Primo AI
Built to run IT with you.

Chat with your fleet, act on your stack, automate across every product. 
Included in every plan, at no additional cost.

Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Dark interface window asking which licenses haven't been used in 30 days with connectors dropdown.
Chat with your entire IT

All your IT knowledge, one conversation away. From your own stack to Primo's own playbooks.

Interface showing a License Optimization Agent task with a trigger for licenses unused for 30 days.
Deploy expert Agents

Every Primo action is available via API. Trigger from Slack, your automation platform, or your own scripts.

Primo AI can chat with your team, 
act on your stack, and run entire lifecycles.

From a single question to a full lifecycle.
Primo AI handles the IT work you shouldn't have to.

Chat interface showing users discussing Figma SSO login issues and AI restoring access messages.

Access that follow the employee lifecycle

When someone joins, changes role, or leaves, Primo updates every SaaS access through HR events. Day-one onboarding is ready when they sit down. Offboarding is clean by the day they leave.

Table listing SaaS tools with their status and number of identities, including ChatGPT marked rejected with six identities.

Every app, surfaced and governed.

Primo discovers every app your team uses, sanctioned or shadow, and maps every access. You know who has what, what costs what, and what nobody touches. Wasted licenses become budget back in your pocket.

HR driven access

Every grant, change, and revoke happens through HR events. Your access requests are now automatically handled.

Shadow IT, surfaced

Every app your team uses, sanctioned or not, gets discovered automatically. You see what your org actually runs on.

Built for IT agents

Ask Primo who has access to what. Automate your access reviews. Let agents handle the routine requests.

Turn compliance into a state, not a project.

MDM control panel showing device status with encryption not encrypted and OS not up to date warnings.

Fix drift before it becomes a breach.

Encryption off, EDR missing, OS unpatched. Primo flags it, agents fix it.

Software update panel showing 1Password 8.10.60 package with high severity CVE and 3 patches pending out of 244 devices.

Every new CVE, closed on your fleet

ew vulnerabilities detected. Patched in the background. Reported to you.

Access Review Agent instructions and triggers for quarterly checks and new admin role grants.

Never miss an access review.

Quarterly reviews across every SaaS. Audit-ready evidence generated live.

Assets & spend, without spreadsheets

Every action Primo AI can take, in one place. Reusable, composable, versioned.

Never chase a 
missing laptop

Every device tied to a person, a location, a status. Just ask.

Reclaim every seat 
nobody uses

Weekly scan of every SaaS. Dormant licenses flagged and reclaimed automatically.

Every leaver's laptop, 
back on your shelf

Prepaid returns sent, condition checked, hardware redeployed to the next hire.

Know what you spent, 
where and why

Ask "How much on hardware last quarter, per country?" and get your answer in seconds.

Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Devices
Create an OS update policy; macOS 15 minimum with a 14-day deadline. Push it to Engineering first, then the whole fleet.
Draft a reply to the VPN ticket using the article we already published
Summarize this week's tickets and tell me what keeps coming back.
Show me every device that hasn't checked in for 14 days.
Watch stock levels across all locations. When a model runs low, order ahead of demand.
Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Access
Who has admin access to our finance apps and shouldn't?
Which employees have access to apps outside their department?
Who has excessive permissions that should be reviewed?
What access does this employee have across all our SaaS apps?
Which former employees still have active access to sensitive apps?
Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Identity Management
Which employees have duplicate accounts across multiple identity providers?
Who has admin-level access to our identity provider?
Which accounts don't have multi-factor authentication enabled?
List all inactive accounts that haven't logged in for 90 days.
Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Compliance
Get us audit-ready: what's compliant, what isn't, who to chase.
Which apps are missing SOC 2 documentation?
Are we compliant with our data retention policy across all vendors?
Which employees haven't completed mandatory security training?
Generate an audit-ready report of all third-party app access.
Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Employees
Order a 16-inch MacBook Pro for the designer starting Monday. Ship it to our Lisbon office.
This MacBook is coming back from an offboarding. Wipe it, put it back in stock, tell me when it's ready.
Which employees are missing required onboarding tasks?
Who joined the company in the last 30 days and hasn't received their equipment yet?
Which employees left the company but still have active accounts?
Onboard September's joiners: order devices per our equipment policy, provision apps based on each role, and flag anything that needs my approval
Connectors
Provision, revoke, review, escalate.
Spend Management
Which subscriptions renew in the next 60 days, and what will they cost us?
How much did we spend on hardware last quarter, by team?
Find every app paid for on a company card this month, and tell me who owns it.
Which SaaS apps are we paying for but no one is using?
What's our total software spend this quarter compared to last quarter?

Open by design

Bring your own agents. Or plug Primo into any AI toolchain you already run.

Automated offboarding steps in Primo: lock device and revoke SaaS access

MCP standard

Connect Claude, ChatGPT, or your own agents to Primo's data and actions. 
Read fleet state, trigger workflows, all through the open standard.

Primo API response returning an employee's device and SaaS data

Full API

Every Primo action is available via API. Trigger from Slack, your automation platform, or your own scripts.

Detailed audit logs

See who did what, when, and from where.

Multi-factor authentication

SSO and password policies enforced by default, for every account.

Compliance

SOC 2 Type II & GDPR compliant, with your data hosted in France.

Built for the future. Available today.

Meet an IT expert

"Primo has become the IT team's cockpit and dashboard for improving compliance and security at Skello."
Skello logo
Fuki Wony
Lead Infra & IT @ Skello

Discover Primo in 2 minutes

Take a tour of our solution in a demo video