Skip to main content
Every connector with skills built for it — expand one to see them. Thread skills need no connector at all.

Thread

1Password Business

Run 1Password Business admin work: vault and group structure, sharing discipline, the Emergency Kit, recovery groups, and suspend-then-recover offboarding.

Abnormal Security

Triage Abnormal Security email cases: read ATO and BEC behavioral signals, treat account takeover as an identity incident, finish auto-remediation gaps.

Access Request Handling

Work an access request for a folder, calendar, DL, or shared mailbox with approval checked, least privilege applied, and expiry on temporary grants.

Access Request Intent Design

Design an access-request intent for folders, distribution lists, and shared mailboxes — capture resource, justification, and approver on intake.

After-Hours Coverage Handoff

Build the end-of-business handoff to on-call or after-hours coverage — open urgent work, expected client callbacks, and site notes the night crew needs.

After-Hours Voicemail Digest

Build a morning digest of overnight voicemails and after-hours calls — urgent items first, callbacks owed with deadlines, and which tickets were created.

Aging, SLA & Follow-Up

Sweep open tickets for real staleness by last client-facing update, separate MSP stalls from legitimate waits, nudge techs, and drive clean closure.

Agreement Profitability

Compute the effective hourly rate on an all-you-can-eat fixed-fee agreement — agreement revenue divided by logged hours — or scan for loss-making clients.

Alert Storm Merge

Collapse a burst of identical alert tickets fired within a few hours into the earliest ticket as parent, so a flapping monitor does not flood the queue.

Alert Title Normalization

Classify a monitoring or security alert ticket and rewrite its title into the desk's standard format using a controlled vocabulary, with an internal note.

APC UPS Alerts

Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.

Apology With Remedy

Draft the message when the desk genuinely failed — specific acknowledgment, concrete remedy, and one prevention step, without groveling or overreach.

Approval Request Email

Draft an email to an approver requesting authorization for a password reset, install, purchase, or access change — what/why/risk/expiry in one read.

Approver Self-Skip

Before firing an approval, check if the ticket submitter is the client's designated approver — if so, skip send_approval and advance with an audit note.

Arctic Wolf MDR

Work Arctic Wolf MDR escalations: pick up where their SOC investigation ended and split response authority between Arctic Wolf and the MSP correctly.

Atera Workflow

Atera-synced desk playbook: ticket lifecycle, resolved-vs-closed nuance, contract types (retainer, block hours, monitoring, project), labor pricing.

Auto Priority Classification

Set a ticket's priority from its title and description against the partner's own priority definitions — built for alert boards and intake flows.

Automation Completion Auto-Close

When note evidence shows an intent or external automation finished the work, verify and auto-close the ticket — abort if any human message arrives after.

Automation Opportunity Finder

Mine recent tickets for repetitive manual work, estimate hours burned per pattern, and route each finding to a flow, intent, RMM policy, or training fix.

Automation ROI Report

Judge whether live automations earn their keep with tickets touched per flow, estimated time saved, noise created, and a keep, kill, or tune verdict each.

Autotask Contract Categories

Read Autotask contract type at triage (recurring, block, retainer, T&M, fixed) to label covered vs billable and add burn-down notes on hourly deals.

Autotask Contracts Blocks

Autotask contract mechanics: block-hour burn tracking, retainer-threshold alerts, and exclusions, overlapping contracts, and expired-contract edge cases.

Autotask Merge Simulation

Autotask has no merge API: dedupe tickets via a 5-step manual sequence — verify, pick survivor, cross-note, carry history, complete the source last.

Autotask Queue Management

Autotask queue model: queues are work pools, not workflow containers — route by moving tickets between queues with correct ownership semantics.

Autotask Service Call Scheduling

Autotask Service Calls: know when work is a scheduled visit object vs a plain ticket, and follow dispatch scheduling conventions so calendars stay right.

Autotask SLA Workflow

Autotask SLA event model — First Response, Resolution Plan, Resolved — with clock-pausing statuses and breach-risk assessment for synced desks.

Autotask Ticket Categories

Classify Autotask tickets with configured Issue Type + Sub-Issue Type pairs and ticket category/type — never invent classification values not in the board.

Auvik Network Monitoring

Triage Auvik network alerts: separate device-down, interface-down, and config-change events, and use the topology map to spot cascades early.

Bad Review Response Prep

After a poor CSAT score or negative review, prepare internal talking points plus an external response draft — facts only, zero defensiveness.

Billable Analysis

When someone asks how billable hours break down by technician, client, or period, or wants to see unbilled-work exposure from time entries.

Bitdefender GravityZone

Triage Bitdefender GravityZone alerts: identify the detection layer (AV, ATC, HyperDetect, EDR) and use Risk Analytics, quarantine, and rollback safely.

Bitwarden Business

Run Bitwarden Teams/Enterprise admin work: organization and collection structure, group-based sharing, account recovery, and offboarding vault handover.

Blackpoint SOC Response

Work Blackpoint MDR SOC calls: confirm what analysts contained (host isolation, account disable), finish the response, and merge companion ticket storms.

Board Routing Rules Engine

Route catch-all tickets to the right board (NOC, procurement, security, help desk) by walking a prioritized keyword-and-signal rule list to a result.

Breached Credential Response

Handle exposed user credentials: notify the user, drive password rotation across reused sites, and verify MFA is enabled before standing down.

Bulk Onboarding Coordinator

Coordinate a multi-hire onboarding wave with one parent ticket, child ticket per hire, and a consolidated status table kept current through cutover.

Bulk Ticket Operations

Safe procedure for bulk close, reassign, or update ticket operations: enumerate, eligibility check, chunked writes, audit notes, abort on anomaly.

Business Email Compromise Recovery

Recover from confirmed BEC: kill sessions and tokens, sweep mail rules and forwarding, notify downstream victims, and trace the fraudulent funds.

Business Value Summary

Summarize value delivered to a client this period in business terms — outcomes achieved, time saved, incidents prevented — as a client-facing story spine.

CAB Brief Builder

Build the weekly change advisory board pack: pending changes ranked by risk, collision flags, and last week's change outcomes for 20-minute CAB decisions.

Catchall Routing

Identify the correct client and contact for a ticket that landed in a catchall or no-company mailbox, including forwarded mail and vendor alert routing.

CEO Service Desk Brief

An owner or CEO asks for a review of the service desk — a business-level readout with trends, risks, and a decision to make, no ticket IDs.

Change Approval Sender

Flow that fires on Change Approval status: resolve the client's Change Approver and send_approval with the change summary — note-and-stop if unresolved.

Change Calendar Management

Check a proposed change window against freeze windows, client calendars, and other scheduled changes so collisions surface before the maintenance email.

Change Request Intake

Normalize a prose change request into a structured record (what, why, scope, when, rollback, risk) and route it to the right approval track before work.

Change Request Prerequisites

Validate a change request against the prerequisites template — justification, scope, rollback, window, approver — and bounce incomplete requests itemized.

Change Risk Assessment

Classify a change request as standard, normal, or emergency by scoring blast radius and rollback confidence so approval effort matches actual risk.

Chat-to-Ticket Conversion

Capture a live Messenger chat's context into a real ticket with title, description, contact, priority, and steps tried — no repeating for the user.

Churn Save Deep Dive

Analyze a client's churn intent using full ticket history to surface what went wrong, what worked, and honest talking points for win-back calls.

Client Health Report

Summarize a client's support health for a period — volume trend, recurring issues, noisy assets, SLA performance, and a few concrete recommendations.

Client RCA Summary

Draft a client-safe root-cause summary for a resolved issue — what happened, impact, cause, and prevention — written defensively for one ticket.

Client Reply

Draft an external client reply in your house voice and format — resolution updates, status notes, closing messages, or any client-facing email on a ticket.

Client Risk Scan

Scan the client portfolio for at-risk accounts using declining sentiment, aging tickets, recurring issues, and unresolved high-priority incidents; ranked.

Closure Note Completeness

Check a ticket's closure note against the house standard — issue, cause, actions, outcome, confirmation — and draft the compliant version when it's short.

Closure Recategorization

At resolution, re-read the thread and correct the ticket's type/subtype/item and category to match the actual work, using only configured board values.

Co-Managed Reference Exchange

Keep ticket references straight across a co-managed IT boundary — recognize the other side's number format, preserve foreign refs, and audit both-way links.

Compromised Account Containment

Rapid containment checklist for a compromised account: block sign-in, revoke sessions, reset password, sweep MFA and inbox rules, timestamp steps.

Conditional Access Exception

Exclude a user, app, or location from a conditional access policy with written risk note, approval, expiry date, and revert plan documented up front.

Connector Degradation

Base skill defining how a skill behaves when an integration it wants isn't connected — do the job with what's native, name the gap, never fake the missing source.

Contract Renewal Routing

Catch renewal and expiry notices in the service queue and route them to the right sales or account manager, retitled and moved with context attached.

COO Ops Review

An ops leader asks what the team is doing well and not so well — an honest, evidence-backed operations review of the service desk.

Cork Protection Posture

Handle Cork cyber-warranty posture signals: identify the required control that slipped and restore it to compliance before warranty coverage lapses.

Courtesy Reply Status Revert

When a thanks-only client reply flips a resolved ticket back to open, revert it to the correct status per a fixed per-board map — the only permitted write.

Cove Data Protection Alerts

Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.

Credential Stuffing Response

Investigate password spraying and credential stuffing patterns: scope the attack across tenants, lock down accounts, and rotate the ones that fell.

Cross-Client Outage Detector

Spot the same symptom appearing across multiple clients within a short window, flag a possible vendor or major incident, and propose a parent incident ticket.

CrowdStrike Falcon Alerts

Triage CrowdStrike Falcon detections: parse detection anatomy, decide when Network Contain is warranted, and spot mass endpoint failures as vendor-side.

CSAT Trends Report

Track CSAT scores over time by client, technician, or ticket category with honest treatment of response rates so a 3-response month isn't shown as 300.

CSM Weekly Ritual

A CSM or vCIO weekly account runbook: proactive outreach, sentiment-decline watch, meeting prep for the week's calls, and an expansion-scan skim.

Custom Time Entry Writer

Summarize thread activity within the active timer window using a recap template, preview the draft, then log the time entry on confirm.

CW Agreement-Aware Triage

ConnectWise Manage triage: read the client's CW agreement type at intake and route or label the work as covered vs billable before anyone touches it.

CW Project Tickets

Recognize ConnectWise Manage project tickets, understand the project → phase → ticket structure, and work within what Thread sees of the Projects module.

CW Service Board Conventions

ConnectWise Manage multi-board desks: pick which board work belongs on and execute cross-board moves without losing status, classification, or history.

CW Status Workflow Mapping

ConnectWise Manage status mapping: align Thread statuses with CW board statuses, take safe transitions, reconcile closed-in-CW-but-open-in-Thread drift.

CW Sync Lag Audit

Sweep Thread ↔ ConnectWise Manage divergence — status, owner, board mismatches — separate real drift from sync lag, and reconcile with CW as the master.

CW Time Entry Conventions

ConnectWise Manage time entries that survive sync: correct work role/type, deliberate billable flag, agreement application, and plain-text notes.

CW Type / Subtype / Item Classification

Classify ConnectWise Manage tickets with the three-level Type → Subtype → Item taxonomy using only values configured on the board — never invented ones.

Dagelijkse samenvatting (Dutch)

Dagelijkse samenvatting van openstaande tickets van een technicus: wat wacht op antwoord, wat is urgent, wat staat vandaag gepland, met 3-regelvariant.

Daglig oversikt (Norwegian)

Daglig oversikt over en teknikers åpne saker: hva som trenger svar, hva som haster, hva som er planlagt i dag, med ultrakort 3-linjers variant.

Daily Digest

Summarize a technician's open tickets in under a minute with what needs a reply, what's urgent, what's scheduled today, plus a 3-line ultra-short option.

Daily Leadership Digest

A service leader asks what needs their attention today — escalations, SLA breaches, at-risk clients, and staffing flags in one short daily view.

Dark Web Alert Lifecycle

Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.

Day Planner

Plan a technician's day around calendar and queue, honoring shift end and timezone, producing a realistic time-blocked plan and not just priorities.

De-escalation Reply

Draft the response to an angry client message — acknowledge, own what's ours, commit to a concrete next step with a time, without matching their tone.

Dead-Air Call Filter

Detect and close voice sessions that were dead air, instant hangups, or robocalls so they don't pollute the queue — human speech means it isn't dead air.

Deep Recap

Build a full ticket recap covering messages, notes, time entries, related sibling tickets, timeline, and current blockers — beyond the default summary.

Default Contact Autofill

When a ticket arrives with no contact, look up the company's documented default contact, confirm with a search, and assign under a confidence gate.

Defender M365 Alerts

Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.

Defender Quarantine Ops

Review Microsoft 365 Defender quarantine items and release requests using Defender portal paths, verdict types, and disciplined release mechanics.

Defensive Writing Standard

Language standard for security writing: use when drafting client notifications, incident updates, postmortems, and alert closures to avoid overstatement.

Delay Apology

Draft an honest acknowledgment that a ticket has taken too long or a commitment slipped — apology without excuses, new commitment only if confirmed.

Delegate Access Forensics

Investigate mailbox audit logs to identify Send As, Send on Behalf, and owner actions in delegation disputes and unauthorized-email claims.

Difficult News Delivery

Draft the message no one wants to send — data loss, unrecoverable state, security exposure — factual, empathetic, and pointed at the path forward.

Dispatch & Workload

Give a dispatcher the full queue picture: unassigned tickets by priority and age, open work per tech, lightest-load proposals, and a daily audit.

Dispatch Control Tower

The dispatcher's live picture in one view — unassigned queue, at-risk tickets, today's scheduled work, and which technicians are free to pick up right now.

Dispatcher Morning Ritual

A dispatcher's board-open runbook: morning dispatch report, clear unassigned via workload balancing, SLA-risk check, and yesterday's assignment audit.

Distribution List Management

Add or remove distribution list members with owner approval and a documented reason logged on the ticket, keeping email groups clean and auditable.

DLP Alert Triage

Triage a DLP alert: separate business-process false positives from real data exfiltration signals, investigating with respect for employee privacy.

DNS Filtering Alerts

Handle DNS-filter block events from Cisco Umbrella, DNSFilter, and similar tools: separate security blocks from category blocks, keep bypass discipline.

Duo MFA Anomalies

Work Duo MFA events: fraudulent pushes, push-fatigue patterns, device re-enrollment, bypass codes. Verify identity and time-box every bypass grant.

Duplicate Hunter

Check whether a ticket duplicates an existing open ticket for the same client, contact or asset, and symptom — and merge only on an exact reference match.

Easy Win Finder

Surface quick-win ticket candidates from the queue that match the requesting technician's skills, with a short reason each one is fast to close.

Email Baseline Standard

The base client-email standard other communication skills build on — structure, tone rules, and placeholder discipline for every outbound message.

Email Header Analysis

Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.

Emergency Change Handling

Run break-glass discipline for an emergency change: minimal in-flight record, act-then-document, then chase full retro documentation to done in 24 hours.

Employee Offboarding

Securely disable a departing employee in the right order: sign-in and sessions first, mailbox before licenses, then reclaim access, assets, and MFA.

End-of-Day Wrap-Up

End-of-day sweep for a technician: stale tickets over 24h, awaiting-client with no follow-up, status mismatches, and tomorrow's first moves lined up.

EOD Closed Ticket Audit

End-of-day quality sweep of every ticket closed today against the closure rubric: resolution, docs, classification, time, message, with pass/fail summary.

Escalation Advisor

Sweep active tickets against L2/L3, management, and project-conversion trigger lists and recommend which should escalate — before they age into problems.

Escalation Completeness Gate

Review tickets entering Escalation Requested status against the escalation checklist and bounce incomplete ones back to the tech with itemized feedback.

Escalation Prep

Build a complete escalation package so a senior engineer, TAM, or third party can pick the ticket up cold, or recommend whether a ticket should escalate at all.

Escalation Risk Radar

Scan open tickets for the early signs of a blow-up — negative sentiment, an SLA deadline closing in, and threads that have gone quiet — score and rank them, so a senior tech can step in before a client escalates.

ESET PROTECT

Triage ESET PROTECT detections by engine, interpret LiveGuard sandbox verdicts, and recognize when a protection-disabled alert is really a policy conflict.

ESL Drafting Assistant

Grammar and idiom cleanup for technicians writing in non-native English — "fix my English" or "mejorar ingles," technical content untouched.

Exec Weekly Ritual

An owner or exec's 20-minute weekly runbook: exec scorecard, resolve one decision ask, and review what has been escalated to me across the service desk.

Expansion Opportunity Scan

Mine a client's ticket history for expansion signals — recurring issues that justify a project or upsell, and training gaps that justify a service offering.

Expectation-Setting Acknowledgment

Draft the first-touch acknowledgment on a new ticket — what we understood, how seriously we're treating it, next steps, and when the client hears back.

Field Visit Scheduler

Schedule an onsite visit and make the trip count: sweep other open onsite-worthy tickets at the same site, group travel, book, confirm the client.

First Contact Resolution Report

Report the desk's FCR rate, the share of tickets resolved by first assignee with no handoffs, with the definition stated to prevent later disputes.

Flow Backup Export

Dump every flow definition to a JSON or markdown snapshot for archive and diffing — a read-only point-in-time backup of the desk's automation, no restore.

Flow Builder

Design an automation flow from a plain-English ask — trigger, filters, actions, notification channels — with a dry-run description before it is created.

Flow Bulk Editor

List the desk's flows, present the target set, then bulk enable, disable, or rename them in one confirmed pass — no editing each flow by hand.

Flow Debugger

Diagnose why a flow or intent didn't fire on a ticket — filters vs actual attributes, flow ordering, board scoping, and trigger-event mismatch.

Flow Note Personalizer

Replace a Flow's static "add note" text with an AI step that resolves the real owner and ticket context to compose a note with actual names and specifics.

Follow-up Chaser

Draft a polite, escalating follow-up when a client hasn't replied on a ticket — first nudge, second nudge, or final pre-closure attempt with tone.

Group Membership Request

Handle a security group membership change by stating what the group actually grants, getting the right approver, and setting a review date on the change.

Halo Actions & Workflows

HaloPSA actions and workflows beyond status changes: approval actions, multi-step workflows, and which action is valid at the ticket's current step.

Halo Agent Teams

HaloPSA team and section routing: team selects the pool, agent selects the person, and unassigned-within-team is a legitimate state — not an error.

Halo Recurring Tickets

HaloPSA recurring tickets and parent/child structures: work the generated instance, never the template, and respect parent/child closure rules on sync.

Halo SLA and Priorities

HaloPSA SLA and priority interplay: priority sets response and fix targets within the client's SLA, and configured hold statuses pause the clock.

Halo Status Actions

HaloPSA transitions run through configured Actions, not raw status edits — pick the action that fires the right status, note visibility, and notifications.

Halo Sync Audit

Sweep Thread ↔ HaloPSA divergence — especially the known pattern of statuses not carrying over — and reconcile toward Halo as the master system.

Health Score Reconciliation

Reconcile a client's own health or satisfaction scores against our ticket reality — where their perception and our data agree, and where they diverge and why.

How-Do-I Self-Help Router Intent Design

Design the catch-all "how do I" self-help router intent: classify the how-to, serve the matching end-user guide or KB article, escalate only if no match.

Huntress ITDR Alerts

Work Huntress ITDR identity reports: unwanted access, rogue apps, mail-rule anomalies. Verify with the user and drive the remediation-approval flow closed.

Inbox Rule Alert Runbook

An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.

Incident Commander Brief

Assemble a handoff brief for an incoming incident commander: timeline, workstream states, comms state, and the next decision point in a single read.

Incident Comms Cadence

Draft internal and client updates on a fixed clock during a major incident from ticket evidence, tracking the next-due time so the cadence never lapses.

Intake Classification Tree

Walk a new ticket through the Incident, Request, or Problem decision tree and recommend a matching type, subtype, and item for consistent classification.

Intent Builder

Build or update a customer-facing intent — trigger phrases, arguments, replies, and per-client variations — with a test plan before anything goes live.

Intent Bulk Variation Update

Apply a shared argument or reply block across every client variation of an intent at once, with per-variation diff preview and explicit write confirmation.

Intent Mining

Analyze recent tickets to find top customer-facing intents worth building, ranked by volume and automatability, with draft trigger phrases for each pick.

Intent Setup Walkthrough

Walk through building a new Triage Agent intent from scratch — check it doesn't already exist, then set the name, description, trigger variations, replies, and any arguments — so a new automatic response is set up cleanly and without duplicates.

Invoice Dispute Investigation

When a client disputes an invoice line, reconstruct the work evidence from tickets and time entries, then draft a factual response backed by the record.

IRONSCALES Phishing

Work IRONSCALES phishing incidents and user banner reports: mailbox-level detection, automated remediation, and correct model-training feedback.

JSON API Response Pattern

Base skill for machine integrations: when an external system calls Super Magic and parses the reply, respond with only a raw JSON object matching schema.

Kaseya BMS Workflow

Kaseya BMS-synced desks: navigate the status/queue/location model, respect the service-desk vs projects split, and audit Thread ↔ BMS drift regularly.

Kaseya Dark Web Monitoring

Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.

Keeper Password Manager

Run Keeper Security admin work: vault and shared-folder structure, role-enforced sharing, break-glass access, and offboarding via Account Transfer.

Klantantwoord (Dutch)

Extern klantantwoord opstellen in de huisstijl: oplossingsupdates, statusberichten, afsluitende berichten of elke klantgerichte e-mail op een ticket.

KnowBe4 Awareness & PhishER

Run a KnowBe4 program: awareness training, phishing simulations, and triage user reports through PhishER and the Phish Alert Button without collisions.

Known Error Database

Maintain the KEDB with every known error in one findable symptom, cause, and workaround format — deduplicated on arrival and retired when the fix ships.

Kundenantwort (German)

Kundengerichtete Ticket-Antwort in der Hausstimme entwerfen: Statusupdates, Zwischenstand, Abschlussnachricht oder jede E-Mail an den Kunden.

Kundesvar (Norwegian)

Utkast til eksternt kundesvar i husets stemme og format: løsningsoppdateringer, statusmeldinger, avslutninger eller enhver kunderettet e-post på en sak.

Laptop Return Logistics

Get a company laptop back from a departing or remote user with prepaid return label, templated email, deadline tracking, wipe verification, and escalation.

LastPass Migration

Run a LastPass migration-away: export, import to a new vault, rotate every secret, decommission the account, and handle the breach-history talk with facts.

Lead Daily Ritual

A service manager's daily runbook: leadership digest, escalation queue pass, silent-ticket sweep, and one coaching observation captured for the team.

License Cost Optimization

When someone wants to find unused, duplicate, or oversized licenses for a client and get downgrade/reclaim recommendations with a savings estimate.

License Lifecycle

Assign or reclaim software licenses by checking for unused seats before buying and leaving a billing note on every change so client spend stays accurate.

Litigation Hold

Place or manage a legal hold on a user mailbox and data with scope confirmed by an authorized requester and no user notification unless counsel approves.

Live Call Transfer Brief

One-minute brief for transferring a live in-progress call to another technician — caller context, what's been tried, sentiment alert, and a verbal opener.

Live Chat Etiquette

House rules for working a live Messenger chat — response cadence, holding messages, handoff phrasing, and ending the chat cleanly for the desk playbook.

Lost or Stolen Device Response

Respond to a lost or stolen laptop or phone: decide lock or wipe, assess exposed data and access, and drive carrier or police steps with approval gates.

M365 SaaS Backup

Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.

Mail Flow Reports

Produce periodic Exchange Online mail flow health summaries: volume trends, spam/malware catch rates, top senders, connector health, forwarding.

Mail Forwarding Audit

Inventory every mail forwarding path in a tenant or mailbox: mailbox forwarding, inbox rules, and transport rules, treating external forwarding as risk.

Mail Trace Investigation

Run disciplined Exchange Online message traces with tight timeframes, sender/recipient pairs, verdict reading, and historical traces beyond 10 days.

Mailbox Permissions Audit

Inventory Exchange mailbox access grants: Full Access, Send As, Send on Behalf, and folder-level permissions, flagging unexpected delegations.

Maintenance Freeze Windows

Record and enforce client freeze calendars (tax season, go-lives, retail peak) so freezes block change scheduling unless a documented exception is signed.

Maintenance Window Notice

Draft a planned-work client notice — what's happening, when, expected impact, duration, and rollback promise — for patching, upgrades, or migrations.

Major Incident Declaration

Run the criteria check, declare or explicitly decline a major incident, assign incident roles, and start the comms clock from one declaration checklist.

Management Escalation Brief

When a client requests escalation to management, prep the leader taking the call with a timeline, an honest account of our misses, and a recovery plan.

Meeting Prep Brief

Rapid pre-meeting brief on a client — open items, recent wins and misses, sentiment, likely topics, and landmines — for meetings starting in 30 minutes.

Merge Duplicate Tickets

Find duplicate tickets — a client who wrote in twice, a re-forwarded alert, the same issue split across threads — confirm they're really the same, and merge them into one so the desk works a single thread.

Messenger Deployment Audit

Report which clients use Messenger versus which are entitled — deployed and active vs. silent — surfacing adoption gaps worth a rollout conversation.

Messenger Outage Banner

Draft, update, and retire the Messenger client-facing incident banner with factual wording, no cause speculation, and hard expiry for stale text.

MFA Fatigue Attack Response

Respond to MFA push bombing and fatigue attacks: treat the password as known, contain the account, and enforce number-matching so approval spam fails.

Mimecast Email Gateway

Work Mimecast gateway events: held-message release requests, URL Protect click alerts, and impersonation-protect hits. Treat allowed clicks as incidents.

Monitoring Companion Merge

Merge companion tickets that multiple monitoring tools opened for the same event on one device, folding them into a single parent within a time buffer.

Morning Briefing

A start-of-day briefing across your tiered support boards — every open human ticket grouped and flagged (unassigned, aging, SLA risk), with the alert/automation noise filtered out, a quick-stats table per board, and the day's key follow-up actions, all in one scannable report.

Morning Dispatch Report

The dispatcher's start-of-day briefing: overnight arrivals, P1/P2 status, unassigned aging, today's scheduled work, and a top-10 priority work list.

Morning Huddle Builder

Build the daily standup or morning huddle message — yesterday's P1s, overnight items, today's SLA risks, and shout-outs — ready to read out or paste.

MSA Change Management

Work through what an MSA change in tier, scope, seats, or sites means operationally: desk updates, notifications, and how effective dating is handled.

Multi-Issue Ticket Splitter

Detect when one ticket bundles two or more distinct problems and split it into cross-linked sibling tickets, one purpose each, with tech confirmation.

Multilingual Reply

Draft the client reply in the client's own language — detect it from their messages, write natively, and provide an English back-translation to verify.

My Queue Summary

Summarize a technician's assigned tickets showing what needs replies, what is urgent, and what to work next, with a clear next step attached to each item.

New Client 30-Day Review

Friction check on a new client's first 30 days — early recurring issues, expectation mismatches, and onboarding gaps — fixed while the relationship forms.

New Hire Intent Design

Design the new-hire onboarding intake intent: collect the full checklist up front so the ticket arrives complete and routes into the onboarding workflow.

New Hire Onboarding

Run a new-hire onboarding end to end with role-based accounts, licenses, groups, hardware, and MFA driven from the client's own onboarding checklist.

New Ticket Approval Gate

Configured clients require the designated approver to authorize work on every new ticket — fire send_approval on intake, hold, and record the outcome.

New Ticket First Touch

One-pass first touch on a new ticket: classify it, check duplicates, pull similar resolved tickets, and draft an acknowledgment for the tech to review.

New User Created Alert

Investigate an unexpected user or admin account creation in a client tenant: check for an authorizing ticket and contain if no one can claim it.

No-Response Closure Sequence

Close a ticket after a client goes silent following three documented contact attempts: send the templated final message, close with a reopen-invite note.

Noise Auto-Close

Close pure-noise tickets — bounce-backs, vendor auto-replies, thanks-only messages, reconnected offline alerts — behind independent stop conditions.

Note Format Standard

Base skill defining the house format, tone, and plain-text PSA-sync rules for internal ticket notes. Other documentation skills reference this standard.

OAuth Consent Grant Abuse

Remove a malicious or over-privileged OAuth consent grant from a client tenant: identify the grant, revoke it, and tighten tenant consent policy.

Offboarding Completeness Audit

Post-offboarding sweep for licenses still assigned, live delegations, unreturned devices, lingering MFA methods and sessions, and external share links.

Offboarding Intent Design

Design the employee-termination intake intent with an authorized-requester check and urgency handling built in from the start for offboarding tickets.

Onboarding Plan Builder

Draft a new tech's onboarding curriculum from the desk's own resolved tickets — the request types they'll actually face, in real volume order, with practice tickets per phase.

One-on-One Prep

A manager is preparing for a 1:1, 30-day check-in, or coaching conversation with a technician and wants a candid brief on their recent work.

One-Shot Ticket Workup

Get fully caught up on an in-flight ticket with a recap, suggested next step, drafted reply, and drafted time entry, previewed before anything is posted.

Out-of-Office on Behalf

Set automatic replies on an absent user's mailbox by request: manager or HR authorization verified, message kept minimal, and an end date set.

Out-of-Scope Billing Flag

Flag a ticket that looks like work outside the client's agreement — projects, installs, non-covered users — with a quote path, not silent free work.

Outage Notification

Draft a major-incident or mass-outage client notice — known impact, what we're doing, when the next update comes — without speculating on cause.

Password & MFA Recovery

Reset a password or recover MFA with an identity verification ladder, locked-versus-disabled account check, and secure delivery of the new credential.

Password Reset Intent Design

Design the password-reset intent — the top deflection target on most desks — with an SSPR-first reply path and a strict identity-verification handoff.

Phishing Simulation Program

Plan a client phishing-awareness simulation: scope, cadence, lure difficulty, a no-shame reporting culture, and desk triage that doesn't collide.

Phishing Triage

Triage a reported phishing email without touching the payload: check blast radius, contain if malicious, and reply to the reporter with a verdict.

Phishing-Triage (German)

Phishing-Triage einer verdächtigen E-Mail: Bewertung ohne Nutzlast, Streuradius prüfen, bei Böserkennung eindämmen, Melder mit Urteil antworten.

Phishing-triage (Norwegian)

Phishing-triage av en mistenkelig e-post: vurder uten å røre nyttelasten, sjekk spredningsradius, inneslutt hvis skadelig, svar melderen med konklusjon.

Phishingtriage (Dutch)

Phishingtriage van een verdachte e-mail: beoordelen zonder payload aan te raken, verspreiding controleren, isoleren bij kwaadaardigheid, oordeel geven.

Pod-Based Dispatch

Route a ticket to the least-loaded technician in the client's assigned service pod: read the pod from company record, load-balance, assign, and note it.

Post-Churn Autopsy

After a client terminates, reconstruct causes from ticket evidence, extract lessons, and identify early-warning signals so the next churn is caught early.

Post-Incident Action Tracking

Turn post-incident review action items into real tickets with owners and due dates, then run the follow-through audit that catches ones dying in backlog.

Post-Mortem & RCA Author

Write a structured post-mortem or root-cause analysis from an incident ticket — executive summary, event timeline, impact, root cause, and action items.

Premature Confirmation Detector

Catch tickets closed on assumption without customer confirmation — work summaries treated as sign-off, closes minutes after last change — then reopen.

Price Increase Letter

Draft the client notice for an agreement price change — value-first framing, effective date, honest rationale — gated behind account-manager approval.

Printer Issues Intent Design

Design the printer-problems intent: three top self-help fixes first, then an escalated ticket that already carries the diagnostics collected from the user.

Priority Downgrade Guard

On a priority change, if AI triage lowered a priority a human or client explicitly set higher, restore the higher priority — deterministic, restore only.

Problem Record Lifecycle

Drive a problem record through its states — opened from an incident cluster, investigating, known error, then fixed or accepted-risk closure.

Problem Ticket Creation

When an incident recurs past threshold, create a problem/RCA ticket linking the incidents and documenting the workaround so the pattern gets a real owner.

Procurement Quote Request

When a ticket needs hardware or software purchased and you want a structured quote-request note (specs, quantity, budget, needed-by) plus a vendor email draft.

Project Conversion Inbox Cleanup

When a ticket is converted to a project or moved to a project board, set the attribute that removes it from live inbox and queue views so dispatch is tidy.

Project Profitability

Check whether a fixed-fee project is on budget — logged hours versus budgeted hours, burn alerts at 70% and 90%, and documented evidence of scope creep.

Proofpoint Email Security

Work Proofpoint email security events: TAP click alerts, attachment-sandbox verdicts, quarantine-digest release requests, and VAP-driven priority triage.

PSA Billing Cycle Prep

Month-end PSA billing readiness sweep: find unposted time, done-but-open tickets, and agreement anomalies before finance runs invoices — clean handoff.

PSA Closed Status Taxonomy

PSA closed-status taxonomy (ConnectWise, Autotask, HaloPSA): find every closed-family status leaking into open searches and maintain the exclusion list.

PSA Field Mapping Doc

Build and maintain a Thread ↔ PSA field-mapping cheat sheet — statuses, boards, priorities, classification values — from observed tickets, not assumptions.

PSA Migration Hygiene

PSA migrations (ConnectWise, Autotask, HaloPSA): enforce dual-running discipline — one master per phase, no orphaned tickets, clean cutover evidence.

PSA New Board Setup

New PSA board or queue setup checklist: statuses, ticket types, SLA mapping, and Thread View plus Flow implications so it syncs cleanly from day one.

PSA Note Discipline

Base skill defining how a note or reply is written when it may sync to a PSA — plain text, internal vs client-visible, and what never goes in a permanent record.

PSA Note Visibility Rules

PSA internal-vs-external note semantics (ConnectWise, Autotask, HaloPSA) with a leak-prevention checklist — a wrong-visibility note goes to the client.

PSA Taxonomy Cleanup

Rationalize PSA ticket type/subtype/category sprawl: census real usage from tickets, propose merges and retirements, enforce migration discipline first.

PSA-Is-Master Reconciliation

Generic Thread ↔ PSA reconciliation pattern (ConnectWise, Autotask, HaloPSA): rule out sync lag first, then move Thread to match PSA, never the reverse.

Quarantine Release Request

Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.

Queue Hygiene Score

Scan a queue for hygiene defects — missing contacts, stale statuses, empty notes, unassigned owners, blank classifications — with score and fix list.

Queue Scoring Triage

Produce a ranked triage order for the queue using two-layer scoring — a per-queue baseline plus per-ticket modifiers — so techs work the right ticket next.

Quote Preparation

Prepare a client quote with structured options like 1-year vs 3-year or good, better, best tiers, plus explicit assumptions ready for the sales owner.

RE/FW Reopen Detection

When a new ticket subject starts with RE: or FW: on a recently closed subject, find the closed parent and flag it as a reopen instead of working new.

Reassign Contact Submitted On Behalf Of

Catch tickets one person opened for a colleague ("submitting this on behalf of Jane") and move the ticket's contact to the person the request is actually for — so it's attributed, notified, and reported against the right end user.

Recurring Issue Report

Someone asks which issues keep coming back — chronic problems hitting the same client or device repeatedly — and whether each has a root-cause fix underway.

Rehire Reactivation

Safely restore a disabled account for a returning employee with authorization verified, old group memberships reviewed, and credentials reset fresh.

Renewal Prep

Build a pre-renewal readout for a client — service record over the term, open risks, the value story, and prep for the pricing conversation.

Reopen Forensics

Analyze why tickets reopen: patterns by technician, client, and issue type over a window, distinguishing premature closure, recurrence, and client reopens.

Resolution Closing Email

Draft the closure email for a resolved ticket — what was wrong, what we did, how to reopen — built from the ticket's actual evidence, not memory.

Respuesta al cliente (Spanish)

Redactar una respuesta externa al cliente con voz y formato de la casa: actualizaciones, notas de estado, cierre o cualquier correo del ticket.

Resumen diario (Spanish)

Resumen diario de los tickets abiertos de un técnico: qué espera respuesta, qué es urgente, qué está agendado hoy, con variante ultracorta.

RFO Letter

Draft the reason-for-outage letter a client receives after a major incident (facts, impact, remediation, prevention) written defensively for legal review.

Round-Robin Assignment

Distribute incoming tickets fairly across a named technician roster in rotation, honoring exclusion rules — runnable unattended inside a Flow.

Réponse client (French)

Rédiger une réponse client dans la voix maison: point d'avancement, note de statut, message de clôture ou tout e-mail client sur un ticket.

SaaS Alerts MDR

Triage SaaS Alerts events in M365 and Google tenants: login anomalies, mail-rule creation, file-activity spikes, privilege changes as identity-plane EDR.

Scope Pushback

Draft the reply when a client requests something outside their agreement — a helpful no showing the path to yes (quote or agreement change) with AM loop.

ScreenConnect Access

Troubleshoot ScreenConnect / ConnectWise Control access: unattended-agent health, session connectivity, and console handoff for the technician on duty.

Screenshot OCR Translate

Extract the text from a pasted screenshot — an error dialog, email, or app screen — translate it to English if needed, and summarize what it actually says.

Security Incident Postmortem

Build a security incident postmortem: executive summary, timeline, impact, root cause, and action items drawn from ticket evidence in defensible language.

Security Noise Tuning

Reduce recurring false-positive security alerts: quantify the FP rate, build an evidence pack, and recommend a retune at the source tool.

Security Vendor Generic

Handle security alerts from any vendor without a dedicated runbook: extract alert anatomy, map severity to desk tiers, build a vendor escalation package.

Sentiment Closure Report

Bucket closed tickets by sentiment score per client, tech, or period, with driver messages cited so a low score is explainable, not just a number.

Sentiment Decline Watch

Find clients whose sentiment is trending down, show the evidence and the specific conversations driving it, and draft suggested outreach for each.

Sentiment Score Explainer

Explain why a ticket thread received its sentiment score by citing the exact messages that drove it — no hand-waving, no re-scoring.

Session Token Theft Response

Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user's password.

Shared Mailbox Delegation

Set up or change shared mailbox access (Full Access, Send As, Send on Behalf) with owner approval and an audit note recorded on the delegation ticket.

Shift Handoff

Produce a skimmable end-of-shift or end-of-day one-pager of open work, grouped by status, for the next shift or a single named receiving technician.

Silent Ticket Detector

Find tickets where the client replied but no technician responded within threshold — surface each with wait time, @mention the tech, and draft a reply.

Single Ticket Handoff Card

Hand one ticket to another technician with a compact card — status table, watch points, overdue-task detection, and a one-sentence next action.

Site-Aware Approval Routing

Resolve a ticket's site, look up the per-site approver from a documented mapping, and send the approval request to that contact — not one hardcoded name.

Skill Authoring Coach

Help a member write a good Super Magic skill: sharpen the description into a real trigger, structure the workflow, and add the guardrails it needs.

Skill-Based Routing

Route a ticket to the technician with demonstrated expertise — who resolved similar issues for this client or this stack — not just whoever is free.

SLA Analytics

Someone asks how the desk is doing against SLA — first-response and resolution performance versus targets, and which tickets breached and why.

Smart Dispatch

Composite dispatcher skill: classify a new ticket, consult a routing matrix of tech specialties and client familiarity, then assign and schedule.

SOC Classification Tree

Classify a security ticket down the Incident, Request, and Problem tree and set type, subtype, and item consistently for reporting and routing.

SOC Client Email Pack

Pick the right client-outreach template for a security event (leaked credentials, BEC, inbox rule, lookalike domain) and draft with verified facts only.

SOC Shift Handoff

Hand off open security investigations at shift change: evidence state, containment progress, and watch items so the next shift can act immediately.

SOW Drafting

Draft a brief scope-of-work from ticket or project context with deliverables, assumptions, exclusions, and a T&M vs fixed pricing recommendation attached.

Spam Sender Triage

Close tickets from known-spam senders and patterns after verifying a human did not forward the message in for investigation or phishing analysis.

Staffing Model Analysis

Someone asks whether the desk is staffed right — ticket arrival patterns by hour and day versus coverage, and where the desk is under- or over-staffed.

Stakeholder Map

Map who matters at a client — contacts organized by role and influence as evidenced in ticket interactions — and where our relationship coverage has gaps.

Stale Ticket Follow-Up Cadence

Drive a configurable 24/48/72 follow-up cadence on tickets awaiting client reply: draft each friendly nudge, count attempts, skip legitimate waits.

Status Check Intent Design

Design the "any update on my ticket?" intent: answer from real ticket status and last client-visible update, escalating only when the trail has gone cold.

Status Nudger

Chase tickets stuck in a waiting status — re-send the pending approval or post the templated client nudge, never nudging twice inside one window.

Status Update Messenger

One command sets the ticket status and posts the matching templated client message from a per-status map, so status and note change together.

Super Magic Enablement

Prep a show-and-tell of the highest-value Super Magic use cases for a specific team, grounded in their own recent tickets so every example is recognizable.

Sweep Honesty

Base skill defining how a skill reports on a search or bulk sweep — result caps, what it could not see, and never presenting a partial pass as a complete one.

Syncro Workflow

Syncro PSA-RMM idioms: tenant-configured ticket statuses, worksheets as embedded checklists, ever-running timer culture, and RMM alerts inside the desk.

Synology NAS Alerts

Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.

Synthèse quotidienne (French)

Synthèse quotidienne des tickets ouverts d'un technicien: qui attend réponse, ce qui est urgent, ce qui est planifié aujourd'hui, variante 3 lignes.

Tagesübersicht (German)

Tagesübersicht offener Tickets eines Technikers: was auf Antwort wartet, was dringend ist, was heute geplant ist — inklusive 3-Zeilen-Variante.

TeamViewer Access

Troubleshoot TeamViewer remote access: host and agent health, unattended access, session connectivity, and the commercial-use-detected flag on handoff.

Tech End-of-Day Ritual

A technician's close-of-day runbook: EOD wrap-up, time-entry compliance self-check, and lining up tomorrow's first move before logging off for the day.

Tech Morning Ritual

A technician's 15-minute start-of-day runbook: digest, schedule check, easy-win pick, and a first-response sweep before diving into ticket work.

Tech Performance Review

A manager asks to evaluate a technician's performance over a period — closed, assigned, reopened, time logged, sentiment — with coaching angles, not a verdict.

Tech Utilization Report

Report billable utilization per technician — logged billable hours against capacity — with role-aware targets and framing as workload economics, not worth.

Technical to Plain English

Translate a technical resolution, diagnosis, or explanation into language a non-technical stakeholder can understand — "make this client-friendly."

Technician Availability Check

Answer who is the next available technician by combining today's schedules, priority-weighted open load, and shift or PTO context into a ranked answer.

ThreatDown Malwarebytes

Triage ThreatDown (Malwarebytes) detections by class — malware, PUP, PUM, exploit — and run the remediation-verification pass the remediated status skips.

ThreatLocker Allowlisting

Work ThreatLocker approval and elevation requests: triage daily allowlisting safely, keep Learning vs Secured mode straight, protect zero-trust posture.

Three Strikes Final Email

Draft the final "we're closing this ticket" email after three documented contact attempts with no client response — only when evidence exists.

Ticket Export for LLM

Produce a clean, sanitized, self-contained export of a ticket for pasting into another AI tool — credentials and PII stripped, context preserved.

Ticket Intake & Formatting

Build a clean ticket title and description from a raw report, voicemail, email, form submission, or rough technician notes, following the house intake standard.

Ticket QA Review

Grade a completed ticket against the closure rubric — resolution, classification, owner, time logged, title, client message — pass or bounce it back.

Ticket Review Training

Turn a real resolved ticket into a sanitized teaching case with what was done well, what could improve, and the transferable lesson for team review.

Ticket Summary & Closure Note

Produce a clean ticket summary as a resolution note, closure note, or templated P1/P2 handoff — in the requested format and point of view.

Ticket Triage

Classify a new or unassigned ticket, gauge severity, catch duplicates, and route it to the right board, status, and priority for the queue.

Tickets to Opportunities

Mine recent service tickets for expansion signals, surfacing work that became or should become a sales opportunity, in a per-client opportunity report.

Tier Dispatcher

Dispatch a new ticket by support tier: classify T1/T2/senior, check that tier's technicians against today's schedule, then assign and book the work around the customer's deadline.

Time Entry Cleanup

Turn raw, rough time notes into clean, standardized time entries with client-facing and internal versions, recording only work explicitly stated as done.

Time Entry Revenue Audit

When someone wants to find tickets that were worked with no time logged — revenue leakage by technician or period — and get the gaps fixed the right way.

Todyl Platform

Route Todyl alerts by plane: SASE network, endpoint EDR, or identity and SIEM detection. Each plane needs a different runbook from the same platform.

Tone Polish Rewrite

Rewrite rough technician text into a polished, client-ready version — "write this nicely," "clean this up" — preserving every fact exactly.

Travel Access Window

Open a temporary conditional access exception for a traveling user with automatic expiry and a tracked revert task so location policies stay in place.

Trend Micro Worry-Free

Triage Trend Micro Worry-Free alerts by engine (signature, ML, behavior, web reputation) and know when a client is on Apex Central or Vision One instead.

Trend Root-Cause Mining

Find what is driving ticket volume and making the desk busy by mining recent tickets for top recurring issues and root causes across a chosen period.

Triage Agent Tuning

Tune Triage Agent custom rules from observed misses — wrong boards, wrong priorities, tickets it should have left alone — plus bypass-word usage analysis.

Triage d'hameçonnage (French)

Triage d'hameçonnage d'un e-mail suspect: évaluer sans toucher la charge, mesurer le rayon d'exposition, contenir si malveillant, répondre au déclarant.

Triaje de phishing (Spanish)

Triaje de phishing de un correo sospechoso: evaluar sin tocar la carga, medir radio de impacto, contener si es malicioso y responder al reportante.

Unattended Output Discipline

Base skill defining the output contract for any prompt or skill that runs unattended inside a flow, where the agent's entire reply is posted verbatim.

Vacation Handoff Pack

Pre-PTO handoff prep listing which tickets need transferring, which need watching, and a per-ticket one-liner brief so cover techs can act fast.

Variation Author

Interview the admin on client-specific troubleshooting differences (printers, VPN, LOB apps), then encode them as intent variations with a test plan.

vCIO Weekly Proactive

Pick the three highest-leverage clients to proactively contact this week from live ticket signals, with a reason and a suggested opener for each outreach.

Vendor Fraud BEC Alert

Respond to a BEC or payment-fraud attempt (fake invoice, banking-change request, exec impersonation): freeze payments and run callback verification.

Vendor Outage Checker

Check vendor status pages and outage reports for M365, ISPs, and SaaS apps, then post sourced findings to the ticket to confirm is it down for everyone.

View Builder

Create or duplicate an inbox view from a plain-English spec — "open P1s", "the dispatch view filtered to a client" — saved filters and view variants.

VIP Priority Handling

Detect VIP contacts and VIP clients at ticket intake, apply the configured priority bump, and fire notify rules without letting VIP status skew triage.

Voice Call QA Review

Review AI-handled voice calls against a rubric — caller identified, issue captured, commitments accurate, clean handoff — with transcript evidence cited.

Voice Catchall Identification

Identify the client and contact behind an unknown caller on a voice ticket with only a phone number, using number, name, and company clues from transcript.

Voice Transcript Intake

Turn a pasted call transcript into ticket action — extract caller, client, issue, and commitments, then create or update the ticket with a time entry.

Voicemail to Ticket

Convert a voicemail transcription into a ticket with a callback commitment — urgency read from what the caller actually said, not from tone guesses.

VPN Issues Intent Design

Design the VPN connectivity intent: a short self-help ladder plus environment capture — client, location, error text — so escalations arrive diagnosable.

Waiting-on-Client Audit

Audit every ticket parked in a waiting status: how long, whether a follow-up was sent, and the correct next action — nudge, reschedule, unpark, close.

Weekly Ops Report

A service manager wants the weekly service-desk report — team volume, closures, sentiment, aging, and anything anomalous versus the prior week.

Wire Fraud Verification Protocol

Callback verification for any payment change request: banking updates, new wire instructions, or payroll redirects — verify out-of-band, no exceptions.

Workaround Documentation

Document a workaround in the standard format (steps, hold time, cost, expiry review) and label the ticket workaround-only so nobody mistakes it for a fix.

Workload-Balancing Assignment

Assign a ticket to the tech with the best availability score — base capacity minus open tickets minus scheduled blocks — with math shown, runs in Flows.

Write Guardrails

Base skill defining the gates that sit in front of any action that changes something — confidence bar, show-me-before-send, when-in-doubt-do-nothing, and never invent data.

XLA Breach Risk Tiering

Tier every open ticket by XLA exposure — Breached, Critical, High, Watch — from remaining time to target with escalation factors and a next move.

Zero-Touch Opportunity Mining

Someone asks where the biggest opportunities are to increase zero-touch resolution, or which ticket patterns should become intents or flows.

IT Glue

Account Takeover Runbook

Respond to a confirmed account takeover: disable sign-in, revoke sessions, reset MFA, sweep inbox rules and OAuth consents, and notify users.

AD CS / Internal PKI Issues

Troubleshoot AD CS internal PKI issues — enrollment and template failures, CRL revocation-check errors, and certificate expiry cascades before reissuing.

AD Replication Issues

Fix Active Directory replication failures using repadmin — GPO version mismatches, password changes not propagating, and event IDs 1311/1388/1988.

Adobe Creative Cloud Licensing

Fix Adobe Creative Cloud sign-in loops, access-denied errors, and Admin Console entitlement gaps between named-user and shared-device licensing.

Anti-Spam Policy Tuning

Tune Exchange Online Protection and Defender anti-spam policies from verdict evidence with scoped overrides and time-limited exceptions.

App Protection Policies

Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.

Archive Mailbox Enablement

Enable Exchange Online In-Place Archive mailboxes to solve quota issues, with license checks, move-policy expectations, and archive caveats.

Audit Prep Review

Run a pre-audit sweep for unresolved prior findings, doc gaps, and stale evidence, and return a ranked readiness report before the auditor arrives.

AutoCAD / Revit Issues

Troubleshoot Autodesk AutoCAD and Revit — FlexNet network license checkout failures, drawing corruption, and BIM central-model worksharing sync.

Autopilot Deployment

Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.

B2B Collaboration Setup

Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.

Backup Failure Triage

Classify a backup failure by alert text and device state, check for recurrence, and decide whether to fix locally or escalate to the backup vendor.

Backup Missed vs Failed Alert

Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.

Backup Restore Request

Intake backup restore requests — deleted files, prior versions, mailboxes, servers — pinning down what, when, RPO limits, and verifying with requester.

BitLocker Key Retrieval

Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.

Break-Glass Account Audit

Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.

Browser Issues

Diagnose browser problems — one broken site, SSO loops, crashes, extension conflicts — using profile isolation and extension bisect, not clear-everything.

BSOD Analysis

Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.

Calendar Permissions

Grant or review Exchange calendar sharing and delegation with least-privilege folder roles, owner consent, and private-items handling.

Certificate Expiry Alert

Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.

Certificate Inventory

Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.

Circuit Inventory

Refresh a client circuit inventory — internet, WAN/MPLS/SD-WAN, POTS-replacement — with carrier, circuit ID, site, bandwidth, and renewal dates.

Citrix Basics

First-line playbook for Citrix Virtual Apps and Desktops (CVAD/DaaS) — VDA registration, StoreFront vs Workspace, hung sessions — before escalating.

Client Offboarding

Run a clean client exit checklist covering data handover, mutual access revocation, final billing notes, and the documentation package for both parties.

Client Onboarding Runbook

Take a newly signed client from MSA to service-desk readiness: boards, routing, contacts, docs intake, monitoring, and welcome comms as tracked tickets.

CMMC Readiness Brief

Produce a CMMC level-readiness snapshot for a defense-adjacent client with likely standing and obvious gaps — never a certification or formal assessment.

Compliance Questionnaire Assist

Draft answers to a client's security or compliance questionnaire from documented facts only, cite each source, and flag unknowns instead of guessing.

Conditional Access Review

Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.

Conference Room AV

Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.

CW Configurations Assets

ConnectWise Manage configurations (assets): link tickets to the right config, follow the desk's config-type taxonomy, and flag stale or duplicate configs.

Cyber Insurance Form Prep

Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.

Device Health Check

Diagnose one device via the RMM — alerts, activities, services, disk, reboot, and patch posture — then propose remediation with a deep-link handoff.

Device Offline Runbook

Work a device-offline alert or "won't connect" ticket — site-wide check first, maintenance windows, last activities, and clear escalate criteria.

Device Wipe Workflows

Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.

Device-to-User Mapping

Answer "who uses this device" by combining RMM last-logged-on data with contact records, ticket history, and documentation when a ticket names only one.

DFS Namespace and Replication

Fix DFS-N referral failures and DFS-R replication backlog, conflicts, and staging-quota issues using health reports and backlog counts, not blind reinit.

DHCP Server Issues

Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.

Dispatcher Intake

Attended chat intake for dispatchers: describe the issue and get back a ticket with board, type, priority, summary, and first-touch note attached.

Distribution vs M365 Groups

Pick between distribution lists, Microsoft 365 Groups, mail-enabled security groups, and dynamic groups, and handle DL-to-M365-Group upgrades.

DKIM Enablement

Enable DKIM signing for a custom domain in Exchange Online: publish selector CNAMEs, activate signing, verify records, and plan key rotation.

DMARC / SPF / DKIM Setup

Diagnose email authentication failures and build correct SPF, DKIM, and DMARC DNS records — new sending sources, alignment, and propagation expectations.

DNS & Domain Issues

Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.

Doc Gap Detector

Find tickets where a security- or configuration-impacting change (firewall, MFA, DNS, admin access) was made with no linked or matching documentation update.

Email Connector Setup

Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.

Endpoint Encryption Audit

Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.

Enrollment Restrictions

Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.

Entra Connect Sync Errors

Fix Entra Connect (Azure AD Connect) sync errors — export failures, duplicate attributes, quarantined objects, users missing in the cloud — no blind runs.

Entra PIM Requests

Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.

Environment Facts Updater

When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.

EOL Product Notice

Draft the client notice that a product or OS is reaching end-of-life — verified EOL date, honest risk framing, upgrade paths, decision deadline.

Exchange Hybrid Issues

Troubleshoot Exchange hybrid — mail stuck on-prem/cloud, blank free-busy, stalled migrations, user-not-found after moves — starting from mailbox ownership.

Exchange On-Prem Mail Flow

Diagnose on-prem Exchange transport — stuck queues, send/receive connector faults, TLS/cert failures, backpressure — using Queue Viewer and protocol logs.

Fax & eFax

Work fax tickets — dead analog lines, ATA fax page corruption, eFax cloud portals not sending or receiving — across the line, ATA, and portal matrix.

File Share Permissions

Diagnose access-denied file share tickets by laddering effective permissions across share vs NTFS vs inheritance and group membership, at least privilege.

Firewall Config Backup Audit

Verify every firewall config backup is current — via Liongard change history or the vendor state — and flag any device whose backup is missing or stale.

Firewall Rule Change Request

Shepherd a firewall change from vague ask to change-ready spec — justification, source/destination/port/protocol, expiry, and routing to the approver.

GDAP Relationship Review

Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.

Group Policy Troubleshooting

Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.

Guest Access Audit

Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.

Hardware Diagnostics

Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.

Hardware Refresh Forecast

Build a 4–5 year hardware refresh workbook per client — devices crossing the age threshold each period and the per-client refresh budget for planning.

HIPAA Safeguards Checklist

Walk a healthcare client's environment against the HIPAA Security Rule technical safeguards, returning a checklist of what's in place versus missing.

Hyper-V Clustering

Troubleshoot Hyper-V failover clusters — quorum loss, CSV redirected or offline, failed live migrations, stuck node drains — from cluster and event logs.

Hypervisor Alert Triage

Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.

IIS Web App

Diagnose IIS web app failures — app pool crashes, rapid-fail protection, binding and SSL problems, HTTP 500/502/503 codes — using HTTP.sys and FREB logs.

Impossible Travel Runbook

Investigate an impossible-travel or atypical-location sign-in alert: check VPN and travel, verify with the user by phone, and contain on confirmed ATO.

Industry Pack Frame

Base skill defining how a vertical pack works — the client's calendar first, then blast radius against it, the desk-vs-vendor boundary, and the regulator's data rules.

Insider Risk Basics

Handle insider-risk signals like data staging, sabotage, or access abuse: preserve evidence quietly, escalate to client HR, and keep it confidential.

Internal DNS Server Issues

Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.

Internal IT Offboarding

Offboard departing MSP staff with client-credential rotation first, then tool deprovisioning, ticket reassignment, and client-facing transition notes.

Internal IT Onboarding

Onboard the MSP's own new hire, technician, dispatcher, or back-office, with accounts, PSA/RMM/docs licenses, role-scoped client access, and shadowing.

Intune App Deployment

Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.

Intune Compliance Policies

Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.

Intune Enrollment Troubleshooting

Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

ISP Outage Tracking

Manage a circuit outage while the carrier owns the fix — capture the carrier ticket reference, run the escalation clock, and keep the client informed.

IT Glue Asset & Contact Lookup

On demand, pull IT Glue contacts, credentials, and flex-asset configs into a plain-text ticket summary, degrading to KB or ticket history if unavailable.

Journaling & Compliance Mail

Handle Exchange journaling and compliance-copy requests with legal justification, external journal targets, cost impact, and retention alternatives.

KB Article Draft

Turn a resolved ticket into a reusable knowledge-base article draft with title, symptoms, cause, numbered resolution, and stripped client specifics.

Knowledge Base Taxonomy

Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.

Label and Receipt Printers

Troubleshoot Zebra thermal label and ESC/POS receipt printers — ZPL/EPL print language, driver mode, spooler, and network faults — distinct from MFPs.

Large File Share Guide

Draft reply-ready instructions for an end user to send a file too big for email using the client's approved method — attachment bounced, big file.

LOB Application Framework

Generic playbook for any line-of-business app failure — dental, legal, accounting, ERP — identify vendor and version, pull logs, build escalation packets.

LOB Database Locks

Clear record-locked-by-another-user tickets in LOB apps — find the locking session in the vendor admin console and release it approved-only, never kill DB.

M365 Group Lifecycle

Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.

M365 License Optimization

Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.

M365 Sign-in Issues

Diagnose Microsoft 365 and Entra sign-in failures — blocked sign-ins, MFA loops, repeated password prompts, device-trust errors — from the sign-in log.

M365 Tenant Health Report

Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.

Mac Fleet Management

Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.

Mac Support

The Windows tech's ladder for Mac tickets — keychain prompts, MDM enrollment, TCC app permissions, FileVault — mapping macOS causes vs Windows reflexes.

Mail Flow & Delivery

Diagnose email delivery — NDR bounces, mail not arriving, stuck outbound, one sender blocked — by decoding the bounce and tracing the actual mail path.

Mailbox Migration Prep

Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.

Mailbox Quota Management

Investigate full or filling Exchange mailboxes and choose targeted cleanup, archive enablement, or license upgrade based on where size lives.

MDR Client Onboarding

Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.

MFA Methods Audit

Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.

MFA New Phone Guide

Draft reply-ready instructions for an end user who got a new phone and needs to move or re-enroll their MFA safely to approve sign-ins again.

MFA Setup Guide

Draft reply-ready instructions for an end user to enroll in multi-factor authentication using the client's actual MFA product for account sign-in.

Mobile Device & MDM

Work mobile MDM tickets — enrollment failures, missing mail profiles, compliance blocks, lost/stolen device response — destructive actions need approval.

Mobile Email Setup

Set up corporate mail on a phone — new-device config, sync failures, MDM enrollment prompts, native Mail vs Outlook — holding the BYOD consent boundary.

Mobile Fleet Review

Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.

Mobile Mail Setup Guide

Draft reply-ready instructions for an end user to get work email on their phone — Outlook mobile app first, matched to the client's mobile policy.

NAS / File Share Provisioning

Plan and document a new network share — folder structure, permission model, quota, backup inclusion — with an approval gate on the access model first.

NetSuite ERP

Support NetSuite ERP tickets as an MSP — roles and permissions, saved-search visibility, SuiteScript/REST/CSV integration errors — no financial edits.

Network Device Inventory

Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.

Network Outage Triage

Triage a suspected site-down — all-devices-offline vs single dead device, ISP vs internal, who to call, and set a comms cadence for the client updates.

Network Share Slowness

Diagnose slow SMB file shares — sluggish copies, crawling folder listings, one office fine — through SMB version, signing, AV filters, and DFS referrals.

New Computer First Day Guide

Draft reply-ready instructions for an end user receiving a new or replacement computer — what to expect, what to do first, and what NOT to do.

New Workstation Imaging Checklist

Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff.

NIST CSF Gap Brief

Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.

Office Activation & Licensing

Fix Office / Microsoft 365 Apps activation — Product Deactivated, unlicensed mode, repeated prompts, shared-computer/RDS errors — detect the license type.

On-Prem to Cloud File Migration

Fix file-server to SharePoint Online and OneDrive migration issues: NTFS permission translation, path length, illegal characters, and sync errors.

OneDrive / SharePoint Sync

Diagnose OneDrive and SharePoint sync — stuck processing changes, missing files, red X icons — separating client state, library limits, and permissions.

OneDrive Known Folder Move

Work OneDrive Known Folder Move rollout tickets — missing Desktop, sync conflicts, path-length and invalid-character legacy files — without unhooking KFM.

OneDrive Restore Guide

Draft reply-ready instructions for an end user to recover a deleted file or roll back a previous version themselves in OneDrive or SharePoint.

OneDrive Storage Governance

Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.

Out of Office Guide

Draft reply-ready instructions for an end user to set their own out-of-office reply correctly — dates, internal versus external messages for OOO.

Outlook Client Issues

Diagnose Outlook desktop crashes, hangs, broken search, password prompts, and crash-on-send using profile, data-file, and add-in isolation branches.

Outlook Profile Setup Guide

Draft reply-ready instructions for an end user to add their work account to Outlook on Windows or Mac — "send the user steps to set up Outlook."

Outlook Search Issues

Fix Outlook search returning nothing or incomplete results by isolating local index vs server search and cached-mode window before rebuilding the index.

PaperCut / PrinterLogic

Diagnose PaperCut and PrinterLogic print-management issues: release stations, driver deployment failures, and quota/account problems from platform logs.

Password Expiry Change Guide

Draft reply-ready instructions for an end user to change a password that's about to expire (or just did) before it locks them out of their account.

PCI DSS Scope Review

Help a client understand PCI DSS scope — what counts as the cardholder data environment (CDE), what's in versus out — not a QSA assessment or AOC.

Plus Addressing & Aliases

Handle requests for extra mailbox addresses: plus addressing for self-service tagging, proxy aliases, and the send-from-alias caveats stated.

POS System Issues

Work POS tickets — frozen terminals, failed card payments, back-office sync — by splitting terminal, payment gateway, and back-office with a PCI boundary.

Power Automate Governance

Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.

Print Server Management

Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.

Printer Connect Guide

Draft reply-ready instructions for an end user to add or reconnect the office printer, matched to the client's actual print setup and drivers.

Printer Fleet Review

Cluster a client printer-related tickets to find chronic devices, quantify the time they burn, and recommend replace-vs-repair per problem printer.

Printer Troubleshooting

Diagnose printing problems — nothing prints, stuck queues, garbled output, wrong printer, scan-to-email fails — via a spooler, driver, and network matrix.

Purview DLP Policy

Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.

QuickBooks Desktop Multi-User

Fix QuickBooks Desktop multi-user errors: H202/H505 hosting, -6000 series company file, stuck locks, via hosting mode and Database Server Manager checks.

QuickBooks Online Issues

Fix QuickBooks Online browser problems: bank-feed failures, multi-user role errors, cache and extension issues; distinguish QBO from Desktop before acting.

RADIUS / NPS Authentication

Diagnose 802.1X and RADIUS authentication failures on Windows NPS: Wi-Fi, wired, VPN rejects, certificates, and shared-secret issues via NPS event logs.

RAID Degradation Alert

Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.

Ransomware Response

Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.

RD Gateway Issues

Fix Remote Desktop Gateway and RD Web Access problems: external RDP failures, certificate errors, CAP/RAP policy mismatches, and MFA integration failures.

RDS / AVD Troubleshooting

Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.

Report Phishing Guide

Draft reply-ready instructions telling an end user what to do with a suspicious email — the client's report-button path, never forwarding around.

Resource Mailbox Setup

Create Exchange room and equipment mailboxes with booking policies, auto-accept or delegate approval, and recurring-meeting and duration limits.

Retention Policy Requests

Change Microsoft Purview retention and deletion policies with scope confirmed, legal-hold interaction flagged, and authorization documented.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

Roaming Profiles & FSLogix

Fix FSLogix and roaming-profile failures on session hosts: cannot attach VHD, temp profiles, sign-in hangs, and settings loss via FSLogix log codes.

Safe Attachments and Links Policy

Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.

Safe File Sharing Guide

Draft reply-ready instructions for an end user to share files the approved way — links over attachments, right audience, external-sharing rules.

Sage 50 / Sage 100

Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.

SCADA / OT Awareness

Support OT-adjacent tickets safely: hard IT vs SCADA/PLC/HMI/ICS boundary, never touching controllers, and routing to the correct OT or vendor owner.

Scanner & Copier Fleet

Fix MFP and copier scan-to-folder failures after SMB or credential changes, address-book cleanup, firmware quirks, and panel errors on leased fleets.

Screen Share Help Guide

Draft reply-ready instructions for an end user to start a remote-support screen share with the desk using the client's actual remote tool.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.

Security Advisory Broadcast

Draft a security advisory going to many clients — new threat, vendor breach, or vulnerability — from verified facts with per-client relevance check.

Security Alert Response

Work an inbound security alert ticket: extract the facts, route to the right client, tier severity, and contain or close with documented reasoning.

Security Defaults vs Conditional Access

Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

Security Questionnaire Vendor DDQ

Draft responses to an inbound vendor security questionnaire or DDQ from documented facts only, cite evidence for each, and flag every unknown for review.

Sensitivity Labels

Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.

Server Decommission Runbook

Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.

Server Patch Windows

Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.

Shared Mailbox Access Guide

Draft reply-ready instructions for an end user to open a shared mailbox they've been granted access to — desktop, web, and mobile paths covered.

Shared Mailbox Creation

Create Exchange Online shared mailboxes: naming, licensing at the 50GB threshold, initial delegation, and documentation for team inboxes.

SharePoint On-Prem

Diagnose on-premises SharePoint Server: search crawl failures, stale results, content-database mounting, and permission inheritance via ULS crawl logs.

SharePoint Site Provisioning

Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.

Slow Computer

Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.

SOC2 Evidence Collection

Map an auditor's SOC 2 evidence request list to ticket, change, and access evidence, packaging it with citations and honestly flagged gaps.

SOP Builder

Write a standard operating procedure — scope, prerequisites, numbered steps, validation, escalation — from a ticket, a rough doc, or a described process.

SOP Candidate Finder

Sweep recently resolved tickets for documentation-worthy resolutions like recurring fixes and vendor workarounds, ranking SOP and KB article candidates.

SQL Backup and Maintenance

Fix SQL Server backup issues: runaway log growth, FULL vs SIMPLE recovery model, missing log backups, VSS conflicts, and broken point-in-time recovery.

SQL Server Performance

Diagnose SQL Server slowness: blocking, deadlocks, missing indexes, stale statistics, tempdb contention, and parameter sniffing via live wait stats.

SSL Certificate Renewal

Handle SSL and TLS certificate renewals: browser warnings, service certificate expiry, issuer-specific renewal paths, and required service restarts.

SSL Inspection Issues

Diagnose TLS/SSL inspection breakage: pinned apps failing, firewall certificate warnings, apps broken only on corporate networks, and bypass routing.

SSPR Password Reset Guide

Draft reply-ready instructions an end user can follow to reset their own password via self-service password reset without calling the help desk.

SSPR Rollout

Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.

Stale Device Cleanup

Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.

Stale Doc Hygiene

Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.

Storage Capacity Planning

Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.

Supporting Accounting Firms

CPA and accounting firm pack covering Lacerte, ProSeries, and UltraTax software, tax-season freeze windows, and IRS Pub 4557 WISP safeguards.

Supporting Architecture and Engineering Firms

AEC firm pack for AutoCAD, Revit, and Civil 3D support, network license servers, GPU workstations, and submittal-deadline urgency.

Supporting Auto Dealerships

Auto dealership pack covering DMS platforms (CDK, Reynolds, Tekion), OEM tooling, F&I data under FTC Safeguards, and month-end urgency.

Supporting Construction and Field Services

Construction and field-service pack for Procore, Bluebeam, and ServiceTitan, plus rugged tablets, jobsite connectivity, and crew clocks.

Supporting Dental Practices

Dental practice pack covering Dentrix, Eaglesoft, and Open Dental PMS, Dexis-class x-ray sensors, HIPAA, and morning-huddle downtime.

Supporting Financial Services Clients

RIA, broker-dealer, and bank pack covering FINRA/SEC email archiving retention, Orion and Redtail advisory tools, and market-hours urgency.

Supporting Insurance Agencies

Independent insurance agency pack for Applied Epic, EZLynx, and HawkSoft AMS, carrier portals, IVANS downloads, ACORD forms, and E&O trails.

Supporting Legal Firms

Law firm pack covering iManage and NetDocuments DMS, Clio practice management, ethical walls, litigation holds, and court-deadline urgency.

Supporting Logistics and Trucking Clients

Trucking and 3PL pack covering McLeod and Trimble TMS, Samsara and Motive ELDs, DOT/HOS compliance, EDI, and 24/7 dispatch operations.

Supporting Manufacturing Clients

Manufacturing client pack covering the OT/IT boundary, PLC and SCADA hands-off rules, ERP/MES stacks, shift patterns, and line-down urgency.

Supporting Medical Clinics

Medical clinic pack for eClinicalWorks and Athenahealth EMR, e-prescribing, lab interfaces, telehealth, and HIPAA PHI ticket hygiene.

Supporting Municipal Government

City, county, and special-district pack covering public-records email retention, CJIS for PD systems, procurement cycles, and council AV.

Supporting Nonprofits

Nonprofit client pack covering Blackbaud donor CRM, TechSoup and Microsoft grant licensing, board access hygiene, and year-end giving.

Supporting Property Management Clients

Property management pack covering Yardi, AppFolio, and Buildium platforms, tenant portals, owner-tenant data separation, and trust accounting.

Supporting Real Estate Clients

Real estate brokerage and title pack covering Dotloop, SkySlope, MLS and lockboxes, wire-fraud and BEC defense, and agent BYOD sprawl.

Supporting Schools and Education

K-12 school and district pack covering PowerSchool SIS, Canvas LMS, FERPA data hygiene, CIPA filtering, E-Rate, and 1:1 device programs.

Supporting Senior Living Communities

Senior living and skilled-nursing pack covering PointClickCare and MatrixCare EHR/eMAR, nurse-call systems, resident wifi split, and HIPAA.

Switch VLAN and Port Change

Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.

Teams Call Quality

Fix Microsoft Teams call quality: choppy audio, robotic voice, frozen video, and drops via CQD-style device, machine, and network path layer isolation.

Teams Issues

Diagnose Microsoft Teams sign-in loops, meeting join failures, no audio or video, stuck presence, and guest access, with cache reset used sparingly.

Teams Meeting Guide

Draft reply-ready instructions for an end user to join and run a Teams meeting — audio and camera checks, screen sharing, recording basics.

Teams Phone Admin

Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.

Teams Rooms AV

Fix Microsoft Teams Rooms devices: room account sign-in, camera, mic, display, touch console health, calendar join failures, and restart discipline.

Tenant Onboarding Checklist

Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.

Ticket Research Copilot

Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.

Transport Rule Management

Inspect, add, or change Exchange Online transport rules safely: document current state, test mode before enforce, and disable instead of delete.

Troubleshooting Ladder

Base skill defining the order every troubleshooting playbook works in — history, documentation, blast radius, versions, verbatim evidence, then branch — and how it closes out.

Veeam Restore Operations

Run Veeam restores end to end: pick file-level, application-item, full-VM, or Instant Recovery, choose the right point, target a safe location, verify.

Vendor Escalation Package

Assemble a third-party vendor support package — environment, repro steps, timeline, diagnostics, contract or entitlement reference — credentials stripped.

VMware vSAN and vMotion

Diagnose VMware vSphere: vSAN health warnings, resync storms, vMotion and DRS migration failures, datastore latency, and APD or PDL via vCenter events.

VoIP Phone Matrix

Diagnose VoIP problems: inbound calls failing, ring group misbehavior, one-way audio, dead phones, provisioning fails, by splitting phone vs site vs trunk.

VPN Connect Guide

Draft reply-ready instructions for an end user to connect to their company VPN using the client's actual VPN software and login flow.

VPN Troubleshooting

Diagnose VPN issues: won't connect, authenticates then no traffic, drops while remote, or can't reach resources by name via a client and DNS matrix.

Vulnerability Report Triage

Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.

Warranty and EOL Report

Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.

Wi-Fi & Network Troubleshooting

Diagnose Wi-Fi and LAN issues: slow or dropping Wi-Fi, connection failures, dead zones, and internet-down reports by laddering user to AP to site scope.

WiFi Connect Guide

Draft reply-ready instructions for an end user connecting a work device to wifi — office network, home network, and captive-portal awareness.

WiFi Heatmap / Site Survey Request

Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.

WiFi Infrastructure Audit

Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.

Windows 11 Migration Issues

Handle post-upgrade Windows 11 migration tickets: driver regressions, reset default apps, missing printers, moved features, with rollback window checked.

Windows Hello for Business

Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.

Windows Profile Corruption

Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.

Windows Update Client Failures

Diagnose Windows Update client failures: 0x8024xxxx and 0x800Fxxxx errors, update loops and rollbacks, and stuck scans across WU, WSUS, and Intune sources.

Working From Home Checklist

Draft a reply-ready remote-work setup checklist for an end user — connectivity, VPN, phone, and how to get help — tailored to the client's stack.

WSUS Patching Infrastructure

Diagnose WSUS server-side issues: clients not checking in, 0% downloads, console crashes, unapproved-but-never-arriving updates, and database bloat.

Zero-Day Emergency Response

Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.

Hudu

AD CS / Internal PKI Issues

Troubleshoot AD CS internal PKI issues — enrollment and template failures, CRL revocation-check errors, and certificate expiry cascades before reissuing.

AD Replication Issues

Fix Active Directory replication failures using repadmin — GPO version mismatches, password changes not propagating, and event IDs 1311/1388/1988.

Adobe Creative Cloud Licensing

Fix Adobe Creative Cloud sign-in loops, access-denied errors, and Admin Console entitlement gaps between named-user and shared-device licensing.

App Protection Policies

Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.

AutoCAD / Revit Issues

Troubleshoot Autodesk AutoCAD and Revit — FlexNet network license checkout failures, drawing corruption, and BIM central-model worksharing sync.

Autopilot Deployment

Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.

B2B Collaboration Setup

Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.

Backup Restore Request

Intake backup restore requests — deleted files, prior versions, mailboxes, servers — pinning down what, when, RPO limits, and verifying with requester.

BitLocker Key Retrieval

Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.

Break-Glass Account Audit

Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.

Browser Issues

Diagnose browser problems — one broken site, SSO loops, crashes, extension conflicts — using profile isolation and extension bisect, not clear-everything.

BSOD Analysis

Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.

Certificate Expiry Alert

Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.

Certificate Inventory

Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.

Circuit Inventory

Refresh a client circuit inventory — internet, WAN/MPLS/SD-WAN, POTS-replacement — with carrier, circuit ID, site, bandwidth, and renewal dates.

Citrix Basics

First-line playbook for Citrix Virtual Apps and Desktops (CVAD/DaaS) — VDA registration, StoreFront vs Workspace, hung sessions — before escalating.

Client Offboarding

Run a clean client exit checklist covering data handover, mutual access revocation, final billing notes, and the documentation package for both parties.

Client Onboarding Runbook

Take a newly signed client from MSA to service-desk readiness: boards, routing, contacts, docs intake, monitoring, and welcome comms as tracked tickets.

CMMC Readiness Brief

Produce a CMMC level-readiness snapshot for a defense-adjacent client with likely standing and obvious gaps — never a certification or formal assessment.

Conditional Access Review

Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.

Conference Room AV

Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.

CW Configurations Assets

ConnectWise Manage configurations (assets): link tickets to the right config, follow the desk's config-type taxonomy, and flag stale or duplicate configs.

Device Wipe Workflows

Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.

DFS Namespace and Replication

Fix DFS-N referral failures and DFS-R replication backlog, conflicts, and staging-quota issues using health reports and backlog counts, not blind reinit.

DHCP Server Issues

Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.

Dispatcher Intake

Attended chat intake for dispatchers: describe the issue and get back a ticket with board, type, priority, summary, and first-touch note attached.

DMARC / SPF / DKIM Setup

Diagnose email authentication failures and build correct SPF, DKIM, and DMARC DNS records — new sending sources, alignment, and propagation expectations.

DNS & Domain Issues

Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.

Doc Gap Detector

Find tickets where a security- or configuration-impacting change (firewall, MFA, DNS, admin access) was made with no linked or matching documentation update.

Email Connector Setup

Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.

Endpoint Encryption Audit

Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.

Enrollment Restrictions

Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.

Entra Connect Sync Errors

Fix Entra Connect (Azure AD Connect) sync errors — export failures, duplicate attributes, quarantined objects, users missing in the cloud — no blind runs.

Entra PIM Requests

Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.

Environment Facts Updater

When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.

EOL Product Notice

Draft the client notice that a product or OS is reaching end-of-life — verified EOL date, honest risk framing, upgrade paths, decision deadline.

Exchange Hybrid Issues

Troubleshoot Exchange hybrid — mail stuck on-prem/cloud, blank free-busy, stalled migrations, user-not-found after moves — starting from mailbox ownership.

Exchange On-Prem Mail Flow

Diagnose on-prem Exchange transport — stuck queues, send/receive connector faults, TLS/cert failures, backpressure — using Queue Viewer and protocol logs.

Fax & eFax

Work fax tickets — dead analog lines, ATA fax page corruption, eFax cloud portals not sending or receiving — across the line, ATA, and portal matrix.

File Share Permissions

Diagnose access-denied file share tickets by laddering effective permissions across share vs NTFS vs inheritance and group membership, at least privilege.

Firewall Rule Change Request

Shepherd a firewall change from vague ask to change-ready spec — justification, source/destination/port/protocol, expiry, and routing to the approver.

GDAP Relationship Review

Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.

Group Policy Troubleshooting

Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.

Guest Access Audit

Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.

Hardware Diagnostics

Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.

HIPAA Safeguards Checklist

Walk a healthcare client's environment against the HIPAA Security Rule technical safeguards, returning a checklist of what's in place versus missing.

Hyper-V Clustering

Troubleshoot Hyper-V failover clusters — quorum loss, CSV redirected or offline, failed live migrations, stuck node drains — from cluster and event logs.

Hypervisor Alert Triage

Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.

IIS Web App

Diagnose IIS web app failures — app pool crashes, rapid-fail protection, binding and SSL problems, HTTP 500/502/503 codes — using HTTP.sys and FREB logs.

Industry Pack Frame

Base skill defining how a vertical pack works — the client's calendar first, then blast radius against it, the desk-vs-vendor boundary, and the regulator's data rules.

Internal DNS Server Issues

Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.

Internal IT Offboarding

Offboard departing MSP staff with client-credential rotation first, then tool deprovisioning, ticket reassignment, and client-facing transition notes.

Internal IT Onboarding

Onboard the MSP's own new hire, technician, dispatcher, or back-office, with accounts, PSA/RMM/docs licenses, role-scoped client access, and shadowing.

Intune App Deployment

Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.

Intune Compliance Policies

Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.

Intune Enrollment Troubleshooting

Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

ISP Outage Tracking

Manage a circuit outage while the carrier owns the fix — capture the carrier ticket reference, run the escalation clock, and keep the client informed.

KB Article Draft

Turn a resolved ticket into a reusable knowledge-base article draft with title, symptoms, cause, numbered resolution, and stripped client specifics.

Knowledge Base Taxonomy

Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.

Label and Receipt Printers

Troubleshoot Zebra thermal label and ESC/POS receipt printers — ZPL/EPL print language, driver mode, spooler, and network faults — distinct from MFPs.

Large File Share Guide

Draft reply-ready instructions for an end user to send a file too big for email using the client's approved method — attachment bounced, big file.

LOB Application Framework

Generic playbook for any line-of-business app failure — dental, legal, accounting, ERP — identify vendor and version, pull logs, build escalation packets.

LOB Database Locks

Clear record-locked-by-another-user tickets in LOB apps — find the locking session in the vendor admin console and release it approved-only, never kill DB.

M365 Group Lifecycle

Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.

M365 License Optimization

Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.

M365 Sign-in Issues

Diagnose Microsoft 365 and Entra sign-in failures — blocked sign-ins, MFA loops, repeated password prompts, device-trust errors — from the sign-in log.

M365 Tenant Health Report

Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.

Mac Fleet Management

Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.

Mac Support

The Windows tech's ladder for Mac tickets — keychain prompts, MDM enrollment, TCC app permissions, FileVault — mapping macOS causes vs Windows reflexes.

Mail Flow & Delivery

Diagnose email delivery — NDR bounces, mail not arriving, stuck outbound, one sender blocked — by decoding the bounce and tracing the actual mail path.

Mailbox Migration Prep

Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.

MFA Methods Audit

Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.

MFA New Phone Guide

Draft reply-ready instructions for an end user who got a new phone and needs to move or re-enroll their MFA safely to approve sign-ins again.

MFA Setup Guide

Draft reply-ready instructions for an end user to enroll in multi-factor authentication using the client's actual MFA product for account sign-in.

Mobile Device & MDM

Work mobile MDM tickets — enrollment failures, missing mail profiles, compliance blocks, lost/stolen device response — destructive actions need approval.

Mobile Email Setup

Set up corporate mail on a phone — new-device config, sync failures, MDM enrollment prompts, native Mail vs Outlook — holding the BYOD consent boundary.

Mobile Fleet Review

Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.

Mobile Mail Setup Guide

Draft reply-ready instructions for an end user to get work email on their phone — Outlook mobile app first, matched to the client's mobile policy.

NetSuite ERP

Support NetSuite ERP tickets as an MSP — roles and permissions, saved-search visibility, SuiteScript/REST/CSV integration errors — no financial edits.

Network Device Inventory

Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.

Network Share Slowness

Diagnose slow SMB file shares — sluggish copies, crawling folder listings, one office fine — through SMB version, signing, AV filters, and DFS referrals.

New Computer First Day Guide

Draft reply-ready instructions for an end user receiving a new or replacement computer — what to expect, what to do first, and what NOT to do.

NIST CSF Gap Brief

Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.

Office Activation & Licensing

Fix Office / Microsoft 365 Apps activation — Product Deactivated, unlicensed mode, repeated prompts, shared-computer/RDS errors — detect the license type.

On-Prem to Cloud File Migration

Fix file-server to SharePoint Online and OneDrive migration issues: NTFS permission translation, path length, illegal characters, and sync errors.

OneDrive / SharePoint Sync

Diagnose OneDrive and SharePoint sync — stuck processing changes, missing files, red X icons — separating client state, library limits, and permissions.

OneDrive Known Folder Move

Work OneDrive Known Folder Move rollout tickets — missing Desktop, sync conflicts, path-length and invalid-character legacy files — without unhooking KFM.

OneDrive Restore Guide

Draft reply-ready instructions for an end user to recover a deleted file or roll back a previous version themselves in OneDrive or SharePoint.

OneDrive Storage Governance

Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.

Out of Office Guide

Draft reply-ready instructions for an end user to set their own out-of-office reply correctly — dates, internal versus external messages for OOO.

Outlook Client Issues

Diagnose Outlook desktop crashes, hangs, broken search, password prompts, and crash-on-send using profile, data-file, and add-in isolation branches.

Outlook Profile Setup Guide

Draft reply-ready instructions for an end user to add their work account to Outlook on Windows or Mac — "send the user steps to set up Outlook."

Outlook Search Issues

Fix Outlook search returning nothing or incomplete results by isolating local index vs server search and cached-mode window before rebuilding the index.

PaperCut / PrinterLogic

Diagnose PaperCut and PrinterLogic print-management issues: release stations, driver deployment failures, and quota/account problems from platform logs.

Password Expiry Change Guide

Draft reply-ready instructions for an end user to change a password that's about to expire (or just did) before it locks them out of their account.

PCI DSS Scope Review

Help a client understand PCI DSS scope — what counts as the cardholder data environment (CDE), what's in versus out — not a QSA assessment or AOC.

POS System Issues

Work POS tickets — frozen terminals, failed card payments, back-office sync — by splitting terminal, payment gateway, and back-office with a PCI boundary.

Power Automate Governance

Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.

Print Server Management

Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.

Printer Connect Guide

Draft reply-ready instructions for an end user to add or reconnect the office printer, matched to the client's actual print setup and drivers.

Printer Troubleshooting

Diagnose printing problems — nothing prints, stuck queues, garbled output, wrong printer, scan-to-email fails — via a spooler, driver, and network matrix.

Purview DLP Policy

Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.

QuickBooks Desktop Multi-User

Fix QuickBooks Desktop multi-user errors: H202/H505 hosting, -6000 series company file, stuck locks, via hosting mode and Database Server Manager checks.

QuickBooks Online Issues

Fix QuickBooks Online browser problems: bank-feed failures, multi-user role errors, cache and extension issues; distinguish QBO from Desktop before acting.

RADIUS / NPS Authentication

Diagnose 802.1X and RADIUS authentication failures on Windows NPS: Wi-Fi, wired, VPN rejects, certificates, and shared-secret issues via NPS event logs.

RD Gateway Issues

Fix Remote Desktop Gateway and RD Web Access problems: external RDP failures, certificate errors, CAP/RAP policy mismatches, and MFA integration failures.

RDS / AVD Troubleshooting

Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.

Report Phishing Guide

Draft reply-ready instructions telling an end user what to do with a suspicious email — the client's report-button path, never forwarding around.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

Roaming Profiles & FSLogix

Fix FSLogix and roaming-profile failures on session hosts: cannot attach VHD, temp profiles, sign-in hangs, and settings loss via FSLogix log codes.

Route, Assign and Document

Take a ticket off the intake board end to end: send it to the right queue, assign the best-suited available technician, explain both choices with supporting docs, and log the time.

Safe Attachments and Links Policy

Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.

Safe File Sharing Guide

Draft reply-ready instructions for an end user to share files the approved way — links over attachments, right audience, external-sharing rules.

Sage 50 / Sage 100

Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.

SCADA / OT Awareness

Support OT-adjacent tickets safely: hard IT vs SCADA/PLC/HMI/ICS boundary, never touching controllers, and routing to the correct OT or vendor owner.

Scanner & Copier Fleet

Fix MFP and copier scan-to-folder failures after SMB or credential changes, address-book cleanup, firmware quirks, and panel errors on leased fleets.

Screen Share Help Guide

Draft reply-ready instructions for an end user to start a remote-support screen share with the desk using the client's actual remote tool.

Security Advisory Broadcast

Draft a security advisory going to many clients — new threat, vendor breach, or vulnerability — from verified facts with per-client relevance check.

Security Defaults vs Conditional Access

Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.

Security Questionnaire Vendor DDQ

Draft responses to an inbound vendor security questionnaire or DDQ from documented facts only, cite evidence for each, and flag every unknown for review.

Sensitivity Labels

Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.

Server Patch Windows

Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.

Shared Mailbox Access Guide

Draft reply-ready instructions for an end user to open a shared mailbox they've been granted access to — desktop, web, and mobile paths covered.

SharePoint On-Prem

Diagnose on-premises SharePoint Server: search crawl failures, stale results, content-database mounting, and permission inheritance via ULS crawl logs.

SharePoint Site Provisioning

Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.

Slow Computer

Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.

SOP Builder

Write a standard operating procedure — scope, prerequisites, numbered steps, validation, escalation — from a ticket, a rough doc, or a described process.

SOP Candidate Finder

Sweep recently resolved tickets for documentation-worthy resolutions like recurring fixes and vendor workarounds, ranking SOP and KB article candidates.

SQL Backup and Maintenance

Fix SQL Server backup issues: runaway log growth, FULL vs SIMPLE recovery model, missing log backups, VSS conflicts, and broken point-in-time recovery.

SQL Server Performance

Diagnose SQL Server slowness: blocking, deadlocks, missing indexes, stale statistics, tempdb contention, and parameter sniffing via live wait stats.

SSL Certificate Renewal

Handle SSL and TLS certificate renewals: browser warnings, service certificate expiry, issuer-specific renewal paths, and required service restarts.

SSL Inspection Issues

Diagnose TLS/SSL inspection breakage: pinned apps failing, firewall certificate warnings, apps broken only on corporate networks, and bypass routing.

SSPR Password Reset Guide

Draft reply-ready instructions an end user can follow to reset their own password via self-service password reset without calling the help desk.

SSPR Rollout

Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.

Stale Device Cleanup

Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.

Stale Doc Hygiene

Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.

Storage Capacity Planning

Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.

Supporting Accounting Firms

CPA and accounting firm pack covering Lacerte, ProSeries, and UltraTax software, tax-season freeze windows, and IRS Pub 4557 WISP safeguards.

Supporting Architecture and Engineering Firms

AEC firm pack for AutoCAD, Revit, and Civil 3D support, network license servers, GPU workstations, and submittal-deadline urgency.

Supporting Auto Dealerships

Auto dealership pack covering DMS platforms (CDK, Reynolds, Tekion), OEM tooling, F&I data under FTC Safeguards, and month-end urgency.

Supporting Construction and Field Services

Construction and field-service pack for Procore, Bluebeam, and ServiceTitan, plus rugged tablets, jobsite connectivity, and crew clocks.

Supporting Dental Practices

Dental practice pack covering Dentrix, Eaglesoft, and Open Dental PMS, Dexis-class x-ray sensors, HIPAA, and morning-huddle downtime.

Supporting Financial Services Clients

RIA, broker-dealer, and bank pack covering FINRA/SEC email archiving retention, Orion and Redtail advisory tools, and market-hours urgency.

Supporting Insurance Agencies

Independent insurance agency pack for Applied Epic, EZLynx, and HawkSoft AMS, carrier portals, IVANS downloads, ACORD forms, and E&O trails.

Supporting Legal Firms

Law firm pack covering iManage and NetDocuments DMS, Clio practice management, ethical walls, litigation holds, and court-deadline urgency.

Supporting Logistics and Trucking Clients

Trucking and 3PL pack covering McLeod and Trimble TMS, Samsara and Motive ELDs, DOT/HOS compliance, EDI, and 24/7 dispatch operations.

Supporting Manufacturing Clients

Manufacturing client pack covering the OT/IT boundary, PLC and SCADA hands-off rules, ERP/MES stacks, shift patterns, and line-down urgency.

Supporting Medical Clinics

Medical clinic pack for eClinicalWorks and Athenahealth EMR, e-prescribing, lab interfaces, telehealth, and HIPAA PHI ticket hygiene.

Supporting Municipal Government

City, county, and special-district pack covering public-records email retention, CJIS for PD systems, procurement cycles, and council AV.

Supporting Nonprofits

Nonprofit client pack covering Blackbaud donor CRM, TechSoup and Microsoft grant licensing, board access hygiene, and year-end giving.

Supporting Property Management Clients

Property management pack covering Yardi, AppFolio, and Buildium platforms, tenant portals, owner-tenant data separation, and trust accounting.

Supporting Real Estate Clients

Real estate brokerage and title pack covering Dotloop, SkySlope, MLS and lockboxes, wire-fraud and BEC defense, and agent BYOD sprawl.

Supporting Schools and Education

K-12 school and district pack covering PowerSchool SIS, Canvas LMS, FERPA data hygiene, CIPA filtering, E-Rate, and 1:1 device programs.

Supporting Senior Living Communities

Senior living and skilled-nursing pack covering PointClickCare and MatrixCare EHR/eMAR, nurse-call systems, resident wifi split, and HIPAA.

Switch VLAN and Port Change

Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.

Teams Call Quality

Fix Microsoft Teams call quality: choppy audio, robotic voice, frozen video, and drops via CQD-style device, machine, and network path layer isolation.

Teams Issues

Diagnose Microsoft Teams sign-in loops, meeting join failures, no audio or video, stuck presence, and guest access, with cache reset used sparingly.

Teams Meeting Guide

Draft reply-ready instructions for an end user to join and run a Teams meeting — audio and camera checks, screen sharing, recording basics.

Teams Phone Admin

Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.

Teams Rooms AV

Fix Microsoft Teams Rooms devices: room account sign-in, camera, mic, display, touch console health, calendar join failures, and restart discipline.

Tenant Onboarding Checklist

Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.

Ticket Research Copilot

Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.

Troubleshooting Ladder

Base skill defining the order every troubleshooting playbook works in — history, documentation, blast radius, versions, verbatim evidence, then branch — and how it closes out.

Veeam Restore Operations

Run Veeam restores end to end: pick file-level, application-item, full-VM, or Instant Recovery, choose the right point, target a safe location, verify.

Vendor Escalation Package

Assemble a third-party vendor support package — environment, repro steps, timeline, diagnostics, contract or entitlement reference — credentials stripped.

VMware vSAN and vMotion

Diagnose VMware vSphere: vSAN health warnings, resync storms, vMotion and DRS migration failures, datastore latency, and APD or PDL via vCenter events.

VoIP Phone Matrix

Diagnose VoIP problems: inbound calls failing, ring group misbehavior, one-way audio, dead phones, provisioning fails, by splitting phone vs site vs trunk.

VPN Connect Guide

Draft reply-ready instructions for an end user to connect to their company VPN using the client's actual VPN software and login flow.

VPN Troubleshooting

Diagnose VPN issues: won't connect, authenticates then no traffic, drops while remote, or can't reach resources by name via a client and DNS matrix.

Wi-Fi & Network Troubleshooting

Diagnose Wi-Fi and LAN issues: slow or dropping Wi-Fi, connection failures, dead zones, and internet-down reports by laddering user to AP to site scope.

WiFi Connect Guide

Draft reply-ready instructions for an end user connecting a work device to wifi — office network, home network, and captive-portal awareness.

WiFi Infrastructure Audit

Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.

Windows 11 Migration Issues

Handle post-upgrade Windows 11 migration tickets: driver regressions, reset default apps, missing printers, moved features, with rollback window checked.

Windows Hello for Business

Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.

Windows Profile Corruption

Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.

Windows Update Client Failures

Diagnose Windows Update client failures: 0x8024xxxx and 0x800Fxxxx errors, update loops and rollbacks, and stuck scans across WU, WSUS, and Intune sources.

Working From Home Checklist

Draft a reply-ready remote-work setup checklist for an end user — connectivity, VPN, phone, and how to get help — tailored to the client's stack.

WSUS Patching Infrastructure

Diagnose WSUS server-side issues: clients not checking in, 0% downloads, console crashes, unapproved-but-never-arriving updates, and database bloat.

Liongard

Backup Missed vs Failed Alert

Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.

Certificate Expiry Alert

Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.

Certificate Inventory

Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.

Cyber Insurance Form Prep

Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.

Cyber Risk Posture Review

Review a client's security posture using the cyber risk dashboard, identity data, open detections, and incident history, ranking the top risks.

DHCP Server Issues

Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.

DMARC SPF Failure Triage

Diagnose SPF, DKIM, and DMARC email authentication failures: distinguish real spoofing attempts from sender misconfiguration and explain to the client.

DNS & Domain Issues

Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.

Domain Expiry Alert Lifecycle

Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.

Endpoint Encryption Audit

Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.

Firewall Config Backup Audit

Verify every firewall config backup is current — via Liongard change history or the vendor state — and flag any device whose backup is missing or stale.

Global Admin Audit

Audit a client tenant's global administrator accounts and recent admin-role changes, flagging unexpected admins, missing MFA, and unauthorized grants.

Group Policy Troubleshooting

Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.

Identity MFA Health Check

Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.

Inspector Read Discipline

Base skill defining how any Liongard inspector is read — resolve the environment, date the dataprint, verify field angles live, and state data age in every answer.

Internal DNS Server Issues

Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

IT Roadmap Builder

Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.

Liongard Access Pattern

Base pattern for reading any system's config through Liongard: resolve environment, find inspector by systemType, verify run, query dataprint.

Liongard Active Directory Read

Answer on-prem Active Directory questions via Liongard AD inspector: privileged groups, stale accounts, password policy, GPOs, FSMO, and DC health.

Liongard AWS Read

Answer AWS account questions via Liongard AWS inspector: IAM users, access-key age, root/MFA posture, S3 exposure, security groups, resource census.

Liongard Azure Read

Answer Azure subscription questions via Liongard Azure inspector: resource inventory, spend signals, NSG changes, public exposure, unattached resources.

Liongard Bitdefender Read

Interrogate a client's Bitdefender GravityZone tenant via Liongard: protected endpoints, agent/module status, threat detections, policies, admins.

Liongard Change Review

Answer "what changed recently" from Liongard detections and timelines, correlating environment changes with new tickets after breakage or incidents.

Liongard Cisco ASA Read

Interrogate a client's Cisco ASA firewall via Liongard: software version, interfaces, ACLs/NAT, IPsec/AnyConnect VPN config, and admin access review.

Liongard Cisco Network Read

Interrogate Cisco IOS/IOS-XE switches and routers via Liongard: IOS versions, running-config change detection, port/interface inventory, VLAN layout.

Liongard ConnectWise Automate Read

Interrogate ConnectWise Automate (LabTech) via Liongard: managed computer inventory, agent check-in status, patch state, monitors, and locations.

Liongard Cross-Client Census

Answer "which clients run <system>?" across the book via Liongard launchpoint inventory: install-base census for zero-days, EOL waves, vendor risk.

Liongard Datto RMM Read

Interrogate a client's Datto RMM footprint via Liongard: managed device inventory, agent online status, patch state, monitored alerts, and sites.

Liongard Duo Read

Answer Duo MFA posture questions via the Liongard Duo inspector: enrollment coverage, bypass users, admin list, and protected-integration inventory.

Liongard Email Security Config Read

Read a client's Mimecast/Proofpoint-class email security config via Liongard: policy posture, connector state, and config drift without admin console.

Liongard Exchange On-Prem Read

Interrogate on-premises Microsoft Exchange via Liongard: server version/CU/build, databases, mailbox inventory, connectors, and admin access review.

Liongard FortiGate Read

Interrogate a client's FortiGate via the Liongard Fortinet inspector: FortiOS firmware, policy changes, VPN tunnels, admin accounts, license state.

Liongard Google Workspace Read

Answer Google Workspace tenant questions via Liongard: super admin roles, 2SV coverage, license usage, and Drive-sharing posture for Google clients.

Liongard Hyper-V Read

Interrogate a client's Hyper-V hosts via Liongard: host and VM inventory, checkpoint sprawl, replica health, and VM placement and power state.

Liongard Internet Domain & TLS Read

Answer domain, DNS, and TLS questions via Liongard Internet Domain and TLS inspectors: registrar, expiry, DNS changes, mail-auth records, cert sweeps.

Liongard JumpCloud Read

Interrogate a client's JumpCloud directory via Liongard: users, MFA enrollment, admins, groups, bound systems, and SSO app assignments for reviews.

Liongard Kaseya VSA Read

Interrogate a client's Kaseya VSA footprint via Liongard: managed agent inventory, online status, patch state, monitor sets, and machine groups.

Liongard M365 Tenant Read

Answer tenant-level Microsoft 365 questions via the Liongard M365 inspector: license assignment, mailbox stats, admin roles, secure score, sharing.

Liongard Meraki Read

Interrogate a client's Cisco Meraki org via the Liongard Meraki inspector: SSIDs, VLANs, firmware, admin list, device inventory, and license state.

Liongard Mimecast Read

Interrogate a client's Mimecast tenant via Liongard: managed domains, users and licenses, policies, connectors and routing, and admin accounts.

Liongard N-central Read

Interrogate a client's N-able N-central footprint via Liongard: managed device inventory, agent/probe status, patch state, monitored services, sites.

Liongard Network Documentation Sync

Diff what Liongard inspectors see (firewalls, switches, wireless, hypervisors, servers) against the doc platform and draft network-doc corrections.

Liongard Okta Read

Answer Okta tenant questions via the Liongard Okta inspector: app assignments, admin roles, MFA policies, and deactivated-user hygiene reviews.

Liongard Palo Alto Read

Interrogate a client's Palo Alto firewall via Liongard: PAN-OS version, config changes and commit history, admin activity, HA state, policy posture.

Liongard pfSense Read

Interrogate a client's pfSense firewall via the Liongard pfSense inspector: version, interfaces, firewall/NAT rules, VPN config, packages, admins.

Liongard Proofpoint Read

Interrogate a client's Proofpoint Essentials tenant via Liongard: protected domains, users and licenses, filtering policy, spooling, and admins.

Liongard QBR Evidence Pack

Assemble QBR-grade posture evidence for one client from Liongard inspectors: identity risk, EOL exposure, cert/domain hygiene, and config drift.

Liongard SentinelOne Read

Interrogate a client's SentinelOne tenant via Liongard: protected agents, agent/version health, threat detections, policy/site assignment, admins.

Liongard SonicWall Read

Interrogate a client's SonicWall via Liongard: SonicOS firmware, security-services licensing and expiry, access rules, VPN policies, admin accounts.

Liongard Sophos Central Read

Interrogate a client's Sophos Central tenant via Liongard: protected endpoints, threat/health status, tamper protection, policy, and admin list.

Liongard Sophos Firewall Read

Interrogate a client's Sophos Firewall (XG/SFOS) via Liongard: firmware, firewall rules, port-forwards/NAT, VPN config, interfaces, admin access.

Liongard UniFi Read

Interrogate a client's Ubiquiti UniFi controller via the Liongard inspector: device inventory, adoption state, firmware drift, and WLAN/network config.

Liongard Veeam Posture Read

Interrogate a client's Veeam deployment via Liongard: job inventory and schedules, repository capacity, protected-VM census, and license state.

Liongard VMware Read

Interrogate a client's vCenter/ESXi estate via Liongard: host versions and build levels, datastore capacity, snapshot sprawl, VM inventory/placement.

Liongard WatchGuard Config Read

Interrogate a client's WatchGuard Firebox posture via Liongard: Fireware version, subscription/licensing, policy inventory, VPN config, admin accounts.

Liongard Webroot Read

Interrogate a client's Webroot GSM console via the Liongard Webroot inspector: protected endpoints, agent status, threat state, policy, and sites.

Liongard Windows Server Read

Interrogate a client's Windows Servers via Liongard: installed roles, local admin members, services, patch level, OS version and end-of-life flags.

Mobile Fleet Review

Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.

Monthly Security Report

Produce a client's monthly security digest: incident and alert counts, notable events, posture trend, and recommendations for client or internal review.

Network Device Inventory

Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.

NIST CSF Gap Brief

Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.

Patch Compliance Review

Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.

QBR & SBR Prep

Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.

RAID Degradation Alert

Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.

RDS / AVD Troubleshooting

Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

Sage 50 / Sage 100

Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

Server Decommission Runbook

Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.

Server Diagnostics

Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.

Switch VLAN and Port Change

Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.

Tenant Onboarding Checklist

Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.

Typosquat Domain Alert

Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.

Warranty and EOL Report

Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.

WiFi Infrastructure Audit

Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.

NinjaOne

Acronis Cyber Protect

Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.

Alert Reset With Note

Reset a NinjaOne alert only after the condition is genuinely healthy, posting an explanation note first. Attended or embedded in a recovery Flow.

AV/EDR Agent Offline Alert

Triage an AV/EDR agent-offline alert — decide if the device is off or up with a dead agent, quantify unprotected time, and route on the protection gap.

Axcient Backup Alerts

Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.

Backup Failure Triage

Classify a backup failure by alert text and device state, check for recurrence, and decide whether to fix locally or escalate to the backup vendor.

Backup Missed vs Failed Alert

Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.

BSOD Analysis

Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.

Budget Planning Brief

Prep a client's annual IT budget conversation — hardware refresh forecast, license spend, and project pipeline — from tickets, assets, and roadmap items.

Client-Facing Device Report

Produce a sanitized device inventory and health report a client contact can read — counts, health, risks in plain business language, no raw tool output.

Conference Room AV

Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.

Cyber Insurance Form Prep

Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.

Datto BCDR Verification

Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.

Device Approval Review

Work the RMM pending-device approval queue — sort expected onboarding or replacement agents from unexpected ones, approving or rejecting with rationale.

Device Health Check

Diagnose one device via the RMM — alerts, activities, services, disk, reboot, and patch posture — then propose remediation with a deep-link handoff.

Device Offline Runbook

Work a device-offline alert or "won't connect" ticket — site-wide check first, maintenance windows, last activities, and clear escalate criteria.

Device-to-User Mapping

Answer "who uses this device" by combining RMM last-logged-on data with contact records, ticket history, and documentation when a ticket names only one.

Disk Space Alert

Triage a low-disk-space alert from any monitor — separate threshold noise from real pressure, read growth rate from history, rank consumer hypotheses.

Disk Space Remediation

Work a disk-pressure alert or full-drive ticket — identify likely consumers from RMM signals and give the tech a safe cleanup sequence with a device link.

EDR Detection Runbook

Work an EDR malware or suspicious-process alert: pull RMM device context, check EDR containment, confirm with the user, then escalate or close.

Endpoint Encryption Audit

Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.

Fleet Health Sweep

Sweep a client fleet through the RMM — offline devices, alert clusters, disk pressure, and missing patches — ranked into the top issues needing attention.

Hardware Diagnostics

Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.

Hardware Refresh Forecast

Build a 4–5 year hardware refresh workbook per client — devices crossing the age threshold each period and the per-client refresh budget for planning.

High CPU/Memory Alert

Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure via history, and route servers versus workstations differently.

Huntress EDR Incident

Work Huntress EDR incident reports: foothold, persistence, or active endpoint threats. Read what Huntress isolated, finish remediation, and verify closure.

Hypervisor Alert Triage

Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

IT Roadmap Builder

Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.

License Billing Reconciliation

Reconcile a client's billing against reality — RMM devices, license export, onboarding tickets — to find missed adds, missed removals, and discrepancies.

Mac Fleet Management

Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.

Maintenance Mode Workflow

Put a device into or out of RMM maintenance mode with an explicit duration and reason, plus a follow-up task so monitoring is re-enabled on schedule.

MDR Client Onboarding

Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.

Mobile Fleet Review

Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.

NAS / File Share Provisioning

Plan and document a new network share — folder structure, permission model, quota, backup inclusion — with an approval gate on the access model first.

Network Device Inventory

Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.

Network Outage Triage

Triage a suspected site-down — all-devices-offline vs single dead device, ISP vs internal, who to call, and set a comms cadence for the client updates.

New Workstation Imaging Checklist

Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff.

NinjaOne Alert Types

Classify NinjaOne condition and threshold alerts (offline, resource, service, patch, hardware, security) and route each class with a deep-link handoff.

NinjaOne Device Lookup from a Ticket

Figure out which device a ticket is about — from the person, their remembered devices, or a hostname in the thread — find it in NinjaOne, and drop the live device details and a deep link into the ticket so the tech starts with context.

Patch Compliance Review

Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.

Patch Failure Alert

Triage a patch-failure alert — separate a one-off from a repeat offender, detect reboot-pending as the usual culprit, correlate against the patch window.

Print Server Management

Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.

Printer Fleet Review

Cluster a client printer-related tickets to find chronic devices, quantify the time they burn, and recommend replace-vs-repair per problem printer.

QBR & SBR Prep

Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.

RAID Degradation Alert

Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.

Ransomware Response

Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.

Reboot Request Workflow

Reboot a device via the RMM with user approval — confirm logoff or saved work, choose normal vs forced deliberately, and verify the device comes back up.

Recurring Maintenance Tickets

Verify scheduled maintenance tickets (backup checks, patch cycles, monthly server reviews) carry real completion evidence and flag skipped cycles fast.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.

Seat Count True-Up

Monthly true-up for per-seat and per-device agreements — compare actual counts from RMM and onboarding tickets against billing, and produce evidence.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

SentinelOne Ranger

Work SentinelOne Ranger network-discovery findings: read the rogue or unmanaged-device signal and drive to identify-then-manage without blind action.

SentinelOne Threat Verdict

Triage SentinelOne threat detections: read static vs behavioral engine verdicts, direct kill, quarantine, rollback, and hold on exclusion requests.

Server Decommission Runbook

Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.

Server Diagnostics

Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.

Server Patch Windows

Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.

Service Restart Runbook

Restart a crashed Windows service via the RMM — allowlisted safe services only, state verified before and after, with a ticket note posted on completion.

Slow Computer

Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.

Sophos Endpoint Alerts

Triage Sophos Central endpoint alerts: read health status and cleanup result, handle tamper protection correctly, and verify cleanup before closing.

Storage Capacity Planning

Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.

Ticket Research Copilot

Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.

Veeam Job Failures

Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.

Vulnerability Report Triage

Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.

Warranty and EOL Report

Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.

Warranty Claim Handling

When a device fails and you need to know whether it's under warranty, how to file the claim, and how to arrange a loaner while it's away.

WatchGuard Firewall Alerts

Triage WatchGuard events: Firebox offline in WatchGuard Cloud, AuthPoint MFA push and token trouble, and mobile VPN authentication failures on the desk.

Webroot Legacy AV

Work Webroot or other legacy signature-AV detections with thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.

WiFi Heatmap / Site Survey Request

Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.

WiFi Infrastructure Audit

Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.

Windows 11 Readiness Assessment

Assess which client devices can upgrade to Windows 11 — CPU generation, TPM, RAM, and edition flags from RMM device details — with an upgrade-blocker list.

Windows Profile Corruption

Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.

Zero-Day Emergency Response

Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.

Zapier

Automation Failure Watch

Detect automation-error signatures in notes — 4xx/5xx bodies, Jinja errors, webhook failures — flag the ticket and ping Teams so broken flows get noticed.

Billing Forensics

When someone asks "why is the client billed X" and the charge needs to be traced to its source across tickets, time entries, agreements, and vendor invoices.

Calendar-Aware Scheduling

Put ticket work on a technician's schedule around their real calendar — check busy periods before proposing a slot, then book it onto the calendar.

CSAT Follow-Up Loop

Close the CSAT loop after ticket closure: confirm the survey went out, pull the response into the ticket as a note, and flag detractors to a lead.

Entra User Lifecycle (Zapier)

Create, update, or disable Microsoft Entra ID users through the Zapier connector with identity resolved from the PSA and approval gated on every write.

QuickBooks Invoice Draft

When time-and-materials work on a ticket is done and you want a QuickBooks invoice drafted from its time entries — created as a draft, never sent.

Sales Handoff Routing

Move a service ticket that turns out to be a sales conversation, a purchase, renewal, expansion, or pricing question, to the sales board and account owner.

Stripe Payment Link

When approved out-of-contract work needs to be paid and you want a Stripe payment link generated and placed in the ticket reply draft.

Weekly QA Digest

Compile the week's closure-QA failures into a digest with per-technician patterns and concrete training suggestions, ready to email or post to the team channel.

Zapier Action Discovery

META skill — before promising a workflow with an external app, verify a Zapier action exists, what fields it takes, and its task cost.

Zapier DocuSign Authorization

Send change-authorization or offboarding-acknowledgment for signature from a ticket via DocuSign, track completion, and file the signed document.

Zapier OneDrive User Files

Work a user's OneDrive during troubleshooting — fetch specific files, run KQL search for lost documents, and mint sharing links with hygiene.

Zapier Outlook Calendar Booking

Book remote sessions and onsite visits on the tech's Outlook calendar — Create Event with Teams link, attendees, ticket reference, mirrored in Thread.

Zapier Outlook Client Email

Send or draft email from shared mailboxes via Outlook and pull a requester's recent emails into ticket context for support conversations.

Zapier PagerDuty On-Call

Page the on-call engineer for a P1 via PagerDuty, tell the requester who was paged, and mirror the ack/resolve loop back to the ticket.

Zapier QuickBooks Time & Billing

Push ticket time entries into QuickBooks as Time Activities and draft (never send) an invoice for out-of-contract work, gated by approval.

Zapier SharePoint Ticket Filing

File ticket artifacts — reports, PIRs, signed docs — into the client's SharePoint library with correct foldering and sharing-link hygiene.

Zapier Slack Approval Request

Use Slack "Request Approval" as the human-in-the-loop gate before privileged or irreversible actions when the desk lives in Slack, not Teams.

Zapier Slack Escalation Ping

Ping the right engineer in Slack — DM or channel — with a one-line brief and ticket link when a ticket needs eyes now, with anti-nag dedupe.

Zapier Teams Approval Gate

Use Teams "Send Approval Request and Wait" as the human-in-the-loop gate before privileged actions — offboarding, admin changes, out-of-contract spend.

Zapier Teams Ticket Notifications

Post ticket updates and escalations into Microsoft Teams channels — client shared channels, internal escalations channel, or per-board feeds.

Zapier Webhook Generic

The escape hatch — fire a generic webhook (Rewst, custom automation, homegrown endpoint) from a skill when no named Zapier app covers the system.

Zapier Xero Billing

For Xero-shop MSPs — draft (never send) invoices from ticket time entries and check a client's overdue-invoice standing before billable work.

ConnectWise RMM

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

License Billing Reconciliation

Reconcile a client's billing against reality — RMM devices, license export, onboarding tickets — to find missed adds, missed removals, and discrepancies.

Mac Fleet Management

Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.

MDR Client Onboarding

Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.

Patch Compliance Review

Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

Seat Count True-Up

Monthly true-up for per-seat and per-device agreements — compare actual counts from RMM and onboarding tickets against billing, and produce evidence.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

Server Patch Windows

Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.

Vulnerability Report Triage

Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.

Zero-Day Emergency Response

Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.

Notion

Environment Facts Updater

When a ticket reveals a changed client environment fact — new server, ISP, VPN, or key contact — draft the update for the client documentation platform.

Knowledge Base Taxonomy

Design a knowledge base category hierarchy and controlled tag vocabulary with naming and placement rules, grounded in what the desk actually documents.

New Hire Onboarding Coach

Interactive onboarding practice for new techs: walk a trainee through real tickets, have them draft the customer reply, and score it against a six-point response rubric.

Notion Change Log

Append approved changes to a queryable Notion change-log database — what changed, for which client, who approved, and the source ticket.

Notion Client Runbook Database

Create and maintain a Notion client-runbooks database, one entry per client per system, updating entries when tickets reveal environment changes.

Notion Intake Forms

Build a Notion form view for structured requests (new hires, access, project intake) and convert submitted rows into tickets without another vendor.

Notion Onboarding Tracker

Run a new-hire progress tracker in Notion — read trainee status, update checklist items and quiz results, and answer "how is <new hire> doing".

Notion QBR Page

Assemble a client QBR pre-read as a Notion page — ticket volume vs prior period, top issues, SLA picture, and recommendations with data views.

Notion SOP Publishing

Turn a resolved ticket into an SOP page in the team's Notion runbooks teamspace, tagged by client, product, and category, with link back to ticket.

Stale Doc Hygiene

Find documentation untouched for 180+ days, test it against current ticket reality, and produce a verification task list of docs to confirm, update, or retire.