The platform

Most platforms in this category were bought, not built

The RMM came from one company, the PSA from another, the documentation tool from a third. They share a sign-in page and not much else. Guardian Plus was built as one system, and the difference shows up in what it can actually do.

Records know each other

Not synced overnight. Not matched on a hostname string and hoped for. Linked — so a technician holding a ticket can see the machine it came from, connect to it with the right credential, and check what the client is contracted for, without leaving the page or knowing a password.

One identity

One identity provider with multi-factor. One place to add someone, one place to remove them. Deactivate them and every session ends — not eventually, immediately.

One permission model

Permissions by action, granted through your groups, applied identically in every module. Change someone’s group once and their access changes everywhere at the same moment.

One audit trail

When something goes wrong there is one history to read, not four to correlate by timestamp — including who revealed which credential and why they were allowed to.

“Integrated” is a word every vendor in this category uses

Here is the difference between the common version and this one.

Integrated at the login
Built as one system
Single sign-on across separate products, each with its own users and roles underneath
One user record and one permission model. Change a group, and it applies everywhere at once
Scheduled syncs and connectors that copy records between products, then drift
Records are linked, and read live. There is nothing to sync because nothing is duplicated
Each product automates within itself; crossing between them means a webhook or a middleware tool
A workflow can span monitoring, service desk and documentation because they are one system
Four audit logs, four formats, correlated by hand when it matters
One trail covering every module, including who revealed which credential and why they were allowed to
Products version independently. Integrations break in the gap
One release train. Everything moves together or nothing does

Things a bundle cannot do

These aren’t features anyone chose not to build. They are what becomes possible when the tools share a database, a permission model and a release, and impossible when they don’t.

Route tickets on what the monitor saw

Intake rules match on hostname, the failing check’s name, the host group, even the check’s exit code — not just the words in an email. A disk alert on a SQL server can go straight to the database queue.

Connect without seeing the password

Credentials are pulled from the vault and injected into the session server-side. A junior technician can work on a domain controller without ever being shown domain admin.

Attachments land somewhere governed

A file emailed into the service desk becomes a tenant-owned document in the vault, scanned on the way in — not a loose blob in storage nobody audits.

No overnight device sync

The device list in your service desk is fetched live from the monitoring platform, not mirrored on a schedule. There is no nightly job to drift, and nothing stale to reconcile.

Turn a fix into documentation

Write the resolution once and publish it to the knowledge base from inside the ticket, as yourself, already linked to the client and the machine it happened on.

Reports that span the whole estate

Build a dashboard that puts monitoring, service desk and documentation data side by side. Not three exports and a spreadsheet.

The assistant can see across modules

Ask it something that spans two modules and it can actually answer, because there is no integration boundary in the middle. Which clients have unpatched machines and an open ticket about it. Which contract covers the server that just went down.

And it answers as you. Every tool it calls re-derives the permissions of whoever asked, so it cannot surface a record you would not be allowed to open yourself.

It sees what you see

Tools re-derive your permissions on every call. It cannot open a record you cannot.

It cannot act unsupervised

Actions that change things are hidden from the assistant entirely and need a person to confirm.

It is not a bolt-on

The same assistant works across every module, because there is only one set of data underneath it.

One platform means one platform

The modules are not standalone products with an optional platform bolted on — they genuinely run on Guardian Plus, and it comes with every deployment. That is the trade: you cannot take one module and run it somewhere else, and in exchange you get everything on this page.