The RMM came from one company, the PSA from another, the documentation tool from a third. They share a sign-in page and not much else. Guardian Plus was built as one system, and the difference shows up in what it can actually do.
Not synced overnight. Not matched on a hostname string and hoped for. Linked — so a technician holding a ticket can see the machine it came from, connect to it with the right credential, and check what the client is contracted for, without leaving the page or knowing a password.
One identity provider with multi-factor. One place to add someone, one place to remove them. Deactivate them and every session ends — not eventually, immediately.
Permissions by action, granted through your groups, applied identically in every module. Change someone’s group once and their access changes everywhere at the same moment.
When something goes wrong there is one history to read, not four to correlate by timestamp — including who revealed which credential and why they were allowed to.
Here is the difference between the common version and this one.
These aren’t features anyone chose not to build. They are what becomes possible when the tools share a database, a permission model and a release, and impossible when they don’t.
Intake rules match on hostname, the failing check’s name, the host group, even the check’s exit code — not just the words in an email. A disk alert on a SQL server can go straight to the database queue.
Credentials are pulled from the vault and injected into the session server-side. A junior technician can work on a domain controller without ever being shown domain admin.
A file emailed into the service desk becomes a tenant-owned document in the vault, scanned on the way in — not a loose blob in storage nobody audits.
The device list in your service desk is fetched live from the monitoring platform, not mirrored on a schedule. There is no nightly job to drift, and nothing stale to reconcile.
Write the resolution once and publish it to the knowledge base from inside the ticket, as yourself, already linked to the client and the machine it happened on.
Build a dashboard that puts monitoring, service desk and documentation data side by side. Not three exports and a spreadsheet.
Ask it something that spans two modules and it can actually answer, because there is no integration boundary in the middle. Which clients have unpatched machines and an open ticket about it. Which contract covers the server that just went down.
And it answers as you. Every tool it calls re-derives the permissions of whoever asked, so it cannot surface a record you would not be allowed to open yourself.
Tools re-derive your permissions on every call. It cannot open a record you cannot.
Actions that change things are hidden from the assistant entirely and need a person to confirm.
The same assistant works across every module, because there is only one set of data underneath it.
The modules are not standalone products with an optional platform bolted on — they genuinely run on Guardian Plus, and it comes with every deployment. That is the trade: you cannot take one module and run it somewhere else, and in exchange you get everything on this page.