Three systems. One answer.
Every client you manage is described three times: by what the RMM observes, by what the PSA and documentation record, and by what the agreement bills. TrueUp reads all three, read-only, and tells you where they disagree — and why.
What it finds
Devices you manage but don't bill
Live endpoints with no seat on the agreement. Counted after ghosts — sandbox detonations, dead agents — are removed, so the number survives the room.
Seats you bill but no longer manage
The other direction: additions that outlived the devices. A true-up before the client finds it.
Why the documentation is wrong
Every orphan gets one cause — a broken sync leg, a rename, a retired RMM still writing — and a named fix. Not a list of symptoms.
How it's built
- Read-only. Inquiry-scoped API members only. The only write it ever makes is a ticket you approve.
- Deterministic. No language model anywhere near a number. Same inputs, same report, every time.
- Runs on your machine. One container or one zip of plain Python. Your keys never leave your network.
- Count and rate never share a list. Seat-count drift and unit-price drift are different problems with different owners.
- A report, not a dashboard. Output appears when something changed. Patterns across clients are one row.
- Checked twice. Every headline is derived at least two ways by different joins, and the report says so.
Where it stands
Account-wide on a ~400-client, ~7,000-device tenant in under ten minutes. A synthetic MSP with planted faults and an answer key passes end to end. What's being built now is the setup path for a second tenant.
Works today with ConnectWise Manage, Datto RMM and IT Glue. Other PSAs and RMMs are a matter of a map file, not a rewrite.