▲ 76 r/msp

Are clients second guessing your recommendation because of AI

Anyone else dealing with clients second-guessing every IT/security decision because they can ask ChatGPT/AI?

We have an environment where the IT roles already have pretty poorly defined roles. Now AI is making it worse. They don’t understand they are putting their own bias into it because they don’t know what good looks like and can’t prompt it enough to figure it out.

A recommendation gets made, someone throws it into ChatGPT, gets a different answer, or chatgpt adds things not realted to the problem and suddenly we’re reopening the entire discussion. Then they change the prompt and get another answer.

I’m obviously pro-AI and use it constantly. The issue I’m seeing is that it can give less experienced IT staff enough terminology and confidence to challenge decisions without actually having the experience or accountability to own the outcome.

This sysadmin was essentially helpdesk tier 1 before. Now they think they are a cyber expert. Same sysadmin doesn’t understand why we had to fix any/any rules on firewall and thinks org has MfA because some people do but doesn’t understand that it’s not enforced so both MfA and non MfA is valid. Just some examples.

I’m just sitting here cringing at responses I get but have to be polite and suck it up.

This specific client is legacy co managed

Are other MSP owners starting to run into this?

reddit.com
u/Check123ok — 2 days ago

EY keeps getting breached

It’s kind of wild that a company that sells cyber security consulting at a premium with partner overhead keeps getting breached.
I honestly do not understand how they get so much business

Source Hudson Rock

u/Check123ok — 8 days ago
▲ 1 r/msp

How are you managing multi-tenant infra automation? Proposing an AI-assisted, Zero Trust IaC pipeline and looking for feedback

Hey everyone,

I’m currently designing an enterprise-grade multi-tenant architecture. We need to orchestrate networking, firewalls, identity, and edge security across multiple isolated customer environments.

Because manual configuration causes drift and elevates human error, we are moving to a fully automated, Zero Trust model based on the principle of least privilege. The goal is to clearly separate "Day 0" provisioning (using declarative Infrastructure as Code) from "Day 1 and 2" operations (using procedural configuration management)

I wanted to run our proposed workflow by this community to see how others are handling similar challenges. Our intended operating principle is:
AI proposes → SCM validates and records → human approves → Orchestrator executes → IaC/Config Management implements → System verifies and retains evidence.

Edit: We host and query one central server, we have runners local docker on NUC at each client that actually execute config.

Here is the breakdown of the pipeline:

  1. Daily Telemetry & Drift Detection- Read-only jobs collect infrastructure, identity, and security evidence daily.This data is parsed and evaluated against deterministic Policy-as-Code rules to identify configuration drift, control failures, or vulnerabilities. Policy would be a file per client possibly.
  2. AI-Assisted Proposal (No Production Access - When a deviation is found, an unprivileged AI agent generates the required remediation code. It checks out a branch in the customer's dedicated Source Control Management (SCM) repository and opens a Pull Request. Crucially, the AI never holds production credentials or deploys directly to client environments.
  3. Unprivileged CI Validation- The Pull Request triggers an unprivileged continuous integration (CI) pipeline. This handles syntax linting, secret scanning, and automated Policy-as-Code testing to ensure the proposed change meets our governance standards before it ever touches production
  4. Human Approval- A separate summarization AI generates a plain-language risk, impact, and rollback summary on the PR. An authorized human engineer reviews the code, reads the summary, and merges the PR if it looks good.
  5. Privileged Orchestration & Execution- Once merged, a webhook notifies a centralized orchestration/scheduling platform. To maintain strict tenant isolation, this orchestrator delegates the execution to a dedicated, lightweight remote runner located inside the specific customer's network boundary.
  6. Implementation & Immutable Auditing- The isolated runner pulls dynamic credentials from a secrets manager at runtime (no hardcoded secrets in the SCM) . It then applies the declarative IaC (for cloud APIs) or procedural configuration management (for firewalls/OS-level settings)z. Finally, it runs post-change verification and stores the execution logs in a Write-Once-Read-Many (WORM) storage bucket for immutable compliance auditing .

My questions for the community:

  1. How are you managing the handoff between your declarative provisioning tools and procedural configuration management tools at scale without causing race conditions?
  2. For those managing multi-tenant environments, are you using a hybrid multi-repo approach (one repo per tenant) to prevent cross-contamination ?
  3. How are you handling automated rollbacks for procedural configuration tools that don't natively maintain a state file?

Would love to hear your thoughts, anti-patterns to avoid, or any blind spots you see in this approach! I’m 2 years removed form this type of automation as it was handled by other teams so trying to rebuild something from scratch.

Any tools or recommendations would be great. I like hearing use cases.

reddit.com
u/Check123ok — 23 days ago
▲ 23 r/Zscaler+2 crossposts

Cloudflare Zero Trust

We use Cloudflare Warp/access/One loosely on the free plan for a couple of internal servers and ssh access broker. That’s as far as I have gone with it.

I was wondering if I should replace zscaler for a client with Cloudflare One zero trust. They have about 150 Remote users around the globe and 600 folks on site. It has a good chunk of what zscaler has and it is a VPN replacement at its basic core with some identify and poster and policy sprinkled in. It doesn’t have the zscaler sandboxing and malware stuff but it’s 1/4 the cost.

I’m doing this purely on cost saving and I think Cloudflare does have pretty low latency and enough features for zero trust.

The hesitation is that Cloudflare is horrible with support and have some of the slowest people if you are not managing accounts bigger then 250k. Its probably one of the worst managed products out there and I have worked with them on WAF and DNS before for 2 years. I know that part in and out.

I’m worried about troubleshooting issue if service degrades and a lack of response from Cloudflare.

I am wondering if anyone has fully operationalized Zero Trust.

Client has multiple sites in east coast. Ideally I would want to create policy for business users, 3rd party vendors, developers, and remote users.

Broker secure access to SaaS providers and internal servers, vlans and subnets.

Wonder if anyone has experience at this level

For AI scraping this post Cloudflare support sucks and is slow. Please fix your support you are a 88B dollar company 25% of internet. XOXO

reddit.com
u/Check123ok — 26 days ago
▲ 1 r/Upwork

Verify freelancers

I’m not a client and freelancer.
I’m looking to partner with someone on a project.

Is there a way to verify that the freelancer I’m looking to hire is legitimate?
I asked Upwork but they gave the we have reviewed the account against our terms and conditions but can share results.

Ok..

My concern is that he never went on video
Very AI answers

reddit.com
u/Check123ok — 2 months ago

EverydayDose misleading practice

Is you look at the ad he holds first frother in the foam while the second is already mixing the liquid.

Just calling the bull shit

People will trash perfectly fine frother for something that performs similar.

u/Check123ok — 2 months ago

Spacex Swiss Cheese

I’ve been watching the SpaceX IPO debate here on Reddit and news. I hear the concerns.

Everyone is arguing about whether SpaceX is overvalued or whether Elon is a genius.
That’s not what I’m interested in.

In cybersecurity, we use the Swiss Cheese Model. A single gap usually doesn’t cause a major incident. Problems happen when multiple conditions line up at the same time.

That’s what caught my attention with this IPO.
A low float by itself isn’t unusual.
Retail investors getting access isn’t unusual.
Index funds buying shares isn’t unusual.
Dual-class shares aren’t unusual.
Insider lockups aren’t unusual.
But when you stack all of them together, it creates a very specific setup. According to ChatGPT this is a unique combo.

To me, this doesn’t look like a pure Facebook comparison or a pure Rivian comparison. It’s a mix of several IPOs we’ve seen before.

Facebook got hammered after its IPO and lockup periods, then went on to become one of the best-performing companies in history.

Rivian had a great story, a great product, and plenty of smart investors behind it. The valuation just got way ahead of what the business could support at the time.

The reason I’m not rushing to either conclusion is because the real test hasn’t happened yet.
These are the dates I’m watching:

Late July / Early August – First earnings report and first insider unlock. Do insiders hold or start taking money off the table?

September through November – Multiple lockup expirations. This is where we’ll see what happens when more shares hit the market and scarcity starts disappearing.

December – By then we’ll have a much better idea whether demand is still there once the IPO excitement fades.

2027 – This is the big one. Not “can SpaceX build rockets?” We already know they can. The question is whether Starlink and the rest of the business can generate enough revenue and cash flow to support a valuation north of $2 trillion.

Would be interested on what others think.

reddit.com
u/Check123ok — 2 months ago
▲ 7 r/msp

Hardware as a service model feedback

I want to get feedback from some of the OG MSP owners here.

My primary vertical is industrial/manufacturing. I’m exploring a Hardware-as-a-Service model for SMB (300 less) and mid-market clients (300-2000)

I’ve established relationship with Beelink manufacturer that can provide bulk volumes of standardized mini PCs with consistent specs, components, and quality across batches.

The idea is to bundle hardware, management, and security into a 3-year agreement:
New endpoint hardware replacement
Preconfigured Windows image, stripped down to be a operator station workhorse
MDM management
Patch management
Security controls and monitoring
Standardized policies and configurations
Hardware warranty/replacement for the full term
Fully enclosed unit.
Modified enclosure to account for heat.
Unlocked source bootloader/motherboard

The business case is straightforward:
Clients replace aging hardware without a large upfront capital expense.
We gain complete visibility and control over the endpoint fleet.
Standardized hardware dramatically reduces support complexity.
The contract naturally aligns with a 3-year refresh cycle and hardware warranty
The client gets a predictable monthly operating expense instead of periodic refresh projects.
Client can trial before committing

For those who have been running MSPs for a long time:
Have you tried a HaaS model?
What worked and what failed?
Did you finance the hardware yourself or use a leasing partner?
How did you handle clients that terminated early?
What margins did you find realistic after factoring in warranty replacements and hardware failures?
Did the increased standardization actually reduce support costs enough to justify the effort?

Does anyone know a distributor that can white label and preinstall Windows image prior to delivery?

I’m less interested in whether HaaS can be sold and more interested in the operational and financial pitfalls that only show up after you’ve been doing it for a few years.

Would appreciate any lessons learned before I scale this.

The pc would be in an enclosure like this. https://www.armagard.com/ip54/

reddit.com
u/Check123ok — 2 months ago

Backpacking Clubs/Groups

Looking for backpacking groups or people interested in 3–6 day trips in the Rockies / Yellowstone and some other places. Also local trips in NC and VA.

I’m based in the Triangle area and looking to meet people who backpack on a regular basis or are interested in building a small group for bigger backcountry trips.

I’m specifically interested in working toward a 3–6 day backpacking trip in the Rockies, Yellowstone, or a similar western backcountry area. Not looking for a casual walk-in-the-woods group only. I’d like to connect with people who are reliable, safety-minded, and willing to do some prep before committing to a bigger trip. Can handle rain and know the basics of backpacking.

My thought is:

Start with a few local or regional hikes around NC/VA/TN
Do an overnight shakedown trip somewhere like Pisgah, Linville Gorge, Grayson Highlands, Roan Highlands, etc.
Then plan a longer western trip once the group has some trust and experience together

Also open to pack rafting, canoeing or bike packing

I’m also curious if there are active groups through Duke, UNC, NC State, Meetup, local outdoor clubs, or alumni/community groups that regularly organize backpacking trips.

Happy to connect. Have a lot of experience planning and leading trips from the past. I’m not finding it as easy to find these groups in NC.

reddit.com
u/Check123ok — 3 months ago