Theo The frontier AI for IT work
Home/Products/AI Technician

The AI Technician.

Theo takes a ticket out of your queue, works it the way a competent L1 would, and closes it. It reads your documentation, executes the change in Microsoft 365 or Google Workspace, writes the note, and logs everything it touched.

Autotask Halo PSA Datto NinjaOne ConnectWise SuperOps Microsoft 365 Google Workspace IT Glue Hudu
Pick any ticket in the queue Approve or change any gated action Toggle supervised vs. earned autonomy
AI features

How the AI Technician works a ticket.

Plan & approval mode

Create execution plans with built-in approval checkpoints, so every write action is reviewed before it runs in a client tenant.

Auto triage

Automatically analyze incoming requests, classify priorities, and route each task to the right workflow in seconds.

Auto investigate

Collect context from connected systems, identify root causes, and surface key insights without a technician digging first.

Auto resolve

Execute approved actions, complete the repetitive workflows, and close the ticket while keeping the desk fully informed.

Control

You hold the dial.

Autonomy in Theo is a grid, not a switch. Every cell is a ticket category for a specific client, and every cell has one of three settings.

Off — Theo doesn't touch this category for this client at all.
Supervised — Theo does the work and stages the action; a technician approves before anything executes.
Autonomous — Theo resolves end-to-end, and still gates anything irreversible.

Changing a cell takes effect on the next ticket. There is no redeployment, no workflow to re-publish, and no support request to raise.

Ticket categoryAcme DentalNorthwindRedwood Fin.
Password resetAutonomousAutonomousSupervised
Account unlockAutonomousAutonomousAutonomous
Licence assignmentAutonomousSupervisedSupervised
OnboardingSupervisedAutonomousSupervised
MFA resetSupervisedSupervisedSupervised
OffboardingSupervisedSupervisedOff

A configuration from week six of a deployment. MFA and offboarding stay supervised everywhere — that is the default we ship, and most MSPs never change it.

Coverage

What Theo handles today.

Over 500 discrete actions across the desk — identity, email, devices, PSA, documentation, licensing, collaboration, and more. These are executions, not suggestions.

User accounts & directories

Search, create, update and restore users. Manager attributes, contact details, org units, and admin roles in Microsoft 365 and Google Workspace.

Identity, MFA & sessions

Password resets, account unlocks, MFA methods, session revocation, risky-user inspection, and blocks — with the irreversible ones gated.

Groups, roles & org units

Security groups, Microsoft 365 groups, distribution lists, dynamic groups, owners and members, Google admin roles, and OU moves.

Licensing & subscriptions

Assign and reclaim Microsoft 365 licences, check SKU availability, and manage Sherweb catalog, orders, amendments and cancellations.

Email, mailboxes & delivery

Forwarding, aliases, send-as, inbox rules, signatures, auto-replies, quotas, quarantine, message trace, and why mail never arrived.

Shared mailboxes & rooms

Create and convert shared, room and equipment mailboxes. Full Access, Send As, folder permissions, GAL visibility, and booking policy.

Calendar, Teams & chat

Room metadata, calendar access, Teams membership and channels, policies, meetings, Google Chat and Meet, Slack users, and technician notify.

Files, SharePoint & Drive

SharePoint sites and lists, OneDrive and Google Drive sharing, permissions, version restore, and Google Shared Drives.

Onboarding & offboarding

Full provisioning, group and licence assignment, mailbox conversion, litigation hold, data transfer, session and token revoke, and restore from recycle bin.

Archiving, hold & retention

Archive mailboxes, retention tags and policies, litigation hold, Google Vault holds and exports, and inactive-mailbox inspection.

Security, alerts & Conditional Access

Compromised-account checks, Google alert centre, named locations, Conditional Access policies, app secrets, and enterprise-app enablement.

Endpoints, Intune & RMM

Intune inventory, ownership and primary user, Datto and NinjaOne health, patches, alerts, remote scripts, and device diagnostics.

Ticketing & time in the PSA

Create, update, reply and resolve tickets in Halo, ConnectWise, Autotask and SuperOps. Contacts, assets, notes, and time entries.

Documentation & passwords

IT Glue and Hudu articles, assets, organisations, password folders, and search across your own resolved ticket history.

Marketplace & procurement

Sherweb customers, catalog, subscriptions, quantity changes, cancellations, and payable or receivable charges.

Compliance, eDiscovery & DLP

Content searches, DLP policy inspection, audit and sign-in logs, email activity, and Google admin and Drive activity reports.

Apps, secrets & enterprise registrations

App registrations, expiring client secrets, redirect URIs, and enable, disable or delete enterprise applications.

DNS, diagnostics & workflows

URL and latency checks, MX and CNAME propagation, one-time secret links, custom client workflows, and CSV export of results.

What Theo can run depends on the integrations you connect. Sensitive writes stay gated until you grant them.

Integrations

Operates on the stack you already run.

ConnectWise
PSA · available
Autotask
PSA · available
Halo PSA
PSA · available
SuperOps
PSA · available
Microsoft 365
Identity · available
Google Workspace
Identity · available
IT Glue
Docs · available
Hudu
Docs · available
Datto RMM
RMM · available
NinjaOne
RMM · available
Microsoft Intune
Device · available
MSP Process
Portal · available
Huntress
Security · available
Sherweb
Marketplace · available
Slack
Chat · available
Teams
Chat · available
Zoom
Collab · available
1Password
Identity · available
CW Automate
RMM · on the roadmap
N-able
RMM · on the roadmap
Objections

The questions you're actually going to ask.

You control what Theo does autonomously and where it requires approval. Every action is logged with a full audit trail. Start fully supervised and expand autonomy as you build confidence.

Two things matter more than the error rate. First, the categories where Theo acts alone are ones you have already watched it work. Second, the actions that are hard to undo — offboarding, MFA changes, shared mailbox permissions — stay gated even in an otherwise autonomous category.

Most of them were workflow builders. They needed someone on your team to design every automation before anything got resolved, and that person never had the time.

Theo doesn't require you to build anything. In your supervised pilot you'll see real tickets from your own queue resolved in the first week, before you've committed to anything.

One week from discovery call to first resolved ticket. We connect your PSA, your Microsoft 365 or Google Workspace tenant, and your documentation platform. There's nothing to build and no automation engineer to hire.

Theo is SOC 2 Type II certified. See the Trust Center.

Your client data is not used to train models, and it is not retained beyond the execution of the ticket. What Theo needs to resolve the work is used for that run — then it is gone.

Your client data is not used to train models. Full stop. It is not retained beyond the execution of the ticket.

Theo acts through the same delegated permissions your technicians use, scoped per client, and every call is recorded against the ticket. You can revoke access from your side at any time without going through us.

Theo is built on bounded access. On every ticket run it receives only the fine-grained permissions required for that work — this client, this identity, these actions — not a standing key to the tenant.

That is the opposite of agents such as OpenClaw, which hand the model unbounded, full-environment access and hope the prompt holds. Theo cannot reach what the ticket does not need, even if the model tries.

You can — at $45,000–$55,000 plus benefits, four to eight weeks to hire, and a few months to competence.

Theo costs less, starts in a week, works the overnight queue, and doesn't leave in eighteen months. Most of our MSPs use it to defer the next hire rather than to reduce the team they have.

Theo connects to ConnectWise, Autotask, Halo PSA and SuperOps, plus Microsoft 365, Google Workspace, IT Glue and Hudu. On the RMM side, Datto RMM and NinjaOne are connected for device metadata, alert intake and remote scripts.

See a full list of applications Theo works with.

Yes. Autonomy is configured per client as well as per ticket category, so you can run Theo fully autonomous for one client and fully supervised for another, with different category sets for each.

The rest of the desk

The AI Technician resolves. Two more agents work either side of it.

AI Triager

Classifies, routes and prioritises every ticket the moment it lands — including the ones the AI Technician will never touch.

See the AI Triager

AI Security Engineer (coming up)

Works the alert queue the way the AI Technician works the ticket queue. Investigation is autonomous; containment is gated.

See the AI Security Engineer

Your next technician starts this week.

We'll map your stack, look at your actual ticket mix, and tell you which categories Theo takes in week one — and which ones it shouldn't touch.