AI Resolution Agent for MSPs
Two resolution agents — one for Microsoft 365, one for your RMM — diagnose tickets against live customer state, build a fix plan your tech can trust, and execute actions end to end — with as much or as little human approval as you want.
Your team solves the same tickets over and over
Password resets, license changes, mailbox permissions, endpoint fixes — the same well-understood work fills the queue, and techs do it by hand in admin portals, slowly and inconsistently.
Slow MTTR
Routine fixes wait in the queue behind everything else.
Portal Hopping
Every standard M365 fix means hunting through admin portals.
Burnout on Repetition
Skilled techs spend their day on tickets a plan could handle.
After-Hours Gaps
Common issues sit unresolved until someone is back online.
One agent for the tenant, one for the device
Resolution work splits in two: cloud-side fixes in Microsoft 365 and device-side fixes through your RMM. Mizo ships a specialized resolution agent for each — with the same plan, approve, execute, audit loop.
M365 Resolution Agent
Resolves identity, licensing, and mailbox tickets directly in the customer's Microsoft 365 tenant. It diagnoses against live tenant state, grounds every step in your client's SOPs, and executes approved actions through Microsoft Graph and Exchange Online.
- Live tenant diagnosis via Microsoft Graph — user state, MFA, licenses, sign-in activity
- Provenance on every plan step: client SOP, live tenant state, or flagged best practice
- Configurable autonomy — per-step approve / skip or fully delegated execution
- Allowlisted Microsoft Graph and Exchange Online actions only
- Safety gates: tenant binding, verified-domain checks, hybrid-identity protection
- Immutable audit record for every action — approver, target, and API result
RMM Resolution Agent
Resolves device-level issues through your RMM — running approved scripts, on-device diagnostics, and remediations on the endpoint itself, with the same approval guardrails and audit trail.
- Automated script execution through your RMM
- On-device diagnostics — services, disk, event logs, health checks
- Endpoint remediation: restarts, repairs, cleanup, and client-side fixes
- Software installs and updates from your approved catalog
- Structured handoff from M365 diagnosis for client-side work
- Configurable approval levels and a full audit trail on every action
What the M365 agent resolves
A growing catalog of 20+ high-volume Microsoft 365 cases — you choose which are enabled for each client.
Identity & Access
- Password reset with secure delivery
- MFA reset & re-registration
- Sign-in unblock & restore
- Temporary Access Pass
- Force sign-out
Licensing & Lifecycle
- License assign, change & remove
- New user provisioning
- Core offboarding
- Group membership changes
- User attribute & manager updates
Mailbox & Collaboration
- Shared mailbox creation & access
- Send As / Send on Behalf
- Distribution list membership
- Forwarding & automatic replies
- Convert user mailbox to shared
Broader cases like OneDrive offboarding, SharePoint permission repair, and Outlook troubleshooting run diagnostic-first — with safe server-side fixes and a structured handoff to the RMM agent for client-side work.
What the RMM agent handles
Device-side work runs through your RMM — approved scripts, on-device diagnostics, and remediations on the endpoint itself.
Script Automation
- Approved script library execution
- Service restarts & resets
- Network & DNS flush and reset
- Scheduled maintenance tasks
- Custom PowerShell runbooks
On-Device Diagnostics
- Device health & performance checks
- Disk space & storage analysis
- Service & process status
- Event log review
- Connectivity & VPN checks
Remediation & Software
- Software install & updates
- Outlook & Office client repair
- Disk cleanup & optimization
- Patch & baseline enforcement
- Browser & cache resets
Every endpoint action follows the same loop as the M365 agent — plan, approve, execute, audit. Nothing runs outside the guardrails and autonomy level you set.
Diagnose, plan, approve, execute
The same loop at any autonomy level — your tech confirms and approves, or delegates trusted cases entirely.
Diagnoses Against Live State
The agent probes live customer state — tenant, identity, or device — and pulls the client's SOPs for the classified issue.
Builds a Provenance-Backed Plan
Every step in the resolution plan cites its source: a client SOP, live state, or a clearly flagged best practice.
Approve — or Delegate
Your technician approves or skips each action with one click — or you delegate trusted cases for fully autonomous execution.
Executes, Verifies & Audits
Approved actions run through Microsoft Graph, Exchange Online, or your RMM — verified and logged to an immutable audit trail.
Less technician time on eligible tickets
Built for safe execution
Both resolution agents share the same foundation: grounded diagnosis, guardrailed execution, verification, and clean escalation.
Live-State Diagnosis
Plans grounded in what's actually true — not model guesswork.
- Live Microsoft Graph probes
- On-device diagnostics via RMM
- Client SOP retrieval with authority tiering
- Root-cause hypothesis on every plan
Guardrailed Execution
Automation that stays inside the lines.
- Allowlisted actions only
- Tenant binding & verified-domain checks
- Configurable autonomy — HITL to full delegation
- Immutable action records
Auto-Verification
Confirms the fix actually worked before closing.
- Post-fix state checks
- Outcome validation
- PSA note on completion
- Reopen or escalate on failure
Escalate on Uncertainty
Hands off cleanly when anything is ambiguous.
- No writes without a classified intent
- Hard stops on unsafe conditions
- Hybrid-identity protection
- Context-rich hand-off to a tech
Resolution impact
What MSPs gain when resolution runs on rails.
less tech time on eligible tickets
M365 resolution cases
delegation — you set the autonomy
audit coverage on actions
Resolution Agent questions
What does the Resolution Agent do?
The Resolution Agent comes in two types. The M365 Resolution Agent diagnoses eligible tickets against live Microsoft 365 tenant state, builds a provenance-backed fix plan, and executes actions through Microsoft Graph and Exchange Online. The RMM Resolution Agent runs approved scripts, on-device diagnostics, and remediations on the endpoint through your RMM. Both run at the autonomy level you configure — from per-step technician approval to full delegation — and both verify the outcome and keep a full audit trail.
What's the difference between the M365 and RMM Resolution Agents?
The M365 agent works in the customer's cloud tenant — identity, licensing, and mailbox work like password resets, MFA recovery, onboarding and offboarding, and shared mailbox permissions. The RMM agent works on the device itself — running scripts, diagnosing endpoint health, remediating client-side issues, and installing software. They hand off to each other: an M365 diagnosis that points to a client-side cause becomes a structured RMM handoff.
Which Microsoft 365 tickets can it resolve?
The M365 agent ships with a catalog of 20+ high-volume cases across identity and access (password resets, MFA reset, sign-in unblock, Temporary Access Pass), licensing and lifecycle (license changes, provisioning, offboarding, group membership), and mailbox and collaboration (shared mailboxes, Send As, distribution lists, forwarding, automatic replies). You control which cases are enabled per client.
Do I have to approve every action?
No — autonomy is yours to configure, per client and per case. Start with per-step human-in-the-loop approval where your technician approves or skips each write, then delegate the cases you trust for fully autonomous, end-to-end execution. Safety gates, allowlisted actions, and the audit trail apply at every autonomy level.
What guardrails keep it safe?
The customer tenant is derived from the ticket, never chosen by the AI, and every target is checked against the tenant's verified domains at plan time and again at execution. Only allowlisted actions can run, hybrid-identity users are protected with hard stops, and every action produces an immutable audit record — whether a technician approved it or it ran fully delegated.
What happens when it isn't confident?
If a ticket doesn't match a known resolution case, the agent proposes no writes at all. If a safety gate fails — wrong tenant, user not found, on-premises-synced identity — it stops hard and explains why. Ambiguities are flagged for technician judgment, and the ticket is handed off with full context so your tech picks up exactly where the agent left off.
Works with the rest of the fleet
Resolution turns a diagnosis into a closed ticket — then documentation and QA take over.
Proven Results for MSPs
26%
Average increased capacity per technician
30%
Less escalations
100%
Removes the need for a dedicated triage and dispatch role
