Ledger docs
Ledger is a read-only endpoint reconciliation auditor for MSPs. It connects to the tools you already run — an RMM, an EDR, Microsoft Intune/Entra, your PSA — and reconciles what each one says about a device into one picture: what's managed, what's missing, and what's billed but not actually protected (or protected but not billed).
Ledger never remediates anything. It never installs an agent or changes a policy, and every connector in this documentation only reads your data. The only requests that are not plain reads are the sign-in requests some connectors make to obtain an access token and Intune's request asking Microsoft to prepare a device export; none of them changes anything in your tools. The one optional exception is ticket creation, which is available only to accounts that have been enabled for it (see tickets). The security page covers data handling, and each connector's page describes what it reads.
Where to start
- New to Ledger? Getting started walks through connecting your first two sources, mapping clients, and reaching your first set of exceptions.
- Connecting a specific source? Each connector has its own step-by-step credential walkthrough: NinjaOne · Microsoft Intune · Huntress · SentinelOne · ConnectWise PSA · ConnectWise Automate · Datto RMM · Microsoft Defender · HaloPSA · Autotask
- Understanding what you're looking at? Client mapping, the device matrix, and exceptions cover how Ledger attributes devices to clients and decides what counts as a problem.
- Money questions? Billing reconciliation explains how Ledger links what you bill to what you actually manage — and where it can't, honestly.
- Getting data out? Reports covers scheduled email reports; exports covers CSV/XLSX downloads.
- Trust and data handling: see security.
- Everything else: see the FAQ.