Integrations

How Hotam connects to the systems you already run

Hotam proves a project was done by reading the systems where the work actually lives: your PSA, your RMM, Microsoft 365 and your documentation. Every connection is read-only, uses credentials you create, and keeps the evidence behind every result.

The rules

What every connection does, and does not do

The same six rules hold for every system Hotam reads, today and as new connectors are added.

Read-only, always

Hotam asks for read permissions only and never changes anything in your systems. It verifies your environment; it does not manage it.

Least privilege, in your own system

You create the credentials in your own PSA, RMM, Microsoft tenant or documentation tool, with the narrowest access each one offers. You can pause or revoke them at any time.

Credentials stay sealed

Credentials are encrypted before they are stored, with a key that exists only on our server. Once saved, nobody can view them again, including us.

Clients matched across systems

The same client has a different record in every system. Each is matched to one client in Hotam, by name or by a person, and an ambiguous match is skipped, not guessed.

Evidence keeps its source and time

Every fact records which system reported it, when it was observed, and which device or user it is about. A rerun adds new evidence; it never edits the old.

Unknown, never a fake pass

When a system cannot say, because access is missing, a limit was reached or the data is not there, the check is Unknown with the reason. It is never shown as passed.

Live today

Four connectors read real systems now

Each was built from the vendor's official API documentation. A connector only collects facts; the deterministic engine compares them with what the project promised and decides the result.

PSA

Autotask PSA

Where the work comes from. Projects sync from Autotask, each filed under its client, so nobody types or imports them.

  • Active customer organizations, as the clients projects belong to
  • Their projects, including completed ones: those are the work Hotam verifies
  • Each project's description, which becomes its scope
  • Start date, end date and percent complete, shown for reference only
AccessA dedicated API user the MSP creates in Autotask. We recommend limiting it to viewing organizations and projects.Known limitTasks, tickets, products sold and user-defined fields are not read yet. Requirements come from the project description for now.
RMM

NinjaOne

Where the device facts come from: which computers and servers are there, and what state they are in.

  • Each client's approved Windows, Mac and Linux workstations and servers
  • Whether the NinjaOne agent is installed
  • Whether monitoring is active: online and not in maintenance mode
  • BitLocker disk encryption, enabled only when every volume is fully encrypted and protected
AccessAn API client app with the Monitoring scope only, which is read-only. No Management or Control scope.Known limitDisk encryption is reported from BitLocker only. FileVault and Linux encryption are not in NinjaOne's API, so those checks show Unknown.
Microsoft and identity

Microsoft 365

Where the user facts come from, read from each client's tenant through Microsoft Graph.

  • Users, and whether each account exists and is enabled
  • Assigned licenses, and seats purchased per plan
  • Whether each user is registered for multi-factor authentication
  • Domains, and whether each is verified
AccessAn app registration with Microsoft Graph read permissions only, approved by an admin in each client tenant. Deleting the app in a tenant removes access.Known limitMFA means registered, not enforced on every sign-in. Conditional Access is not evaluated yet.
Documentation

IT Glue

Where the documentation check comes from: do the records a project promised actually exist?

  • Each client's documents and flexible assets, by name
  • Whether each record is archived, and when it was last updated
  • Never document content, asset fields or passwords
AccessAn API key the MSP creates in IT Glue, with password access left off. Hotam only sends read requests.Known limitHotam counts records that exist. It cannot tell whether a record's content is complete, so an empty document still counts.
From connection to result

One client, many systems, one answer

A project in your PSA says what should exist. Hotam matches its client to the same client in NinjaOne, Microsoft 365 and IT Glue, reads what is there, and compares.

  • Expected state comes from the project's scope, turned into requirements a person reviews
  • Observed state comes from the connectors above, each fact with its source and time
  • The decision comes from fixed rules: Passed, Failed, Warning or Unknown, never from AI
When a system cannot answer what you see
SituationResult
Credentials refused or expiredUnknown, with the reason
Permission missing, or tenant not approvedUnknown, with the reason
Vendor rate limit or outageUnknown, next sync retries
The system has no data for that factUnknown
Evidence shows the requirement is not metFailed
Evidence proves the requirementPassed
On the roadmap

The rest of the MSP stack, planned

These systems are common in MSPs and are planned, not available yet. You can record them as part of your stack today; their checks stay Unknown until a connector exists. Design partners' systems are built first.

PSA

  • ConnectWise PSA
  • HaloPSA
  • Syncro
  • Kaseya BMS

RMM

  • Datto RMM
  • ConnectWise Automate
  • ConnectWise RMM
  • N-able N-central
  • N-able N-sight RMM
  • Kaseya VSA
  • Syncro

Identity and cloud

  • Google Workspace
  • Okta
  • JumpCloud
  • Microsoft Azure
  • Amazon Web Services

Endpoint protection

  • SentinelOne
  • Microsoft Defender for Endpoint
  • CrowdStrike Falcon
  • Huntress
  • Sophos Central
  • Bitdefender GravityZone
  • Datto EDR
  • N-able EDR

Backup

  • Cove Data Protection
  • Datto BCDR
  • Veeam Backup & Replication
  • Acronis Cyber Protect Cloud
  • Axcient x360Recover
  • Datto SaaS Protection

DNS and application control

  • DNSFilter
  • Cisco Umbrella
  • WebTitan
  • ThreatLocker
  • Airlock Digital

Network

  • Cisco Meraki
  • Fortinet FortiGate
  • SonicWall
  • Ubiquiti UniFi
  • WatchGuard Firebox
  • Auvik

Email security

  • Proofpoint Essentials
  • Mimecast
  • Microsoft Defender for Office 365
  • Harmony Email & Collaboration (Avanan)
  • IRONSCALES
  • Graphus
  • N-able Mail Assure

Training and passwords

  • KnowBe4
  • Breach Secure Now
  • BullPhish ID
  • Huntress Managed Security Awareness Training
  • Keeper
  • 1Password
  • Bitwarden
  • Passportal

Documentation

  • Hudu
  • ITBoost

Product names belong to their owners. Listing a product here does not mean a partnership with its vendor.

Beyond IT

Built for any work that can be checked against evidence

Nothing in the engine knows it is checking endpoints. It compares what was promised with what a system of record observed, and decides with evidence. IT projects for MSPs are where we prove it. These industries are the direction we are building toward; none of them is available today.

Manufacturing

Expected: Work orders and quality plans. Observed: MES, QMS, ERP and machine telemetry.

Direction, not available today

Warehousing

Expected: Receiving, picking and chain-of-custody rules. Observed: WMS scans, RFID and dock records.

Direction, not available today

Software delivery

Expected: Definitions of done and release checklists. Observed: CI results, code scans and deployment records.

Direction, not available today

Field service

Expected: Installation checklists and maintenance standards. Observed: Technician records, device telemetry and sign-off.

Direction, not available today

From completed to verified.

Bring one real project. Hotam reads the scope, checks the systems, and shows you what your last QA missed. If it finds nothing, you have proof. If it finds something, you found it before your client did.