Proof that the work actually got done.

Hotam reads what a project promised, checks the real systems it touched, and shows exactly what passed, what failed and the evidence behind it. A project closes when the intended state exists and the evidence proves it, not when someone clicks Complete. Onboardings, migrations, server and firewall implementations, security rollouts, network refreshes: any project with a promised outcome. Built first for IT service providers. Designed for every industry where "done" and "correct" are not the same word.

Read-only integrations. Evidence on every result. Works across any vendor stack.
New Client Onboarding · ABC Manufacturing · 10 requirementsReading scope…
RMM agent
NinjaOne
73 / 73
EDR active
SentinelOne
69 / 73
Users migrated
Microsoft 365
85 / 85
Licensing
Microsoft 365
83 / 85
MFA enforced
Microsoft 365
80 / 85
Backup
Cove
3 / 4
Monitoring
NinjaOne
4 / 4
DNS filtering
DNSFilter
Configured
Documentation
IT Glue
10 / 12
!
4 endpoints are not present in SentinelOne. PC-JSMITH, PC-MJONES, LAPTOP-023, WS-ACCOUNTING04. The ticket said "EDR deployed". The console says otherwise. The project cannot close.
QA statusFailed · 50%
Requirements failed4 of 10
Caught before handoff12 items
What it does

Everything QA should own, verified against the systems

Not a dashboard and not a ticket checker. Hotam takes responsibility for the acceptance layer of the business: what was promised, what actually exists, what evidence proves it, and what still blocks the project from being called complete.

Project Assurance

One screen per project: what was promised, what we found, where it came from, what passed, what failed, what happens next.

Evidence on every result

Source, timestamp, expected, observed and the named devices or users that failed. Immutable once written.

Four honest states

Passed, Failed, Warning, Unknown. When evidence is missing the answer is Unknown, never a guess.

Your standards

Define what a managed workstation or a managed user means in your shop. Stack standards per project. Mark what is critical.

QA queue

Every project waiting for action in one list: ready, failed, needs review, ready for rerun, verified.

Findings

Every unresolved gap across every client, with severity, affected items and history. Nothing closes by clicking.

Attestation

Rack cabling, training, physical work: a human signs for what software cannot see, and the signature is kept.

Continuous assurance

A client passes onboarding in January. Hotam keeps asking whether the environment still matches the standard it passed.

Project types

Any project that promises an outcome

Onboarding is the example because everyone knows it. Hotam verifies every kind of implementation your PSA tracks: each project type is a template of controls, each control is checked against the systems that hold the evidence, and each result is explained.

New client onboarding

Users, endpoints, RMM, EDR, licensing, MFA, backup, monitoring, documentation. All of it, proven, before the handoff.

Microsoft 365 migration

Expected users migrated, licenses assigned, domains verified, MFA and security defaults enforced, mailboxes and groups in place.

Server implementation

Server exists and reports, roles configured, backup job succeeding, monitoring active, patching policy applied, documented.

Firewall replacement

New device online, old device retired, required policies present, VPN and logging configured, monitored by your network tool.

Network and infrastructure refresh

Switches, access points and circuits replaced as scoped, every device discovered and monitored, configs backed up, diagram updated.

Security stack rollout

EDR, DNS filtering, application control, encryption and MFA deployed to every in-scope endpoint and user, with the stragglers named.

RMM or tenant migration

Every device present in the new platform, none left behind in the old one, policies and alerts recreated, old agents removed.

Workstation refresh

New machines enrolled, encrypted, protected and monitored; retired machines removed from every console and from the client's licensing.

New office or location

Network, endpoints, printers, phones and access controls delivered as scoped, physical work attested by the technician on site.

New user onboarding

Account, license, groups, MFA, mailbox, device, RMM, EDR and the client's own policies. Small project, same standard.

Client or user offboarding

Access revoked everywhere, licenses reclaimed, devices wiped or returned, data retained as agreed, nothing still reporting.

Your own project types

Any repeatable implementation becomes a template: pick the controls, set the expected values from the scope, run it every time.

How it works

Inside the engine

Hotam is not an AI reading your tickets and giving an opinion. It is a pipeline: AI turns the promise into checkable requirements, read-only connectors collect the facts, and a deterministic engine compares the two. The result is auditable line by line, and it is never an opinion.

Sources
Your systems
PSA, RMM, Microsoft 365, EDR, backup, DNS, documentation. Read-only.
Layer 1
Scope
Project description, SOW, tickets, products sold, expected quantities.
Layer 2
Expected state
AI maps the language to requirements: 73 endpoints need EDR, 85 users need MFA.
Layer 3
Observed state
Connectors return facts per device and per user, with timestamps. Never a verdict.
Layer 4
Deterministic engine
Compares expected with observed against your standards. No AI inside. Fully tested.
Layer 5
Results
Passed, Failed, Warning, Unknown, with evidence and the named missing items.
Outputs
Findings and Verified
Open findings for engineers; a Verified project only when every requirement passes.
↺Rerun loop. An engineer fixes the gap, you rerun, and the finding resolves only when the new evidence proves it. A human can accept a risk, with a note, but cannot declare something fixed.
1
Read the promise

Every project says what it will deliver. Hotam writes it down as requirements.

A project hits Ready for QA in your PSA. Hotam pulls the scope, the SOW, the tickets and the products sold, and AI turns the language into structured requirements with counts and values. You review and edit them before anything runs. AI only fills in blanks; it never grades.

  • Templates for onboarding, M365 migration and new user setup
  • Every requirement shows the sentence in the scope it came from
  • Anything AI cannot map is listed, with the reason, not guessed
What it's answeringWhat exactly was this project supposed to leave behind?
Expected state Project #4382 · from scope text
RequirementResourceExpectedSource sentence
RMM agent installedEndpoint73"onboard 73 Windows endpoints into RMM"
EDR activeEndpoint73"…and endpoint protection"
Migrated to Microsoft 365User85"migrate approximately 85 users"
Business Premium licenseUser85"to Microsoft 365 Business Premium"
MFA enforcedUser85"enforce MFA for all active users"
Backup configuredServer4"configure Cove backup for the 4 servers"
Rack cabling completedManual, Added by reviewer
2
Collect the facts

Ask the consoles, not the tickets

Read-only connectors pull the observed state from the systems where the work actually lives: which devices report to the RMM, which ones the EDR console can see, which users have MFA, which servers had a successful backup last night. Each fact carries its source and the time it was observed.

  • Scope comes from the RMM's managed list; the EDR only reports devices it has
  • A device that should exist but has no record is a failure with evidence, not a mystery
  • Evidence is immutable; a rerun writes new records, never edits old ones
What it's answeringWhat is actually true in this environment, right now, according to the system of record?
Evidence Run 2 · collected 14:02 UTC
SubjectAttributeSourceValueObserved
PC-JSMITHrmm.installedNinjaOnetrue2 h ago
PC-JSMITHedr.activeSentinelOneno record,
LAPTOP-023edr.activeSentinelOneno record,
WS-FINANCE01edr.activeSentinelOnetrue3 h ago
jdoe@abcmfg.comm365.mfaMicrosoft 365false14:01
bthomas@abcmfg.comm365.licenseMicrosoft 365Business Standard14:01
SRV-FILE02backup.healthyCovelast job failed3 d ago
Tenantdns.filteringDNSFilterconfigured14:02
3
Compare

Expected against observed, by rule, with no judgment call

The engine applies one rule per control: every in-scope device must have the attribute, every user must hold the license, the count must match. The output is one of four states, and the explanation is generated from the rule itself, so it reads the same way every time.

  • Missing evidence is Unknown, never Passed; a connector outage is Unknown too
  • Two sources that disagree produce a Warning that shows both values
  • Every control has tests for Passed, Failed, Warning and Unknown
What it's answeringDoes what exists match what was promised, and how do we know?
Results ABC Manufacturing · run 2
RequirementExpectedFoundResultEvidence
RMM agent installed7373PassedNinjaOne
EDR active7369Failed4 missing devices
Migrated to Microsoft 3658585PassedMicrosoft 365
Business Premium license8583Failed2 users
MFA enforced8580Failed5 users
Backup configured43FailedSRV-FILE02
Documentation complete1210Warning2 records
Rack cabling completed, , UnknownAttestation needed
QA score · 4 passed, 4 failed, 1 warning, 1 unknown
50%
4
Explain

Every failure names what is missing and where the evidence came from

A failed requirement becomes a finding: severity from your standard, the affected devices or users by name, the source, the time, and a history of every run that checked it. Engineers get a list, not a hunch. Managers get an answer to "why did this fail?" without opening five consoles.

  • Critical, high or medium, from the controls you marked critical
  • Affected items are listed by hostname or UPN, ready to act on
  • No name-and-shame: the product never scores technicians
What it's answeringWhy did this fail, which items, and who needs to know?
Open findings 5 · ABC Manufacturing
4 endpoints missing SentinelOne EDRPC-JSMITH, PC-MJONES, LAPTOP-023, WS-ACCOUNTING04 · in NinjaOne scope, not present in SentinelOne
Critical
5 users without MFAjdoe, asmith, bthomas, mjohnson, rwilson · Microsoft 365, 14:01 UTC
Critical
1 server backup not reportingSRV-FILE02 · Cove, last successful job 3 days ago
Critical
2 users with wrong licensebthomas, kpatel · Business Standard, expected Business Premium
High
2 documentation records missingNetwork Diagram, Backup Runbook · IT Glue
Medium
Automatically verifiable requirements
9 of 10
5
Fix, rerun, verify

The finding closes when the evidence changes. Not before.

Engineers fix the gap in the real systems. You rerun. Hotam collects fresh evidence, compares again, and resolves each finding only if its requirement now passes. Manual items are attested by a named person with a timestamp. When everything passes, the project is Verified, and that word means something.

  • No Resolve button exists; only a passing rerun resolves a finding
  • Accept a risk with a note, and it stays visibly accepted, not hidden
  • Old runs are never edited, so the history is the audit trail
What it's answeringIs it fixed, and can we prove it?
Run 3 · after remediation

Fresh evidence collected 09:40 UTC. The four devices now report to SentinelOne, five users have MFA, SRV-FILE02 completed a backup, licenses corrected, records added. Rack cabling attested by Mike Torres.

Requirement results · run 2 → run 3
2− EDR active · 69 / 73 · Failed
2+ EDR active · 73 / 73 · Passed · SentinelOne 09:40
5− MFA enforced · 80 / 85 · Failed
5+ MFA enforced · 85 / 85 · Passed · Microsoft 365 09:40
10− Rack cabling completed · Unknown · attestation needed
10+ Rack cabling completed · Passed · attested by M. Torres, Oct 2
10 of 10 · 100%
Standards

Your definition of correct, not ours

Every MSP defines a managed workstation differently. One requires NinjaOne, SentinelOne and DNSFilter; another runs Datto, Huntress and ThreatLocker. Hotam does not hard-code a universal answer. You build standards from a library of vendor-neutral controls, stack them on a project, and mark which ones are critical enough to fail it.

  • Reusable controls: RMM, EDR, MFA, licensing, backup, encryption, monitoring, documentation
  • Several standards per project; the stricter setting wins when they disagree
  • Critical flags decide the project status; change one and every affected project asks to rerun
Managed Windows Workstation Standard · 7 controls
RMMRMM agentRMM-AGENT-001
Critical
EDREndpoint protectionEDR-001
Critical
BKBackup healthyBACKUP-001
Critical
ENCDisk encryptionENCRYPTION-001
Required
DNSDNS agent, 48 hDNS-AGENT-001
Required
+
Stacked with "Managed Microsoft User"Migration, Business Premium license, MFA (critical) and domain verification apply to the same onboarding project. Two standards, one run, one result.
2 standards
Continuous assurance

Passing once is not the same as staying correct

A client passes onboarding on January 5. By April, two agents are gone, three users turned off MFA, and a server's backup has been failing quietly for a week. Hotam keeps the baseline from the day the project was verified and keeps asking whether the environment still meets it.

Drift · ABC Manufacturing Baseline Jan 5 · checked today
ControlBaselineTodayChange
RMM agent73 / 7373 / 73, Holding
EDR active73 / 7371 / 73−2Drifted
MFA enforced85 / 8582 / 85−3Drifted
Licensing85 / 8585 / 85, Holding
Backup healthy4 / 43 / 4−1Watch
DNS agent, 48 h73 / 7373 / 73, Holding
What changed 3 findings opened this week
!
2 endpoints dropped out of SentinelOneLAPTOP-041, PC-RGREEN · last seen in NinjaOne 2 h ago, no EDR record since Mar 28
Critical
!
3 users disabled MFAtnguyen, lortiz, dkim · Microsoft 365 sign-in policy changed Apr 2
Critical
≈
SRV-FILE02 backup failingCove · last successful job 6 days ago; two retries failed
High
✓
Everything else matches the January baselineHotam re-checks every client on your schedule and opens a finding only when evidence changes.
Holding
Where it goes

One engine. Four phases. Every industry that records work.

We are not building a QA tool for onboardings. We are building the layer that proves operational work was done correctly, and IT service providers are where we prove it first, because the evidence already lives behind APIs and the founders know the work. Each phase is unlocked by the one before it.

Phase 1 · now
Project Assurance
Did we complete this project correctly? Every implementation type an MSP delivers, verified against the systems before acceptance.
Phase 2
Continuous Assurance
Is the environment still correct? The verified baseline is re-checked on a schedule; drift opens a finding the day it happens.
Phase 3
Controlled Remediation
Can we fix it safely? Approved automations close the loop: detect, remediate, re-verify, document. Humans approve where risk warrants.
Phase 4
Operational Assurance Platform
The same engine, with a pack per industry: connectors, terminology, controls and templates for factories, warehouses, software teams and field crews.
↺What stays the same across every phase and every industry. The expected-state model, the evidence model, the four honest states, the rule that nothing closes without a passing rerun, tenant isolation and the audit trail. What changes per industry is a pack, not a product.
The platform and the packs

The engine does not know it is checking endpoints

Strip the IT vocabulary away and the question is the same everywhere. A work order, a shipping requirement or a definition of done says what should happen. An MES, a scanner or a CI pipeline records what did. Hotam compares them, with evidence, and decides. Domain partners from each industry shape its pack; MSP expertise does not transfer to a factory floor on its own, and we are not pretending it does.

  • Shared: expected-state model, evidence model, deterministic engine, findings, verification runs, integrations framework, identity, audit trail
  • Per industry: connectors, terminology, control library, project templates, domain experts
  • Sequence: prove the engine with MSPs, build the repeatable connector architecture, demonstrate ROI, then open the next vertical with people who know it
Expected state versus observed state by industry
IndustryExpected state fromObserved state from
IT and MSPScope, SOW, PSA project, products sold, standardsPSA, RMM, Microsoft 365, EDR, backup, network, documentation
ManufacturingWork order, SOP, BOM, quality plan, tolerancesMES, QMS, ERP, PLC and IIoT telemetry, inspection systems
WarehousingReceiving SOP, pick and pack rules, chain of custody, cutoffsWMS, barcode and RFID scans, inventory, dock and shipment records
Software deliveryTicket, definition of done, release checklistCI/CD results, test coverage, code scanning, deployment records
Field serviceScope, installation checklist, maintenance standard, safety rulesCMMS, technician records, device telemetry, photographs, sign-off
Regulated operationsRequired controls, policies, approvals, proceduresLogs, configurations, approval records, control evidence

IT services and MSPs

Every implementation type, verified against PSA, RMM, Microsoft 365, EDR, backup and documentation.

Phase 1 · available now
"69 of 73 endpoints protected. The project cannot close until four are fixed."

Manufacturing

Work orders and quality plans versus MES, QMS, ERP and machine telemetry.

Phase 4 · first pilots
"Five process steps required. Four recorded. The job does not ship."

Warehousing and distribution

Picking, packing and chain-of-custody rules versus WMS scans, RFID and dock records.

Phase 4 · first pilots
"24 items required, 23 scanned. The pallet waits."

Software delivery

Definition of done and release checklists versus CI results, scans and deployment records.

Phase 4
"Release marked done. Security scan never ran on the final commit."

Field service

Installation checklists and maintenance standards versus technician records, telemetry and sign-off.

Phase 4
"12 units installed. 11 reporting. One never came online."

Facilities

Inspection schedules and safety requirements versus CMMS, sensors and photographs.

Phase 4
"Quarterly inspection closed. No photo, no reading, no evidence."

Construction and trades

Scope and punch lists versus inspection records, photos and change orders.

Later
"Punch list closed with 3 items never inspected."

Regulated operations

Required controls and procedures versus logs, configurations and approval records. Continuous, not annual.

Later
"Control claimed in the policy. Evidence last collected 14 months ago."
Integrations

Reads from the systems you already run

Read-only, always. Hotam asks to verify your environment, never to change it. Least privilege, tenant isolation, encrypted credentials, full audit log. Your design-partner stack gets built first.

CWConnectWise ManagePSA · first
ATAutotaskPSA
HHaloPSAPSA
SDSuperOpsPSA
NNinjaOneRMM · first
DDatto RMMRMM
CWConnectWise RMMRMM
NAN-ableRMM
INIntuneDevice management
MMicrosoft 365Graph · first
ENEntra IDIdentity and MFA
GWGoogle WorkspaceIdentity
P8Pax8Licensing
S1SentinelOneEDR
HUHuntressEDR / MDR
DFDefender for EndpointEDR
CSCrowdStrikeEDR
TLThreatLockerApplication control
BLBitLockerEncryption, via RMM
CVCoveBackup
VEVeeamBackup
DBDatto BCDRBackup
AXAxcientBackup
DFDNSFilterDNS security
CUCisco UmbrellaDNS security
AUAuvikNetwork monitoring
MKMerakiNetwork
UBUniFiNetwork
ITIT GlueDocumentation
HUHuduDocumentation
SPSharePointDocumentation
APIREST APIAnything else
ATAttestationHumans, with a signature
+Custom connectorBuilt with design partners
Read-only, alwaysLeast privilegeOne tenant never sees anotherEncrypted at rest and in transitNever trains on your dataFull audit log
Insights

On proving work, not recording it

Short reads on what changes when a company can prove its work was done correctly, and why "completed" has been letting everyone down.

Pricing

Priced like the rework it prevents. Costs like software.

One onboarding that closes with four unprotected machines costs more than a year of Hotam. We are taking three MSPs into a founding design-partner program before general availability.

Design partner

Founding pricing, locked
Three seats. Real projects, honest feedback, your integrations built first.
  • Full platform from day one
  • Your PSA, RMM and Microsoft stack connected first
  • Weekly working session with the founders
  • Pilot report: defects caught before handoff
Apply for a seat

Enterprise

Custom
Multi-location MSPs, custom connectors, your security review.
  • Custom and private integrations
  • Security questionnaire and review support
  • Dedicated onboarding and standards workshop
  • Priority on the integration roadmap
Talk to us

Prices are working hypotheses for the pilot program and will be set with design partners.

Common questions

We already QA our projects. Why would we want this?

Most manual QA takes hours per project and still relies on someone comparing lists across five consoles by hand. Hotam does that comparison in minutes, every time, and leaves the evidence behind. Your senior people review the exceptions instead of verifying everything.

Does it change anything in our systems?

No. Every integration is read-only. Hotam asks to verify your environment, never to modify it. Remediation actions, when they arrive, will sit behind explicit approval and remain optional.

How is this different from ticket QA tools?

Ticket QA checks whether the ticket was well documented. Hotam checks whether the outcome exists: it asks the EDR console how many endpoints are protected, not the ticket. A perfectly written ticket that says "deployed to 73" still fails when the console shows 69.

How is this different from configuration monitoring?

Monitoring tools tell you what exists and what changed. Hotam starts from what was promised for a specific project and proves whether every required outcome was delivered before you accept it. Continuous assurance then watches for drift from that verified baseline.

What if a source is down or the evidence is missing?

The result is Unknown, never Passed. A connector outage produces Evidence Unavailable. Two sources that disagree produce a Warning that shows both values. Hotam does not guess, and it does not hide uncertainty to make a screen look green.

Does it score our technicians?

No. The product never reads who attested, acted or fixed anything into any report, and a test fails if a person's name leaks into the dashboard. The goal is operational quality, not surveillance.

Where does our data go?

An isolated tenant in an encrypted database. One MSP can never see another's data, enforced at the database layer. It is never used to train anything. Disconnect any time.

How long until it's useful?

A read-only connection takes minutes. The first project runs through QA the same day. The first finding you did not know about usually arrives in the first week.

From completed to verified.

Bring one real project. Hotam reads the scope, checks the systems, and shows you what your last QA missed. If it finds nothing, you have proof. If it finds something, you found it before your client did.