Imagine you’re reviewing a client’s environment when you find an AI assistant connected to company tools through an employee’s personal account. The employee wanted to get work done faster. The client never asked you to review the setup because they didn’t know it existed.
Before you can recommend anything, you need to understand what the assistant can reach, who’s responsible for it, and whether that access is appropriate. Your client needs those answers too, even if they’ve never used the phrase “AI governance.”
For an MSP, this is a practical place to start building a service. You have a client question to answer and work you can scope around it. As you work through what the client needs, the shape of the offering becomes clearer.
The MSP Guide to Securing and Selling Agentic AI explores how to turn those needs into a service clients can buy. Here’s how that conversation can develop, from the first discovery to an ongoing engagement.
Start by Showing the Client What’s Running
A client can tell you which AI tools they’ve approved without knowing everything their employees use. Personal accounts, browser extensions, and connections to coding assistants which can sit outside that approved list.
Asking whether the business “uses AI” may therefore leave you with an incomplete answer. A more useful conversation looks at the tools people actually use, the systems they’ve connected, and the information those tools can access.
That work has value before you’ve proposed an ongoing contract. A fixed-scope, paid discovery assessment can help the client understand their environment and decide what deserves attention.
For your MSP, it also provides a sound basis for the next recommendation. You’re proposing work in response to what you’ve found, with a scope the client is able to understand.
Give Each Agent Someone Who Is Responsible for It
Discovery is the beginning of the conversation. If you find an agent acting on the client’s behalf, someone needs to be responsible for what it does.
Consider an agent created for a particular project. Its creator moves to another team, but the agent keeps running with the access it was originally given. Unless ownership is maintained, the client can end up with an active identity that nobody is reviewing.
This gives you a concrete need to address: record the agent’s purpose, assign an accountable human owner, and review whether its access still fits its work. An agent also needs its own identity so its activity can be distinguished from a person’s actions or a shared account.
Keeping those records current is continuing work. People leave, projects end, and permissions need to change. That is the part of the value an ongoing governance service can provide after the initial assessment.
Make Sure the Client Can Act on What You Find
Knowing who owns an agent won’t be enough if nobody can withdraw its access when its purpose changes or its activity needs investigation.
Once you’ve established ownership, the conversation needs to cover control: what the agent should be able to reach, who can change that access, and how it can be revoked.
For the client, these are practical questions about running their business. They want useful AI tools to keep working, with a way to intervene when necessary. Your service should make those responsibilities clear.
That clarity also helps you scope the work. Reviewing access, maintaining policies, and handling revocation are specific activities you can discuss and package. A broad promise to “secure AI” leaves much more room for misunderstanding.
Give Them a Record They Can Use
The client may later need to explain an agent’s activity to a business leader, an auditor, or someone investigating an incident. Knowing that an action occurred is only part of the answer. They may also need to establish which agent acted, who owned it, and what access it had.
Activity records tied to an agent’s identity can help answer those questions. They also give your team something to review when deciding whether the agent still needs its permissions.
This is where reporting becomes a useful part of the service. It supports the client’s oversight and gives you a basis for discussing what needs to change as their AI use develops.
Match the Offering to the Client’s Starting Point
By now, the service has a recognizable scope: discover AI use, establish ownership, manage access, and maintain visibility into activity. The commercial model should reflect how much of that help the client needs.
A client still figuring out what’s running may be best served by a standalone assessment. A client already asking for continuing oversight may be ready for an add-on to their agreement or coverage within your premium tier. Where the need is ongoing advice, a retainer can provide dedicated time each month.
The delivery costs matter too. Before choosing a package, consider what your team can support through its existing identity and device capabilities and where additional work or tooling would be required.
The first conversation doesn’t need to settle all of this. It needs to establish what the client doesn’t yet know and whether you can help them make a better decision. A useful assessment can create the basis for a longer relationship, with ongoing work that both sides understand.
To work through the offering for your own MSP, download The MSP Guide to Securing and Selling Agentic AI. It explains four ways to package AI governance and how JumpCloud’s Agentic IAM platform supports the discovery, identity, access, and oversight behind the service.