All Things MSP

TRUST BUT VERIFY: The MSP Lesson on Documentation, API Keys, and Auditing | EP135

This week, hosts Justin Esgar and Eric Anthony pull back the curtain on a recent crisis within Justin's company that highlights a universal MSP challenge: the dangerous intersection of trust, poor documentation, and automated billing.

Justin shares a raw, real-time story about discovering that custom API calls, built by a former programmer to connect HaloPSA with third-party resellers, had failed to update for months. This led to the company being shorted $60–$70 per month on a single customer — a problem likely compounding across multiple clients.

The hosts dive deep into the operational fallout: spending three hours trying to locate undocumented API keys and wrestling with missing configuration data. The discussion naturally evolves into the broader need for MSPs to implement a "trust but verify" culture. They stress that relying on a single employee’s assurance without operational or financial controls is a fatal flaw.

You'll also hear another cautionary tale: how a computer recycled four years ago suddenly reappeared and re-enrolled in their systems from China, exposing a critical gap in their hardware off-boarding process. This is a must-listen for any MSP owner, manager, or technician who wants to learn how to:

Mitigate risk when relying on proprietary API integrations.
- Establish controls to monitor for automation or vendor breakages.
- Implement documentation SOPs (Standard Operating Procedures) to capture critical business logic, even for internal projects.
- Watch the full episode on YouTube here: https://atmsp.link/YTpodcast

Listen on your favorite platform:
- Apple Podcasts: https://atmsp.link/applepodcasts
- Spotify: https://atmsp.link/spotify
- Audible: https://atmsp.link/audible

Connect with the Hosts:
Justin Esgar (Host, Owner/CEO of Virtua Computers): https://www.linkedin.com/in/justinesgar/
Eric Anthony (Founder and Producer): https://www.linkedin.com/in/esanthony/

Join the All Things MSP Community:
- Facebook Group: https://www.facebook.com/groups/allthingsmsp
- LinkedIn Page: https://www.linkedin.com/company/allthingsmsp/
- YouTube Channel: https://www.youtube.com/@AllThingsMSP

A huge thank you to our Premier Sponsors:
- Gozynta: atmsp.link/gozynta
- EasyDMARC: atmsp.link/easydmarc
- Nodeware: atmsp.link/nodeware
- Helpt: atmsp.link/helpt
- Compliance Scorecard: atmsp.link/compliancescorecard
- Movebot: atmsp.link/movebot

The All Things MSP podcast is a Biz POW LLC production.