CrossTenant
Home / Features / AI assistant

AI that reads the whole fleet

An assistant that can see posture, drift, alerts, and activity across every customer, wrapped in a governance model built for MSPs. It proposes, you confirm, and the audit log remembers.

Prefer email? Get in touch and we run onboarding with you.

What's included

Fleet-wide answers

Ask once and the assistant answers across your whole book (security posture, policy drift, alert activity, admin changes), streamed as it works. Answers are advisory: reading the fleet never changes it.

streamed advisory fleet context

Executive summaries on reports

Reports can open with an AI-written executive summary: the plain-English paragraph a customer actually reads, generated from the same data the report charts.

Drafted fixes, never direct action

When the assistant spots something fixable, it drafts a proposal from a fixed registry of known actions. It cannot invent an operation, and every draft is re-validated server-side, fail-closed. The model proposes; only an operator executes.

action registry fail-closed proposer-not-actor

Dry-run first, then a confirmation ladder

Every proposed action goes through the same dry-run preview as a manual bulk change, and confirmation scales with risk: routine actions ask you to confirm the affected count, unusual ones get a full interstitial. Content an action carries, like a signature, is typed by the operator, never generated into place.

dry-run count-confirm interstitial

Audit-stamped, tamper-evident

Anything executed from an AI draft is marked ai-assisted in the audit log, with the prompt that produced it recorded alongside. The log itself is hash-chained, so the record of what the AI touched cannot be quietly edited afterwards.

ai-assisted prompt recorded hash-chained

Redaction before every call

Mailbox and file contents are stripped before anything is sent to the model. It reasons over settings, posture, and metadata, not your customers' email. The guard sits on every AI code path and is tested to fail if raw content ever reaches a payload.

content redaction settings & posture only

Off until you say otherwise

The AI master switch ships off. Nothing model-facing runs until an operator enables it. Postures are then set per action and per engineer, and they only ever tighten: a permissive default can be restricted anywhere down the chain, never loosened.

master switch tighten-only per-engineer

Gemini policy oversight

Separately from CrossTenant's own assistant, the AI & Gemini page shows each customer's Google-side Gemini and AI settings across the fleet: who has what enabled, tenant by tenant. That is Google's AI, surfaced; the governed assistant above is CrossTenant's.

google-side settings per-tenant view

AI features are optional and stay off until an operator enables them. The assistant is built on Claude, Anthropic's language model. The redaction, confirmation, and audit rules above apply to every call regardless.

AI, governed

Intelligence without handing over the keys

Turn the assistant on when you are ready. It ships off, and every action it drafts still goes through you.