GalyctMSP

Platform

An operations layer above your whole portfolio.

Galyct MSP does not copy each client's environment. It consolidates what belongs at operator level, then lets you step into the client's context when the work calls for it.

Architecture

Three levels of reading, from portfolio to client detail.

01

Portfolio

A light projection of each organisation and today's priorities. Fast to scan, even with hundreds of clients.

02

Client 360°

A client's posture, services, mandate, actions and governance, on a single record.

03

Client environment

Business depth and client-specific actions, in Galyct Pro, under mandate and on the record.

Home

My day

  • clients needing action, on watch and stable;
  • incidents and situations to handle;
  • SLAs at risk and overdue actions;
  • service and connector health;
  • today's NARA briefing.
What needs my attention this morning? The operator home ranks the portfolio by real urgency: incidents, SLAs at risk, expiring mandates, silent connectors. A client that is not measured is never shown as stable.

Portfolio

Who needs action, and why.

Filter by criticality, service, NIS 2 obligation, owner, SLA, mandate and connector. Every state is explained and shows how fresh its measurement is. No opaque score is ever presented as the truth.

The portfolio reads a projection computed server-side: you only see clients you hold a mandate for.

Who in my portfolio needs action? Each row states its condition in words, its top reason and the time of its last measurement. The state is explained, never reduced to a score.

Client 360°

Everything you need to know about a client, and what you are allowed to do.

Posture by family, operated services, mandate and its deadlines, open actions, governance decisions. Access to the client's environment is one click away, under your account, within the mandate's scope, and every access is logged.

Where does this client stand, and what am I allowed to do? The record brings together posture, services, mandate and actions. To go deeper, you step into the client's environment, under mandate and on the record.

Operations

From signal to evidence, with no lost step.

Signals from your tools are normalised, deduplicated and correlated. A situation is qualified, then closed with a written decision.

  1. SignalReceived from a connected tool, normalised into a common format.
  2. SituationSignals correlated by client and pattern, without duplicates.
  3. DecisionAction, incident, campaign, client validation or justified closure.
  4. ActionCreated at the client, under the mandated account.
  5. EvidenceTime-stamped log, with the author and reason for each decision.
Is this signal a problem, and what do we decide? Signals are normalised, deduplicated and correlated into situations. A situation closes with a written decision: action, incident, campaign, client validation or justified closure.

Production

The team's work, across all clients, without losing context.

Board, list, workload, calendar, waiting-on-client and SLAs. Every task keeps its client. When you are waiting on the client, the SLA clock stops, and the pause is logged.

Who does what, by when, and which deadline is at risk? Work across all clients is laid out as a board, list or calendar, and every task keeps its client. When you wait on the client, the SLA clock stops, and that is logged.

Campaigns

Same pattern, eligible population, separate actions.

A campaign identifies eligible clients, prepares one common response, then opens a separate action at each client. Validation happens client by client; progress is tracked globally, evidence is kept per client.

The same problem across several clients: how do you act without acting blind? The campaign prepares one common response, then each client validates and receives its own action, separately. Only very low-risk actions pre-approved in the mandate go through without case-by-case validation.

Incidents

The portfolio view of incidents.

Galyct MSP aggregates each incident's phase, priority, owner, SLA and escalation. The detailed handling stays in the client's environment: playbooks, timeline, evidence, report.

When a case is beyond your team, you request escalation to the Galyct firm, as a separate engagement.

  • phase and priority of every open incident;
  • owner and time remaining;
  • escalation requested or under way;
  • direct link to the client's case.

Services and SLAs

What you sold, measured.

A managed service links a commitment, a scope, controls, evidence and an SLA. Its state reads in four words: compliant, degraded, non-compliant, not measured.

Is what I sold actually delivered? A managed service links a commitment, a scope, controls, evidence and an SLA. Its state is compliant, degraded, non-compliant or not measured, and it is reviewed monthly.

Portfolio GRC

Your clients' compliance, at a glance.

Where each client stands on NIS 2, ISO 27001, GDPR or its own commitments, and which deadlines are coming. The view is aggregated; the detail of controls, evidence and exceptions stays in each client's environment. Galyct MSP does not rebuild a second compliance engine.

  • portfolio compliance deadlines;
  • exceptions due for renewal;
  • open gaps by framework;
  • maturity assessments and their progress.

Reports

Show the work done.

Monthly reports, services and SLAs, steering committees, portfolio and campaigns. They carry your brand and the mention "Service operated with GALYCT".

How do I show the work done? Monthly reports, SLA reviews, steering committees and campaign reports come from the same data as operations: decisions, actions, evidence and progress.

NARA

An assistant that prepares and explains. You decide.

NARA analyses the portfolio, a client, an incident, a campaign, a service or your progress in the program. It recommends, prepares, and only executes within authorised categories, after your explicit validation.

It explains before it acts

The recommendation, the signals used, the clients concerned, the expected impact, the risks, the prerequisites and the validation required.

It respects isolation

Multi-client analysis relies on normalised signals, metadata and indicators. No raw data from one client is ever exposed to another.

It follows published lists

Galyct publishes and versions the list of pre-approvable actions and the list of actions NARA may never perform, even when validated.

The AI provider is chosen and managed by Galyct; a partner cannot change it. The AI engine processes data in France or the European Union.

Mandates

No access to a client without a mandate.

The mandate

  • Galyct's standard template is mandatory; annexes are allowed, mandatory clauses cannot change;
  • start date, end date, revocable at any time;
  • reminders at 90, 60, 30, 15, 7 and 1 day before expiry;
  • renewal only after the client's explicit approval.

After the mandate

  • at expiry without renewal, your rights to act are suspended at once;
  • you keep read access to your own intervention history only;
  • a change of provider is scheduled with no overlap;
  • the client keeps its full history, without rebuilding its environment.

Mandates and transfers in detail

Client portal

Your client sees, comments, validates and uploads evidence.

In their Galyct Pro environment, your client views their assessment, maturity score and history, comments, validates actions and uploads documents. They can revoke a mandate or request a transfer.

Some decisions require their validation before closure. Each validation is named, time-stamped and audited: it is a formal, traceable validation, distinct from an electronic signature.

Mandatory client validations

  • risk acceptance;
  • closure of a major incident;
  • exception or non-compliance;
  • business continuity or disaster recovery plan approval;
  • sensitive change of scope;
  • any decision that commits them.

Galyct sets these minimum categories; you can add more.

Team and routing

Every alert goes to the certified role that knows how to handle it.

Galyct defines the routing matrix; a critical alert can go to several roles. Teams, Slack and email are the normal channels.

Type of alertCertified role that receives it
Administration, connectors, exportsCertified Administrator
Posture, vulnerabilities, remediationCertified Operator
Incident, compromiseCertified Incident Operator
Compliance, risk, GDPRCertified GRC Consultant

White label

Your brand up front. Galyct always visible.

Logo, colours, reports, emails, portal and domain can be customised. Galyct remains visible everywhere through a standard mention: "Service operated with GALYCT" or "Secured by GALYCT". Your client always knows which platform holds their data.

  • partner logo and colours;
  • PDF reports and emails in your brand;
  • custom portal and domain;
  • standard Galyct mention, placement set by the partner charter.

See the platform with your own roles.

The 15-day sandbox opens every role and every workflow, on an empty environment you configure yourself.