One place to run every client you look after.
Ferrule is a co-managed IT platform for the people who keep everyone else working — in-house IT teams and the providers who work alongside them. Every client’s data sits behind its own boundary, and remote access is consent-gated and logged.
The console your team lives in.
A workspace per client — one of them or a hundred — and one login for whoever works across them. Nothing below is a separate product with its own password.
Microsoft 365 visibility
Users, licences, MFA registration status and licence waste, read through Microsoft Graph with read-only scopes.
Ticketing & escalation
A queue with time tracked against it, and a hand-off that carries the history and the reason along with it.
Asset inventory
What is deployed where, per client, kept next to the tickets and projects that touch it.
Secure remote access
Sessions into a client’s machines, gated by that client’s own consent policy and written to an audit trail.
Projects & time
Scheduled work, opportunities, and billable time recorded where the work happens instead of in a second system.
Two ways in, and they meet in the middle.
Co-managed means the in-house person and the provider are both real, and both stay. Ferrule is built for that arrangement rather than around it.
For teams with their own IT
Your IT person keeps the systems, the context, and the relationship. Ferrule is the tooling they have been doing without.
- Your team stays in charge of your environment
- Raise a ticket and see what actually happened on it
- Your IT role sets the consent mode, within a floor the provider sets
- Escalate a ticket to your provider with its history attached
For IT providers
Ferrule is the platform your team works in all day — tickets, assets, remote access and Microsoft 365 across every client you cover.
- A separate workspace per client, with its own boundary
- Your technicians in front of the client, not ours
- Deploy the agent yourself, per client, at your own pace
- An escalation opens an access grant scoped to that one ticket
A hand-off carries the history with it.
Escalating is a deliberate act with a required reason, and the payload that leaves carries the client, the ticket, the device, the person and the recent timeline. Nothing moves on its own.
Whoever handles IT day to day raises the ticket and works it. Nothing moves off their desk on its own.
What they already tried stays on the ticket, so anyone who joins it later starts from something.
When they want another pair of hands, they send the ticket on — history attached, and a reason, which is required.
A deliberate act, never an automatic hand-off. The work comes back with an answer rather than disappearing.
Moving a ticket to the platform tier opens an access grant covering that ticket and nothing else.
It is not a standing key to the workspace: the grant is scoped to the one ticket, and reads against it are written to the audit trail.
Why you can put everything on it.
Putting everything you look after into one platform is a decision somebody will ask you to defend. These are the properties you can defend it with.
- Separate databases
One workspace’s data is not in another workspace’s file. The isolation is enforced by which database a request is holding, not by a filter somebody has to remember to write — there is no query that could return another workspace’s row.
- The client boundary
Inside a workspace, a client-side account only ever sees its own rows. The two boundaries compose, and neither is a substitute for the other.
- Consent, set per client
The client’s IT role chooses how remote access works for its people — ask first, notify on connect, or neither — within a floor the MSP admin sets and it cannot go below. Changing the policy revokes the session links already issued under the old one.
- Sessions are on the record
A remote session records who opened it, into what, and why. Internal sessions always ask permission, and no policy change can loosen that.
- Platform access is granted, not standing
Ferrule staff have no standing read of any workspace. Escalating a ticket grants access to that ticket and nothing else, and the grant ends with it.
Book a walkthrough.
Tell us what you run and we’ll walk you through the console working against a real workspace.