TRUST BUT VERIFY: The MSP Lesson on Documentation, API Keys, and Auditing | EP135
Update: 2025-10-21
Description
This week, hosts Justin Esgar and Eric Anthony pull back the curtain on a recent crisis within Justin's company that highlights a universal MSP challenge: the dangerous intersection of trust, poor documentation, and automated billing.
Justin shares a raw, real-time story about discovering that custom API calls, built by a former programmer to connect HaloPSA with third-party resellers, had failed to update for months. This led to the company being shorted $60–$70 per month on a single customer — a problem likely compounding across multiple clients.
The hosts dive deep into the operational fallout: spending three hours trying to locate undocumented API keys and wrestling with missing configuration data. The discussion naturally evolves into the broader need for MSPs to implement a "trust but verify" culture. They stress that relying on a single employee’s assurance without operational or financial controls is a fatal flaw.
You'll also hear another cautionary tale: how a computer recycled four years ago suddenly reappeared and re-enrolled in their systems from China, exposing a critical gap in their hardware off-boarding process. This is a must-listen for any MSP owner, manager, or technician who wants to learn how to:
Mitigate risk when relying on proprietary API integrations.
- Establish controls to monitor for automation or vendor breakages.
- Implement documentation SOPs (Standard Operating Procedures) to capture critical business logic, even for internal projects.
- Watch the full episode on YouTube here: https://atmsp.link/YTpodcast
Listen on your favorite platform:
- Apple Podcasts: https://atmsp.link/applepodcasts
- Spotify: https://atmsp.link/spotify
- Audible: https://atmsp.link/audible
Connect with the Hosts:
Justin Esgar (Host, Owner/CEO of Virtua Computers): https://www.linkedin.com/in/justinesgar/
Eric Anthony (Founder and Producer): https://www.linkedin.com/in/esanthony/
Join the All Things MSP Community:
- Facebook Group: https://www.facebook.com/groups/allthingsmsp
- LinkedIn Page: https://www.linkedin.com/company/allthingsmsp/
- YouTube Channel: https://www.youtube.com/@AllThingsMSP
A huge thank you to our Premier Sponsors:
- Gozynta: atmsp.link/gozynta
- EasyDMARC: atmsp.link/easydmarc
- Nodeware: atmsp.link/nodeware
- Helpt: atmsp.link/helpt
- Compliance Scorecard: atmsp.link/compliancescorecard
- Movebot: atmsp.link/movebot
The All Things MSP podcast is a Biz POW LLC production.
Justin shares a raw, real-time story about discovering that custom API calls, built by a former programmer to connect HaloPSA with third-party resellers, had failed to update for months. This led to the company being shorted $60–$70 per month on a single customer — a problem likely compounding across multiple clients.
The hosts dive deep into the operational fallout: spending three hours trying to locate undocumented API keys and wrestling with missing configuration data. The discussion naturally evolves into the broader need for MSPs to implement a "trust but verify" culture. They stress that relying on a single employee’s assurance without operational or financial controls is a fatal flaw.
You'll also hear another cautionary tale: how a computer recycled four years ago suddenly reappeared and re-enrolled in their systems from China, exposing a critical gap in their hardware off-boarding process. This is a must-listen for any MSP owner, manager, or technician who wants to learn how to:
Mitigate risk when relying on proprietary API integrations.
- Establish controls to monitor for automation or vendor breakages.
- Implement documentation SOPs (Standard Operating Procedures) to capture critical business logic, even for internal projects.
- Watch the full episode on YouTube here: https://atmsp.link/YTpodcast
Listen on your favorite platform:
- Apple Podcasts: https://atmsp.link/applepodcasts
- Spotify: https://atmsp.link/spotify
- Audible: https://atmsp.link/audible
Connect with the Hosts:
Justin Esgar (Host, Owner/CEO of Virtua Computers): https://www.linkedin.com/in/justinesgar/
Eric Anthony (Founder and Producer): https://www.linkedin.com/in/esanthony/
Join the All Things MSP Community:
- Facebook Group: https://www.facebook.com/groups/allthingsmsp
- LinkedIn Page: https://www.linkedin.com/company/allthingsmsp/
- YouTube Channel: https://www.youtube.com/@AllThingsMSP
A huge thank you to our Premier Sponsors:
- Gozynta: atmsp.link/gozynta
- EasyDMARC: atmsp.link/easydmarc
- Nodeware: atmsp.link/nodeware
- Helpt: atmsp.link/helpt
- Compliance Scorecard: atmsp.link/compliancescorecard
- Movebot: atmsp.link/movebot
The All Things MSP podcast is a Biz POW LLC production.
Comments
In Channel























