Trend Vision One Endpoint Security Agent
Trend Vision One in Switchboard. Review AI skills, playbooks, access limits and setup requirements before connecting your MSP systems.
How the Trend Vision One integration works
Trend Vision One for Service Providers runs Worry-Free protection across your clients, and its partner console knows things your RMM cannot: which protection modules are switched off on which client, which devices are offline or behind on their agent and pattern versions, what was detected and what the engine did about it, and where licence seats run over or under. Connect your partner key and a session can read all of it across every client at once — customers and their status lights, devices, detections and their outcomes, policies per client and your default, which products each client holds, seat history, and notification settings, and, with an optional Vision One key, the partner console's own accounts, API keys and audit log. Read-only today: no credential we issue carries a write scope, and no connected session can reach a write tool, so nothing here isolates a device, starts a scan, sends a command or changes a policy. Switchboard connects through an MSPStuff-hosted MCP server, so there is nothing to install and no key to hand your techs.
Hosted and external AI connections provide read-only access. Guidance, shared playbooks and automations we release for everyone are included with Dedicated. Bespoke automation builds are scoped separately. Any change a platform could make is held back — refused by our server before anything reaches the platform — until a person switches it on, and nothing is switched on today. Vendor consent does not switch any change on.
| Client | Devices with it off |
|---|---|
| Acme | 3 of 42 |
| Harbor | 2 of 18 |
| Northstar | 1 of 27 |
Read-only today, across every client your partner key reaches: customers and their protection status lights, devices and their health, detections and their outcomes, detection summaries, policies per client and your default, which products each client holds, seat history, and notification settings — plus, with the optional Vision One key, the partner console's accounts, API keys and audit log. No credential we issue carries a write scope, and no connected session can reach a write tool — so there is no path from a session to isolating a device, starting or stopping a scan, sending a command, creating a customer or changing a policy or setting. Trend's partner key is not limited by role, so everything a session sees is what your Remote Manager account can see; the calls that hand back activation codes, installer links or uninstall passwords are not made, and any such field is stripped from what a session reads. Any change the integration could make in Trend Vision One is held back — refused by our server before anything reaches Trend Vision One — until a person switches it on, and nothing is switched on today.
What it can do
- Customers & status lightsYour clients as Trend knows them: each customer with seats and licence period, the groups beneath it, the per-client status lights for every protection module, and a summary of what happened over a window — the resolver for which client a question is about.7skills
Reading only — no customer, group or licence is created or changed from here.
- Every client under your partner key, with seats, licence type and expiry, searchable by name — how a client's name becomes the customer a session then asks about.
- The status lights per client — ransomware, outbreak, real-time scan, web reputation, behaviour monitoring, device and application control, seat use — for a handful of clients or the whole book.
- The device groups inside a client, for the question of which group a machine that behaves differently sits in.
- What happened on a client over a window of up to thirty days — detections, affected devices and outcomes — in one read.
- Which Trend products each client holds — Worry-Free, email security, cloud app security — so a client with no endpoint protection is named as that rather than shown as an empty row.
- Your partner licence's seats in use against seats purchased, day by day for up to a year — the history a true-up conversation needs.
- What Trend's partner interface offers and which parts of it this connection reads — the plain answer to what it covers and what it leaves alone.
- Devices & healthThe endpoint roster per client and its health: online state, last check-in, agent and pattern versions, sensor and isolation status, scan history and what each machine has caught.5skills
Reading only — no device is isolated, scanned, restarted or sent anything.
- Every device under one client with its online state, last connection, agent and component versions and scan times — the page a ranking of stale and outdated machines is built from.
- The computers under up to ten clients in one read, for a quick look across several clients without paging each one.
- The devices Trend itself flags as out of date for one client, rather than a version comparison worked out by hand.
- The machines behind one partner-wide event type — the devices that caught ransomware, say — so a summary number turns into names.
- How many machines Trend itself counts with out-of-date components or a scan problem across the whole book — a second number to hold a device report against.
- Detections & threat historyWhat Trend found and what it did: the virus, spyware, web-reputation and ransomware logs per client, one event opened in full, and the partner-wide totals and top lists that show where the noise comes from.10skills
Reading only — no detection is cleaned, quarantined, restored or excluded from here.
- One client's detection log — virus, spyware or web reputation — for a window of up to an hour, read a page at a time, for the moment a single incident needs its exact timeline.
- Detections across every type for one client, ransomware included, with the action taken and whether it worked — the list a monthly security review starts from.
- One detection event opened in full, when the summary row leaves open what was found and where.
- Partner-wide detection totals over a window, the one number that says whether this month was quieter than last.
- The threats seen most across your clients, so a repeat offender gets named rather than counted.
- The programs most often caught across your clients, for spotting the one piece of software behind a wave of detections.
- The web categories most often blocked across your clients, for the conversation about what people are actually browsing into.
- The notifications Trend raised for up to ten clients — the console's own record of what it thought worth telling you.
- The partner-wide notification feed: every client's open action-required or warning notices, by category, with how often each was raised and when it was last seen.
- Threat totals across every Trend product for a window, the independent number a monthly report is checked against.
- Policy & notification settingsWhat protection each client gets: the policies per client and device group with each module on or off, your partner default to compare them against, who changed a policy or a setting, and which events the console reports and to whom.5skills
Reading only — no policy or notification setting is changed from here.
- Each client's policies per device group — real-time scan, behaviour monitoring, ransomware protection, web reputation and the scheduled scan, each on or off — read one client at a time.
- One policy opened in full, with its approved and blocked lists, for the moment a single setting needs its exact value.
- The console's own record of who changed a policy, an account or a setting for one client, and when.
- A client's default policy for desktops or servers on each operating system — where a module switched off at onboarding usually turns out to live.
- Which events a client's console reports and to whom, for the question of why nobody heard about an outbreak.
- Vision One console (optional key)The partner console itself, read with the optional Vision One API key: the accounts that can sign in, the API keys that exist, and the audit log of who did what — nothing about your clients' devices.4skills
Reading only, and only with the Vision One key connected — no account, role or key is created, changed or revoked from here.
- Every account in your Vision One partner console with its role and status, for the question of who can still sign in.
- The API keys your console has issued, with their roles and expiry dates — the key that lapses unnoticed is the one that breaks an integration.
- The console's audit log for a window, anomalous sign-ins included, so an unexpected logon is a question with an answer.
- The roles defined in your Vision One console and whether each can be given to an account or an API key, read beside the accounts and keys to see who holds a broad role.
How it has been taught to work it
Playbooks are the vetted techniques a session loads for this platform — what to check, in what order, and what a number means before it is reported.
- Client protection review — one client's lights, devices and detectionsHow protected is this client; a protection review or QBR section for one customer; what is wrong at one client in Trend.Vetted Oct 3, 2026
- Console hygiene — anomalous logons, API keys and accountsHas anyone logged on to the Trend console unusually; which Vision One API keys expire; who has console accounts; who did what in the console. Needs the optional Vision One key.
- Detection triage — one threat or one device, its history and what the action didWhat was detected on this device or at this client; did the clean succeed; which devices keep getting infected; are detections rising; what is this threat.
- Fleet protection sweep — every client rankedWhich clients have red status lights, the most devices offline or out of date, real-time scan off; how many devices in total; a fleet-wide Trend posture summary.Vetted Oct 3, 2026
- Licence true-up — seats bought, seats in use, expiriesWhich clients use more seats than they bought or far fewer; which licences expire soon; seat savings at renewal.
- Policy review — which clients have protection switched off by policyWhich clients have real-time scan, behaviour monitoring or web reputation turned off by policy; what a client's or a group's policy is; how a client's policy differs from the default; who changed a policy.
- Querying Trend Vision One — the cache, one customer per call, and the result capAlways when Trend Vision One is attached. Which questions the cache answers in one call, when to go live, one customer per device call, ten customers per batch, the result cap, the two-stage detection read, and the customer with no Worry-Free product.Always on
- Stale and outdated devices — the remediation list by clientWhich devices have not been seen for a week or a month; which have out-of-date components or an old agent; devices waiting on a reboot or not scanning; a clean-up list grouped by client.
- Trend Vision One — what the platform ISAlways when Trend Vision One is attached. The partner console and its customers, the status lights, Worry-Free versus Vision One, what offline and stale mean here, what this connection cannot see, and what it does not do: MSPStuff only makes read calls to Trend.Vetted Oct 3, 2026Always on