Built for MSPs and IT teams
Give your team AI access to your tools — without giving up control
Ridge is a secure MCP gateway that connects Claude, ChatGPT, Microsoft Copilot, and Cursor to Autotask, Hudu, Datto RMM, Microsoft 365, and more — with per-user permissions, per-client scoping, approval on destructive actions, and a full audit trail.
- 13
- integrations, live today
- 0
- shared API keys
- Every
- action audited
- Any
- MCP client
The problem
Every AI client can call your PSA and RMM now. Almost none of them are governed.
Claude, ChatGPT, and Copilot can all reach your business tools today. What's missing is the layer between the model and the tool: identity, least privilege, approval, and audit.
One shared vendor key
Most AI-to-PSA/RMM setups run on a single API key handed to the whole team. Anyone who can reach the chat client can do anything that key can do.
No identity behind the call
The AI knows which chat it's in, not which technician is behind it. There's no seat, no role, no per-client boundary — just a key that works or doesn't.
No approval, no record
An AI client reboots a device, closes a ticket, or runs a command the moment it decides to. Nobody approves it, and nothing is written down.
Ridge sits between your team's AI clients and your business tools. Every call has a person behind it, a permission model that says exactly what they can touch, a hold on anything destructive until someone approves it, and an audit record of what happened.
How it works
Ridge is the MCP gateway between your team and your tools
Nobody talks to your business tools directly. Every AI client goes through Ridge, and Ridge decides what happens next.
Connect your tools
Credentials are added once, in Ridge, and never live in a chat client.
Decide who can do what
Grants are set per person or per team, per tool, per client — in three tiers: read, write, destructive.
Your team works from any AI client
Ridge enforces every call, holds destructive actions for a human, and writes an audit record.
Your team's AI clients
Claude, ChatGPT, Copilot, Cursor
Ridge
identity · permissions · approvals · audit
Your tools
PSA, RMM, documentation, and more
In practice
What it looks like in a working day
Three examples of how Ridge behaves once it's in front of your tools.
Service desk
“Show me every open ticket for this client and draft an update.”
The tech only sees the clients they're assigned to. Ridge filters the tool results before the model ever sees them.
Endpoint ops
“Isolate that device.”
Ridge holds the action until an approver says yes — from the console or right in the chat — and records the decision either way.
Documentation
“Pull the VPN setup procedure from Hudu.”
The model gets the steps. It never gets the password.
Integrations
13 integrations, built for how MSPs actually work
Every integration below is live today — no roadmap, no waitlist.
PSA & documentation
- Autotask
- Hudu
Search tickets, create tickets, add notes, and log time in Autotask; pull procedures and documentation from Hudu — never the secrets stored alongside them.
RMM & endpoint
- Datto RMM
- Conduit
- SentinelOne
- Huntress
List devices, check status, and review alerts. Isolation and remediation actions are held for approval before they run.
Network & security
- Sophos
- FortiGate
- UniFi
- Cloudflare
Look up firewall rules, network status, and DNS records. Changes are a separate permission, and the high-impact ones — deleting records, removing rules — wait for a human.
Business & cloud
- Microsoft 365
- Pax8
- QuickBooks Online
Check licensing, subscriptions, and invoices without handing out a shared admin login.
Need another integration? Ask us.
Security posture
The control layer a shared API key skips
Eight product principles that don't get compromised for convenience.
Every call has a person behind it
Every action is tied to the person who's signed in — never to a shared key that could be anyone on the team.
Least privilege, per person and per client
Grants are set per person, per tool, per client, in three tiers: read, write, destructive. People only ever see what they're allowed to touch.
Destructive actions wait for a human
Reboot, uninstall, isolate, delete — high-impact actions are held for approval before they run, decided from the console or right in the chat. Routine changes need their own explicit permission.
Secrets never enter the chat
Passwords and API keys are never returned into a model's context. A governed reveal happens outside the conversation, not inside it.
Credentials never leave Ridge
A chat client's token never reaches your vendor, and a vendor credential never reaches a chat client. Ridge is the only thing that ever holds both.
One enforcement point
Every AI client — Claude, ChatGPT, Copilot, Cursor — goes through the same gateway and the same rules. Nothing gets a side door.
Complete, tamper-evident audit trail
Every call writes a permanent record before it returns. Export the stream to a webhook, Splunk, or Microsoft Sentinel.
Works for one person or a whole company — same rules
One technician or five hundred run the identical permission model, approval flow, and audit trail. Nothing is special-cased.
Works with
Any MCP client — the same gateway, the same grants
Any MCP client. One sign-in, the same permissions everywhere.
Claude
Desktop and claude.ai
Claude Code
One-line setup
ChatGPT
Business & Enterprise connector
Microsoft Copilot Studio
Entra-aware
Cursor
Any MCP-capable editor
Enterprise
For organizations that already have an identity provider
The same gateway, with the controls a security or IT team asks for first.
Entra SSO + SCIM
Sign in through Microsoft Entra (OIDC) with domain-verified auto-provisioning and IdP attribute → role mapping. SCIM keeps membership in sync as people join and leave.
Bring your own encryption key
Stored credentials are already encrypted per organization. With BYOK, the key that wraps them is one you control.
SIEM export
Stream the audit trail to a webhook, Splunk, or Microsoft Sentinel as it's written.
Deploy your way
Run Ridge in the cloud, or deployed on your own infrastructure — with the same security model either way.
Pricing
Per-seat cloud pricing. Private deployment available. Tell us your seat count and we'll send a quote.
FAQ
Frequently asked questions
What is MCP?
MCP (the Model Context Protocol) is an open standard that lets an AI client — Claude, ChatGPT, Copilot, Cursor — call tools exposed by a remote server. Ridge is that server: it sits in front of your team's real business tools.
Does Ridge (or the AI) see our secrets?
No. Secret values never enter a chat conversation. A governed reveal decrypts a credential outside the model's context, only for someone explicitly granted that access. Ridge is the only thing that ever holds a vendor credential.
Which AI clients does it work with?
Any MCP client: Claude (Desktop and claude.ai), Claude Code, ChatGPT, Microsoft Copilot, and Cursor — plus anything else that speaks MCP.
Which tools does it integrate with?
Autotask, Hudu, Datto RMM, Conduit, SentinelOne, Huntress, Sophos, FortiGate, UniFi, Cloudflare, Microsoft 365, Pax8, and QuickBooks Online — 13 integrations, all live today. Ask us about adding another.
How is this different from a shared API key?
A shared key means anyone with access to the chat client can do everything the key can do, with no record of who did what. Ridge puts a real person behind every call, per-user and per-client permissions, human approval on destructive actions, and a full audit trail in between.
Can we run it on our own infrastructure?
Yes — talk to us. We support both cloud and private deployment, with the same security model either way.
Is Ridge SOC 2 / ISO 27001 certified?
Not today. Ask us about our roadmap.
Give every AI client a governed way in.
See Ridge with your own tools.