

Governed AI for managed service providers.
Governed AI for managed service providers.
ARIA is built for regional MSPs running managed IT, security, network, and infrastructure services across many client environments. It inherits policy-based access per tenant, human approval on consequential actions, and reviewable execution records, with cloud, on-premise, and air-gapped deployment options verified per release.
ARIA is a governed AI platform for regional managed service providers, built by Trunnion AI and first deployed at Ardham Technologies.
It is designed for policy-based authorization, layered tool controls, reviewable execution records, and human-in-the-loop approval gates, with implementation and tests verified for the exact release, deployed to cloud, on-premise, or fully air-gapped environments (security boundaries). Trunnion AI is aDuskbridge company, built by the team behind Viceroy NM.
How ARIA turns a request into an accountable outcome.
This representative sequence shows where policy, automation, human authority, and evidence sit in a managed services workflow.
- 01Tenant
Receive the MSP request
The workflow starts inside the approved customer and service boundary.
- 02Identity
Resolve tenant policy
Identity, role, tenant, and tool rules scope every proposed action.
- 03Operate
Prepare the service action
Agents organize managed IT, security, network, or infrastructure work.
- 04Decision
MSP operator approval
A named operator reviews consequential actions before execution.
- 05Evidence
Keep tenants accountable
Release-specific records connect request, policy, approval, and outcome.
Illustrative workflow. Exact controls, integrations, and evidence are verified for the deployed release.

Regional managed service providers running managed IT, security, network, and infrastructure services across many client environments.
What ARIA is for, and what it is not.
Designed for regional managed service providers operating across multiple client tenants. Available workflows, integrations, controls, and deployment boundaries are confirmed for the exact release and written agreement.
Like every Trunnion product, ARIA is designed to propose, draft, and prepare work for human decision, with consequential actions pausing at a human approval gate. AI outputs may be inaccurate, incomplete, or unsuitable and should not be the sole basis for a consequential decision affecting a person. Expected inputs, model providers, known failure modes, and the exact human review points for a deployment are documented in the release documentation and written agreement. See theAI transparency notice and theAI acceptable use policy.
ARIA: key facts.
| Product | ARIA |
|---|---|
| Category | Managed Services |
| Status | Live |
| Platform | Trunnion control plane: governed multi-agent orchestration |
| Governance | Designed for policy-based authorization and layered tool controls; verified per release |
| Audit | Reviewable execution records; integrity and replay verified per release |
| Human oversight | Human-in-the-loop approval gates on consequential actions, by design |
| Model posture | LLM-agnostic model routing, hosted or on-premise |
| Deployment | Cloud, on-premise, or fully air-gapped |
| Classification | Designed for classification-aware workflows up to TS/SCI; accreditation determined per environment |
| Security alignment | Engineered to align with NIST SP 800-53 control families; alignment by design, ahead of formal certification. |
| Developer | Trunnion AI, LLC, a Duskbridge company |
Governed by design, like every Trunnion product.
ARIA inherits the platform's governance, audit, and deployment patterns instead of rebuilding them: policy on every action, a human operator in command, and a record you can hand to an auditor.
Policy-aware governance
Attribute-based access control (ABAC) is designed to decide what every agent may see and do, per tenant, role, and classification.
Human-in-the-loop gates
Consequential actions are designed to pause for a named operator to approve, edit, or reject before anything executes.
Reviewable execution records
The architecture is designed to record actions, approvals, and supporting traces for review. Cryptographic implementation is verified per release.
Common questions about ARIA.
Who is ARIA built for?
Ardham was the first deployment. ARIA is productized for regional managed service providers across approved MSP operating models and system boundaries.
What is ARIA's public capability boundary?
The public page provides positioning only. Available workflows, integrations, controls, and operational behavior are confirmed for the exact release and written agreement.
How are ARIA capabilities verified?
Availability, integrations, controls, and operational behavior are confirmed for the exact release, configuration, deployment, and written agreement.
Next step
See ARIA against your workflow.
Request a demo and see the governed control plane run in your environment, from cloud to air-gap.