Use these pre-built prompts in your administrative assistant console to run quick audits, build customer reports, and monitor operational health across your tenant portfolio.
MSP Prompts (Portfolio Level)
# | Use Case | Prompt | Outcome |
1 | Customer portfolio overview. Show adoption gaps and expansion opportunities for leadership and sales planning. | "Give me a view of my MSP customer portfolio. List every customer with status, access mode (Managed or Restricted), tenant count, edition and storage regions. Build a product-adoption matrix for Enterprise Workloads, Microsoft 365, Endpoints, Google Workspace, Salesforce and other enabled products. Highlight customers using only one product, Business-edition customers eligible for an upgrade, and the most common missing products." | A portfolio table, a customer × product adoption matrix, and cross-sell and upgrade candidates. |
2 | NOC shift handoff. Spot SLA breaches, backup failures and new incidents at the start of every shift. | "Run a start-of-shift health check across all my customers for yesterday 00:00 UTC to today 00:00 UTC. Treat any backup status other than successful as a failure. Show customers with active SLA violations, including the rule, workload, resource, observed value and threshold. Summarise backup jobs and failures for Enterprise Workloads, SharePoint, Teams, Groups, Public Folders, Google Shared Drives and Salesforce. List the ten most important failed jobs with customer, resource and failure reason. Flag any product where today's failures are more than 3× its 7-day daily average. Present this as a shift-handoff dashboard with red/amber/green status by product, a worst-customers table and anomaly alerts." | A shift dashboard: status per product, active SLA breaches, worst customers, a top-10 failed-jobs list and spike alerts, with the time window stated. |
3 | SaaS and Endpoint protection health. Find users and devices that aren't protected, including those that were never backed up. | "Assess Microsoft 365, Google Workspace and Endpoints protection across all customers. For each customer, show provisioned vs backed-up users. Give backup status by workload (Exchange, OneDrive, SharePoint, Teams, Groups, Gmail, Drive) with counts of successful, failed and never-backed-up users. For Endpoints, show devices whose last backup failed, that were never backed up, or that haven't backed up in more than 7 days. Include storage by workload, preserved-user counts and active alerts. Highlight customers where more than 5% of users or devices are unprotected." | A customer × workload health matrix, unprotected % per customer, storage and preserved users, active alerts, and at-risk customers highlighted. |
4 | SLA risk and coverage gaps. Catch SLA misses before the customer does, and find customers you aren't monitoring. | "For the last 7 days, show every customer whose backup success rate is below 95%, broken down by workload, with the main failure reasons. Include SLA rule violations raised in the same period and whether each is active or resolved. Then list the customers and products that have no data protection rule applied." | A customer × workload success-rate table, active and resolved violations, and a list of customers or products with no SLA rule. |
5 | Weekly operations summary. A Monday leadership update with early warning of drift. | "Generate a weekly operations summary for the last 7 complete days compared with the 7 days before. Show total backup jobs, success and failure rates by product with a daily trend, customers with the most failures, SLA violations (new, resolved, active) and current CU consumption vs commitment balance. List customers whose success rate dropped more than 5 points week over week, with the workloads behind each drop. End with the top five items needing attention. Use KPI tiles and trend lines, not raw tables." | Executive KPI tiles, daily trend lines, a week-over-week drift table, top-failing customers, CU status and five watch items. |
6 | Customer SLA compliance report. A customer-ready monthly report without manual consolidation. | "Generate an SLA compliance report for [CUSTOMER_NAME] covering the last 30 days. Show the data protection rules applied and the products they cover. List SLA violations with what was violated, when, and whether it is resolved. Report backup success rates for Enterprise Workloads, Microsoft 365, Google Workspace and Salesforce. Include licensed vs active users per SaaS module and storage and quota utilisation. Make it clean, professional and printable so it can be shared directly with the customer." | A printable customer report: rules and coverage, a violation timeline, success rate per product, and user, storage and quota utilisation. |
7 | Quota and capacity forecast. Prevent overages and raise upsells before customers hit their limits. | "Show quota health across all customers. For each customer and module, show quota limit vs current usage, utilisation %, active violations with severity, and any automatic increase with its next date. Using the last 90 days of daily usage, project each quota 30 days ahead and label it Within quota, Will exceed or Already over. Highlight customers above 80% with no automatic increase, and customers with more than 20% month-over-month storage growth. Show the MSP warning threshold. Green below 70%, amber 70–90%, red above 90%." | A colour-coded quota table with 30-day projections, at-risk customers without auto-increase, fast-growing customers and the warning threshold. |
8 | Monthly billing, reconciliation and margin. Month-end invoicing, commit tracking and profitability in one step. | "Prepare billing for [MONTH YYYY]. Show CUs consumed per customer by product module (Enterprise Workloads, Microsoft 365, Endpoints, Google Workspace) and usage type, priced at $[PRICE] per CU, with each customer's share of the total. Include peak users and storage per customer. Compare licensed capacity with actual usage and flag over- and under-provisioned customers. Add month-over-month change and flag swings above 20%. Reconcile the total against the commit-balance report, and show the remaining balance, daily burn and months until depletion. Using $[COST] per CU as cost, add gross margin by customer and module. Give me a CSV for finance." | Invoice lines with dollar amounts, provisioning flags, MoM changes, a commit-balance reconciliation and runway, a margin breakdown and a finance CSV. Run it at least 48 hours after month-end. |
9 | License renewal tracker. Stop missed renewals and tenant suspensions, and catch trial conversions. | "List every tenant license across all customers with customer, product, edition, service plan, evaluation or commercial, expiry date, status, storage region and enabled premium features (Long Term Retention, Archive, Accelerated Ransomware Recovery, Premium Security). Group them into expiring in 30, 60 and 90 days, with an urgent list for the next 30. Separately list evaluation tenants nearing expiry, suspended tenants, and tenants created in the last 30 days." | A renewal tracker by expiry bucket, an urgent list, a trial-conversion pipeline, suspended tenants and new tenants. |
10 | Security readiness and upsell. Assess security posture and turn the gaps into a sales pipeline. | "Audit security posture across my portfolio. Build a customer × feature matrix for Accelerated Ransomware Recovery (EW, M365, Endpoints, Google Workspace), Long Term Retention, Archive, Premium Security and Security Posture & Observability. Classify each customer as Basic (none), Standard (LTR or Archive), Advanced (any ARR) or Premium (Premium Security). List disconnected Enterprise Workloads agents and Endpoints not backed up in more than 7 days. Find Enterprise or Elite customers without ransomware recovery. Give an action list with customer, recommended feature, prerequisites and active user count." | A security heatmap, a maturity tier per customer, disconnected agents and stale endpoints, and a prioritised upsell list with prerequisites. |
Customer Deep-Dive Prompts
# | Use Case | Prompt | Outcome |
1 | Backup failure root cause (NOC, per incident). Connects the MSP failure count to the actual cause without logging into the customer console. | "My MSP reports show backup failures for [CUSTOMER_NAME]. First show the MSP view for the last 24 hours: failed jobs per product and the failure rate. Then drill into that customer and show: failed Enterprise Workloads jobs with error codes and messages, related alerts, and the last successful recovery point for each failing backup set; whether Microsoft 365 and Google Workspace apps are connected, and which users have failed backups; and Endpoints devices whose last backup failed, that haven't connected in 7 days, or that run an old inSync client version. Give me one view linking each failure to its cause, with the next step for each." | An MSP → customer chain: failure counts, then failing resources with error messages, last good backup, app connection state and device issues, and a fix list. Apps that show as disconnected must be reauthorised in the Druva console; the API can't reconnect them. |
2 | New customer onboarding go/no-go (MSP admin, 24–48 hours after provisioning). | "I onboarded [CUSTOMER_NAME]. At the MSP level, confirm that the customer and every tenant are Ready, and check the edition, service plan features, tenant features, storage regions, and whether access is Managed or Restricted. Then drill into the customer and confirm which products are reachable, Microsoft 365 or Google Workspace connection status, users provisioned, Endpoints devices enrolled and backed up at least once, and Enterprise Workloads organisations, backup sets, policies and first successful jobs, plus any open alerts. Give me a green or red checklist with specific next steps." | A go/no-go checklist per product (provisioned, connected, backing up), mismatches between the plan and the tenant, and next steps. |
3 | Ransomware readiness (security, monthly or after industry news). | "Run a ransomware readiness check. At the MSP level, list customers with and without Accelerated Ransomware Recovery, Premium Security and Security Posture & Observability, disconnected EW agents, and recent rollback actions. Then for [CUSTOMER_NAME / my top 5 customers by user count], check restore-scan settings, Threat Watch configuration and detections in the last 30 days, currently quarantined resources, and IOC sets loaded. Classify each customer as Protected, Partially protected or At risk, and give a prioritised remediation plan." | A readiness matrix (features, scans, Threat Watch, quarantine) per customer, a classification, and a remediation plan. For an active incident, add: "…then create a threat hunt for hash [SHA1] and show matches". Claude will confirm before quarantining anything. |
4 | Complete customer QBR package (service delivery manager, quarterly). | "Prepare a QBR package for [CUSTOMER_NAME] for the last 90 days. From the MSP level: SLA compliance and violations, CU consumption by month, quota utilisation, license details and backup success rates. From inside the customer: Enterprise Workloads storage usage (source vs after dedup), Microsoft 365 or Google Workspace backup health, Endpoints fleet status, cyber resilience posture (restore scans, Threat Watch, quarantines), and admin logins. Present it as a customer-facing report with an executive summary, trends and recommendations, printable." | A customer-ready QBR: executive summary, SLA and usage trends, per-product health, security posture and recommendations. |
5 | Admin access audit (compliance, quarterly). SOC 2 evidence across both layers. | "Run an admin access audit. At the MSP level, list MSP, Tenant and Read Only admins with active status and last login, and flag anyone with no login in 90+ days. Then for [CUSTOMER_NAME / my top 10 customers], list customer console admins with role, state, product access and last login, and flag disabled accounts, admins inactive for 90+ days, and admins created in the last 30 days. Give totals, a role breakdown and recommended actions." | MSP and customer admin inventories, stale and new accounts, a role breakdown and actions. This audit only reports; changing or disabling an admin needs your confirmation. |
