There is no universal "managed workstation," and that is fine
Ask ten MSPs what a managed workstation must have and you get ten lists. NinjaOne or Datto. SentinelOne, Huntress or Defender. DNSFilter or Umbrella. BitLocker required or optional. Patching within seven days or thirty. None of them are wrong. They are different businesses with different clients and different risk appetites.
A verification platform that hard-codes one definition is useless to nine of them. One that has no definition cannot verify anything. The answer is a standards engine: a library of vendor-neutral controls, and a way for each MSP to select, parameterize and prioritize them.
Controls, not vendors
The control is "every managed endpoint has active endpoint protection." Which console answers that question is a connector detail. Swap SentinelOne for Huntress and the control does not change, the evidence source does.
Standards stack
An onboarding touches workstations and users. Those are usually maintained by different people with different rules. So a project should follow more than one standard, and when two disagree on the same control, the stricter setting wins and the conflict is shown, not silently resolved.
Critical means something
Not every control should block a project. Documentation being two records short is a warning. Four unprotected machines is a failure. The standard decides which is which, and changing that decision should make every affected project ask to be rerun.