/AnyConnect VPN config, and admin access review.
Liongard Cisco Network Read
Interrogate Cisco IOS/IOS-XE switches and routers via Liongard: IOS versions, running-config change detection, port/interface inventory, VLAN layout.
Liongard ConnectWise Automate Read
Interrogate ConnectWise Automate (LabTech) via Liongard: managed computer inventory, agent check-in status, patch state, monitors, and locations.
Liongard Cross-Client Census
Answer "which clients run <system>?" across the book via Liongard launchpoint inventory: install-base census for zero-days, EOL waves, vendor risk.
Liongard Datto RMM Read
Interrogate a client's Datto RMM footprint via Liongard: managed device inventory, agent online status, patch state, monitored alerts, and sites.
Liongard Duo Read
Answer Duo MFA posture questions via the Liongard Duo inspector: enrollment coverage, bypass users, admin list, and protected-integration inventory.
Liongard Email Security Config Read
Read a client's Mimecast/Proofpoint-class email security config via Liongard: policy posture, connector state, and config drift without admin console.
Liongard Exchange On-Prem Read
Interrogate on-premises Microsoft Exchange via Liongard: server version/CU/build, databases, mailbox inventory, connectors, and admin access review.
Liongard FortiGate Read
Interrogate a client's FortiGate via the Liongard Fortinet inspector: FortiOS firmware, policy changes, VPN tunnels, admin accounts, license state.
Liongard Google Workspace Read
Answer Google Workspace tenant questions via Liongard: super admin roles, 2SV coverage, license usage, and Drive-sharing posture for Google clients.
Liongard Hyper-V Read
Interrogate a client's Hyper-V hosts via Liongard: host and VM inventory, checkpoint sprawl, replica health, and VM placement and power state.
Liongard Internet Domain & TLS Read
Answer domain, DNS, and TLS questions via Liongard Internet Domain and TLS inspectors: registrar, expiry, DNS changes, mail-auth records, cert sweeps.
Liongard JumpCloud Read
Interrogate a client's JumpCloud directory via Liongard: users, MFA enrollment, admins, groups, bound systems, and SSO app assignments for reviews.
Liongard Kaseya VSA Read
Interrogate a client's Kaseya VSA footprint via Liongard: managed agent inventory, online status, patch state, monitor sets, and machine groups.
Liongard M365 Tenant Read
Answer tenant-level Microsoft 365 questions via the Liongard M365 inspector: license assignment, mailbox stats, admin roles, secure score, sharing.
Liongard Meraki Read
Interrogate a client's Cisco Meraki org via the Liongard Meraki inspector: SSIDs, VLANs, firmware, admin list, device inventory, and license state.
Liongard Mimecast Read
Interrogate a client's Mimecast tenant via Liongard: managed domains, users and licenses, policies, connectors and routing, and admin accounts.
Liongard N-central Read
Interrogate a client's N-able N-central footprint via Liongard: managed device inventory, agent/probe status, patch state, monitored services, sites.
Liongard Network Documentation Sync
Diff what Liongard inspectors see (firewalls, switches, wireless, hypervisors, servers) against the doc platform and draft network-doc corrections.
Liongard Okta Read
Answer Okta tenant questions via the Liongard Okta inspector: app assignments, admin roles, MFA policies, and deactivated-user hygiene reviews.
Liongard Palo Alto Read
Interrogate a client's Palo Alto firewall via Liongard: PAN-OS version, config changes and commit history, admin activity, HA state, policy posture.
Liongard pfSense Read
Interrogate a client's pfSense firewall via the Liongard pfSense inspector: version, interfaces, firewall/NAT rules, VPN config, packages, admins.
Liongard Proofpoint Read
Interrogate a client's Proofpoint Essentials tenant via Liongard: protected domains, users and licenses, filtering policy, spooling, and admins.
Liongard QBR Evidence Pack
Assemble QBR-grade posture evidence for one client from Liongard inspectors: identity risk, EOL exposure, cert/domain hygiene, and config drift.
Liongard SentinelOne Read
Interrogate a client's SentinelOne tenant via Liongard: protected agents, agent/version health, threat detections, policy/site assignment, admins.
Liongard SonicWall Read
Interrogate a client's SonicWall via Liongard: SonicOS firmware, security-services licensing and expiry, access rules, VPN policies, admin accounts.
Liongard Sophos Central Read
Interrogate a client's Sophos Central tenant via Liongard: protected endpoints, threat/health status, tamper protection, policy, and admin list.
Liongard Sophos Firewall Read
Interrogate a client's Sophos Firewall (XG/SFOS) via Liongard: firmware, firewall rules, port-forwards/NAT, VPN config, interfaces, admin access.
Liongard UniFi Read
Interrogate a client's Ubiquiti UniFi controller via the Liongard inspector: device inventory, adoption state, firmware drift, and WLAN/network config.
Liongard Veeam Posture Read
Interrogate a client's Veeam deployment via Liongard: job inventory and schedules, repository capacity, protected-VM census, and license state.
Liongard VMware Read
Interrogate a client's vCenter/ESXi estate via Liongard: host versions and build levels, datastore capacity, snapshot sprawl, VM inventory/placement.
Liongard WatchGuard Config Read
Interrogate a client's WatchGuard Firebox posture via Liongard: Fireware version, subscription/licensing, policy inventory, VPN config, admin accounts.
Liongard Webroot Read
Interrogate a client's Webroot GSM console via the Liongard Webroot inspector: protected endpoints, agent status, threat state, policy, and sites.
Liongard Windows Server Read
Interrogate a client's Windows Servers via Liongard: installed roles, local admin members, services, patch level, OS version and end-of-life flags.
Mobile Fleet Review
Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.
Monthly Security Report
Produce a client's monthly security digest: incident and alert counts, notable events, posture trend, and recommendations for client or internal review.
Network Device Inventory
Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.
NIST CSF Gap Brief
Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.
Patch Compliance Review
Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.
QBR & SBR Prep
Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.
RAID Degradation Alert
Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.
RDS / AVD Troubleshooting
Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
Sage 50 / Sage 100
Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.
SD-WAN / Multi-Circuit Monitoring
Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
Server Decommission Runbook
Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.
Server Diagnostics
Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.
Switch VLAN and Port Change
Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.
Tenant Onboarding Checklist
Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.
Typosquat Domain Alert
Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.
Warranty and EOL Report
Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.
WiFi Infrastructure Audit
Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.
NinjaOne
Acronis Cyber Protect
Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.
Alert Reset With Note
Reset a NinjaOne alert only after the condition is genuinely healthy, posting an explanation note first. Attended or embedded in a recovery Flow.
AV/EDR Agent Offline Alert
Triage an AV/EDR agent-offline alert — decide if the device is off or up with a dead agent, quantify unprotected time, and route on the protection gap.
Axcient Backup Alerts
Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.
Backup Failure Triage
Classify a backup failure by alert text and device state, check for recurrence, and decide whether to fix locally or escalate to the backup vendor.
Backup Missed vs Failed Alert
Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.
BSOD Analysis
Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.
Budget Planning Brief
Prep a client's annual IT budget conversation — hardware refresh forecast, license spend, and project pipeline — from tickets, assets, and roadmap items.
Client-Facing Device Report
Produce a sanitized device inventory and health report a client contact can read — counts, health, risks in plain business language, no raw tool output.
Conference Room AV
Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.
Cyber Insurance Form Prep
Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.
Datto BCDR Verification
Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.
Device Approval Review
Work the RMM pending-device approval queue — sort expected onboarding or replacement agents from unexpected ones, approving or rejecting with rationale.
Device Health Check
Diagnose one device via the RMM — alerts, activities, services, disk, reboot, and patch posture — then propose remediation with a deep-link handoff.
Device Offline Runbook
Work a device-offline alert or "won't connect" ticket — site-wide check first, maintenance windows, last activities, and clear escalate criteria.
Device-to-User Mapping
Answer "who uses this device" by combining RMM last-logged-on data with contact records, ticket history, and documentation when a ticket names only one.
Disk Space Alert
Triage a low-disk-space alert from any monitor — separate threshold noise from real pressure, read growth rate from history, rank consumer hypotheses.
Disk Space Remediation
Work a disk-pressure alert or full-drive ticket — identify likely consumers from RMM signals and give the tech a safe cleanup sequence with a device link.
EDR Detection Runbook
Work an EDR malware or suspicious-process alert: pull RMM device context, check EDR containment, confirm with the user, then escalate or close.
Endpoint Encryption Audit
Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.
Fleet Health Sweep
Sweep a client fleet through the RMM — offline devices, alert clusters, disk pressure, and missing patches — ranked into the top issues needing attention.
Hardware Diagnostics
Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.
Hardware Refresh Forecast
Build a 4–5 year hardware refresh workbook per client — devices crossing the age threshold each period and the per-client refresh budget for planning.
High CPU/Memory Alert
Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure via history, and route servers versus workstations differently.
Huntress EDR Incident
Work Huntress EDR incident reports: foothold, persistence, or active endpoint threats. Read what Huntress isolated, finish remediation, and verify closure.
Hypervisor Alert Triage
Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
IT Roadmap Builder
Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.
License Billing Reconciliation
Reconcile a client's billing against reality — RMM devices, license export, onboarding tickets — to find missed adds, missed removals, and discrepancies.
Mac Fleet Management
Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.
Maintenance Mode Workflow
Put a device into or out of RMM maintenance mode with an explicit duration and reason, plus a follow-up task so monitoring is re-enabled on schedule.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
Mobile Fleet Review
Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.
NAS / File Share Provisioning
Plan and document a new network share — folder structure, permission model, quota, backup inclusion — with an approval gate on the access model first.
Network Device Inventory
Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.
Network Outage Triage
Triage a suspected site-down — all-devices-offline vs single dead device, ISP vs internal, who to call, and set a comms cadence for the client updates.
New Workstation Imaging Checklist
Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff.
NinjaOne Alert Types
Classify NinjaOne condition and threshold alerts (offline, resource, service, patch, hardware, security) and route each class with a deep-link handoff.
NinjaOne Device Lookup from a Ticket
Figure out which device a ticket is about — from the person, their remembered devices, or a hostname in the thread — find it in NinjaOne, and drop the live device details and a deep link into the ticket so the tech starts with context.
Patch Compliance Review
Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.
Patch Failure Alert
Triage a patch-failure alert — separate a one-off from a repeat offender, detect reboot-pending as the usual culprit, correlate against the patch window.
Print Server Management
Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.
Printer Fleet Review
Cluster a client printer-related tickets to find chronic devices, quantify the time they burn, and recommend replace-vs-repair per problem printer.
QBR & SBR Prep
Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.
RAID Degradation Alert
Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.
Ransomware Response
Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.
Reboot Request Workflow
Reboot a device via the RMM with user approval — confirm logoff or saved work, choose normal vs forced deliberately, and verify the device comes back up.
Recurring Maintenance Tickets
Verify scheduled maintenance tickets (backup checks, patch cycles, monthly server reviews) carry real completion evidence and flag skipped cycles fast.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
SD-WAN / Multi-Circuit Monitoring
Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.
Seat Count True-Up
Monthly true-up for per-seat and per-device agreements — compare actual counts from RMM and onboarding tickets against billing, and produce evidence.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
SentinelOne Ranger
Work SentinelOne Ranger network-discovery findings: read the rogue or unmanaged-device signal and drive to identify-then-manage without blind action.
SentinelOne Threat Verdict
Triage SentinelOne threat detections: read static vs behavioral engine verdicts, direct kill, quarantine, rollback, and hold on exclusion requests.
Server Decommission Runbook
Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.
Server Diagnostics
Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.
Server Patch Windows
Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.
Service Restart Runbook
Restart a crashed Windows service via the RMM — allowlisted safe services only, state verified before and after, with a ticket note posted on completion.
Slow Computer
Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.
Sophos Endpoint Alerts
Triage Sophos Central endpoint alerts: read health status and cleanup result, handle tamper protection correctly, and verify cleanup before closing.
Storage Capacity Planning
Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.
Ticket Research Copilot
Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.
Veeam Job Failures
Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.
Vulnerability Report Triage
Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.
Warranty and EOL Report
Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.
Warranty Claim Handling
When a device fails and you need to know whether it's under warranty, how to file the claim, and how to arrange a loaner while it's away.
WatchGuard Firewall Alerts
Triage WatchGuard events: Firebox offline in WatchGuard Cloud, AuthPoint MFA push and token trouble, and mobile VPN authentication failures on the desk.
Webroot Legacy AV
Work Webroot or other legacy signature-AV detections with thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.
WiFi Heatmap / Site Survey Request
Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.
WiFi Infrastructure Audit
Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.
Windows 11 Readiness Assessment
Assess which client devices can upgrade to Windows 11 — CPU generation, TPM, RAM, and edition flags from RMM device details — with an upgrade-blocker list.
Windows Profile Corruption
Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.
Zero-Day Emergency Response
Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.
Zapier
Automation Failure Watch
Detect automation-error signatures in notes — 4xx/5xx bodies, Jinja errors, webhook failures — flag the ticket and ping Teams so broken flows get noticed.
Billing Forensics
When someone asks "why is the client billed X" and the charge needs to be traced to its source across tickets, time entries, agreements, and vendor invoices.
Calendar-Aware Scheduling
Put ticket work on a technician's schedule around their real calendar — check busy periods before proposing a slot, then book it onto the calendar.
CSAT Follow-Up Loop
Close the CSAT loop after ticket closure: confirm the survey went out, pull the response into the ticket as a note, and flag detractors to a lead.
Entra User Lifecycle (Zapier)
Create, update, or disable Microsoft Entra ID users through the Zapier connector with identity resolved from the PSA and approval gated on every write.
QuickBooks Invoice Draft
When time-and-materials work on a ticket is done and you want a QuickBooks invoice drafted from its time entries — created as a draft, never sent.
Sales Handoff Routing
Move a service ticket that turns out to be a sales conversation, a purchase, renewal, expansion, or pricing question, to the sales board and account owner.
Stripe Payment Link
When approved out-of-contract work needs to be paid and you want a Stripe payment link generated and placed in the ticket reply draft.
Weekly QA Digest
Compile the week's closure-QA failures into a digest with per-technician patterns and concrete training suggestions, ready to email or post to the team channel.
Zapier Action Discovery
META skill — before promising a workflow with an external app, verify a Zapier action exists, what fields it takes, and its task cost.
Zapier DocuSign Authorization
Send change-authorization or offboarding-acknowledgment for signature from a ticket via DocuSign, track completion, and file the signed document.
Zapier OneDrive User Files
Work a user's OneDrive during troubleshooting — fetch specific files, run KQL search for lost documents, and mint sharing links with hygiene.
Zapier Outlook Calendar Booking
Book remote sessions and onsite visits on the tech's Outlook calendar — Create Event with Teams link, attendees, ticket reference, mirrored in Thread.
Zapier Outlook Client Email
Send or draft email from shared mailboxes via Outlook and pull a requester's recent emails into ticket context for support conversations.
Zapier PagerDuty On-Call
Page the on-call engineer for a P1 via PagerDuty, tell the requester who was paged, and mirror the ack/resolve loop back to the ticket.
Zapier QuickBooks Time & Billing
Push ticket time entries into QuickBooks as Time Activities and draft (never send) an invoice for out-of-contract work, gated by approval.
Zapier SharePoint Ticket Filing
File ticket artifacts — reports, PIRs, signed docs — into the client's SharePoint library with correct foldering and sharing-link hygiene.
Zapier Slack Approval Request
Use Slack "Request Approval" as the human-in-the-loop gate before privileged or irreversible actions when the desk lives in Slack, not Teams.
Zapier Slack Escalation Ping
Ping the right engineer in Slack — DM or channel — with a one-line brief and ticket link when a ticket needs eyes now, with anti-nag dedupe.
Zapier Teams Approval Gate
Use Teams "Send Approval Request and Wait" as the human-in-the-loop gate before privileged actions — offboarding, admin changes, out-of-contract spend.
Zapier Teams Ticket Notifications
Post ticket updates and escalations into Microsoft Teams channels — client shared channels, internal escalations channel, or per-board feeds.
Zapier Webhook Generic
The escape hatch — fire a generic webhook (Rewst, custom automation, homegrown endpoint) from a skill when no named Zapier app covers the system.
Zapier Xero Billing
For Xero-shop MSPs — draft (never send) invoices from ticket time entries and check a client's overdue-invoice standing before billable work.
ConnectWise RMM
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
License Billing Reconciliation
Reconcile a client's billing against reality — RMM devices, license export, onboarding tickets — to find missed adds, missed removals, and discrepancies.
Mac Fleet Management
Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
Patch Compliance Review
Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
Seat Count True-Up
Monthly true-up for per-seat and per-device agreements — compare actual counts from RMM and onboarding tickets against billing, and produce evidence.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
Server Patch Windows
Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.
Vulnerability Report Triage
Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.
Zero-Day Emergency Response
Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.
Notion
Environment Facts Updater
When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.
Knowledge Base Taxonomy
Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.
New Hire Onboarding Coach
Interactive onboarding practice for new techs: walk a trainee through real tickets, have them draft the customer reply, and score it against a six-point response rubric.
Notion Change Log
Append approved changes to a queryable Notion change-log database — what changed, for which client, who approved, and the source ticket.
Notion Client Runbook Database
Create and maintain a Notion client-runbooks database, one entry per client per system, updating entries when tickets reveal environment changes.
Notion Intake Forms
Build a Notion form view for structured requests (new hires, access, project intake) and convert submitted rows into tickets without another vendor.
Notion Onboarding Tracker
Run a new-hire progress tracker in Notion — read trainee status, update checklist items and quiz results, and answer "how is <new hire> doing".
Notion QBR Page
Assemble a client QBR pre-read as a Notion page — ticket volume vs prior period, top issues, SLA picture, and recommendations with data views.
Notion SOP Publishing
Turn a resolved ticket into an SOP page in the team's Notion runbooks teamspace, tagged by client, product, and category, with link back to ticket.
Stale Doc Hygiene
Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.
TimeZest
Appointment No-Show Follow-Up
A client missed a scheduled appointment: log the no-show on the ticket, draft a courteous rebooking email, and apply the repeat-no-show policy on miss #3.
Reschedule Request Handling
A client asks to move an appointment: find the schedule entry or booking, propose new slots that actually work, update it, and confirm to the client.
Scheduling Intent Detector
Find "can we get on a call / book a time" requests hiding in recent tickets and route them to scheduling — skipping tickets where a tech has already engaged.
TimeZest Booking
Create a TimeZest scheduling request from a ticket — pick the right appointment type and resource, and drop the self-service booking link into the client reply.
WiFi Heatmap / Site Survey Request
Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.
Zapier Outlook Calendar Booking
Book remote sessions and onsite visits on the tech's Outlook calendar — Create Event with Teams link, attendees, ticket reference, mirrored in Thread.
Linear
Engineering Escalation to Linear
Escalate a ticket or recurring pattern to engineering as a Linear issue, with aggregated evidence and affected-client count, cross-referenced both ways.
Linear Release Notes
Turn a completed Linear cycle's issues into client-safe release notes and post fix notices to affected tickets. Close the loop on shipped bugs.
Linear Spec Lookup
Pull the PRD or spec from Linear documents to answer "is this a bug or by design" before escalating a suspected defect. Cite spec or confirm none.
ImmyBot
ImmyBot Environment Review
Review an ImmyBot tenant read-only — computers and maintenance-session history, what ran, what failed, and which machines keep failing on deployments.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
Was this page helpful?