DendronAI
Every client’s tenant. One console. Governed AI doing the work.
DendronAI is one control plane for every Microsoft 365 tenant an MSP manages, built in partnership between Northern Tech Hub and RiverAI. Northern Tech Hub owns the product and the MSP domain. RiverAI brought the AI engineering and the governance model: agents designed, governed and orchestrated on OneReach GSX, safe to point at other people’s tenants from day one.
Mar – Jul 2026
engagement to production ready
One console
every client tenant
6 steps
alert to verified containment
Multi-tenant management is solved. Multi-tenant intelligence isn’t.
Northern Tech Hub knows the MSP world from the inside. Twenty tenants, fifty, a hundred, each with its own Entra ID, its own Intune estate, its own idea of what “secured” means, and a team stitching it together one browser profile and one PowerShell script at a time.
There are capable tools in the category already, and MSPs run them for good reasons. Consoles and scripts are a solved problem. What the category lacked was the layer above: AI that does the work, inside boundaries you set, across every client tenant at once, rather than a chatbot bolted to a dashboard summarising an alert you could already read.
Building that layer safely is enterprise-scale work: agent design, governance, orchestration. That is what Northern Tech Hub brought RiverAI in to get right.
The AI engineering and the governance model.
DendronAI’s intelligence runs on OneReach.ai’s Generative Studio X (GSX), the agentic orchestration platform enterprises use to govern and coordinate AI agents at scale. RiverAI worked alongside the Northern Tech Hub team on how the agents are designed, governed and orchestrated.
Governed agents, not free-range AI
Every agent acts with defined authority, inside set boundaries, with full audit lineage on every decision. The agent suggests, the change is shown as a diff, and a person applies it. Nothing changes in a client tenant without a human in the loop.
Outcome: AI that is safe to run against other people’s tenants.
True orchestration
GSX scores and routes each job to the right model. Models get swapped underneath; the technician’s console does not move. Not a homegrown wrapper around one model’s API, and not hostage to one vendor’s roadmap.
Outcome: the intelligence improves without the product changing under its users.
Authority that inherits the security model
Agent authority follows the platform’s least-privilege design: scoped per tenant, consented per capability, audited like every human action.
Outcome: the AI layer inherits the access story auditors already signed off rather than punching a hole in it.
Enterprise infrastructure at MSP reach
The orchestration layer large enterprises deploy, made available to a fifty-client MSP that could never build or buy it alone.
Outcome: well-governed agents supporting technicians to be more efficient, including when the technician is not at the desk. The work still belongs to the human; the agent does the legwork and shows its reasoning.
Threat response at 2am, without anyone in a portal.
An alert is useless at 2am if nobody is in your portal. The old pattern for an out-of-hours identity alert, in a tenant you might not have opened in a month: the alert sits in a queue until someone logs in, then a technician gathers context by hand across admin centres before anyone can decide anything, let alone act.
DendronAI’s Threat, Detection & Response orchestration replaces that queue with a decision pushed to the analyst, wherever they are.
- Alert lands in a portal nobody is watching
- Context gathered by hand across admin centres: sign-ins, device state, group membership, app permissions
- Response depends on someone being at a desk, in the right tenant
- No guarantee the action taken is recorded, verified, or in policy
- The alert triggers an orchestration that enriches, recommends, asks a human, acts, and verifies
- The decision comes to the analyst on Teams, with voice or SMS escalation if it goes unacknowledged
- Every action stays inside the platform’s least-privilege, tenant-scoped boundaries
- The incident record is updated and a timeline posted, automatically
The six steps.
- 01
Trigger
An identity alert fires: an impossible-travel sign-in, a risky OAuth grant, a mass download, MFA fatigue.
- 02
Enrich
The platform gathers the context a technician would otherwise chase by hand: user risk, recent sign-ins, device compliance, group membership, what the app can access.
- 03
Recommend
The severity is classified and a recommended action set drafted, for example: revoke sessions, disable the account, require re-MFA. Every recommendation is checked against policy before it is offered.
- 04
Decide · human in the loop
A card lands with the on-call analyst on Teams: Contain, Investigate, or Dismiss, with the context inline. Unacknowledged alerts escalate to voice or SMS.
- 05
Act
On approval, the response executes within the platform’s tenant-scoped, least-privilege boundaries.
- 06
Verify and write back
The orchestration confirms the action took effect, updates the incident record, and posts a timeline summary.
Why this is different
- The decision loop lives on the analyst’s channel. Teams, SMS, voice, not a portal that assumes someone is watching it.
- The orchestration keeps going. Enrich, notify, wait for a human, contain, verify, write back, across minutes or hours if that is what the incident takes.
- Policy comes first. Every recommended action is checked against policy before a human ever sees it.
For the MSP, the pitch to their customers changes: MDR-grade response orchestration, not just alerts in a dashboard.
Built for the whole security lifecycle.
The orchestration layer sits inside a platform Northern Tech Hub built for the whole security lifecycle:
One console, every tenant.
Users, groups and Intune devices provisioned, configured and offboarded at scale. Conditional access, SharePoint permissions and mailboxes in the same console. Templates rather than bespoke PowerShell, with one-click rollback.
Prevent, detect, respond, recover.
Configuration drift surfaced and fixed at source; cross-tenant threat signal in one alert stream tagged by client; triage and rollback from where the alert fired; restore to known-good with proof of what changed and when.
An access model auditors sign off.
No standing admin permissions and no client secret stored in the customer’s tenant. Each capability is consented individually, on Microsoft’s own admin-consent screen, with only the permissions it needs.
AI is not magic here, and we will not sell it as such.
The agents are useful because they are bounded, audited and supervised, not because they are autonomous. Putting more of an MSP’s operation on one platform also concentrates it, so isolation, uptime and exit options are fair questions, better asked early than late.
The point is not AI for its own sake; it is the simplest thing that measurably changes how an MSP’s week runs, with a human in control of every change that lands.
Read the full story of the partnership →Building a product that needs to be AI native?
Northern Tech Hub owned the domain; RiverAI brought the AI engineering and the governance. If you have a product that needs intelligence built in rather than bolted on, tell us what you are bringing to market.
Start a conversation →