Start an evaluation

The agent

One installer, forty-two declared verbs, and remote control included — with a privacy boundary enforced in the database rather than promised in a policy.

One installer, one signed channel, no second daemon

Every action it can take is a declared verb sitting on the autonomy ladder with its risk tier. There is no back door and no unlisted capability — a verb that skipped the declaration would be invokable and ungated, which is the one thing the design does not permit.

Remote control is included, not an add-on. Attended and unattended sessions, remote shell, file transfer both ways, and chat with the person at the desk. Most MSPs pay a separate vendor per technician per month for exactly this. It is in the six dollars.

And the session never leaves your building. Every other remote-control product in this market relays through the vendor's cloud — the technician connects to their infrastructure, the endpoint connects to their infrastructure, and the two are joined somewhere you do not control.

That relay reaches every endpoint you manage. In 2024 a remote-access product used right across this industry shipped a flaw that let anybody in without a password, and it was being used against MSPs before most of them had patched it. The blast radius of that kind of flaw is every machine on every client site, through a system nobody in your building operates.

Here the relay is your own box. The agent already has a signed channel to it, and remote control runs down that same channel — no second daemon, no second update path, no second thing to trust, and no third party anywhere in the connection.

Starting a session requires a step-up authentication, and every session is on the record with who took it, which machine and when. Your client can read that record in their own portal.

ALL NAMES CARRY THE agents. PREFIX READ · 18 browse_fileschat_repliesdrivesevent_loglist_adapters list_linux_updateslist_printerslist_processeslist_serviceslogin_history pingregistry_readremote_framescreenshotspeed_test system_infotoast_cancellationstraceroute ACT · 9 capture_packetschat_sendcontrol_serviceprinter_actionremote_close restore_hostrun_inventorytoastwake_on_lan DESTRUCTIVE · 15 agent_execdeploy_linux_packagedeploy_patchdeploy_thirdpartyisolate_host kill_processrebootregistry_writeremote_inputremote_open remote_shellremote_transferrun_scriptterminaluninstall_patch there is no forty-third a verb that skipped the declaration would be invokable and ungated
Never commits to a client · approves billable time · attests compliance NOT A RUNG — NOT ON THE LADDER AT ALL 04 Act, consequential patches, isolates, changes a configuration OFF BY DEFAULT PER CLIENT 03 Act, reversible restarts a service, clears a queue, with an undo 02 Recommend drafts an action for a person 01 Observe reads, reports, never touches Each client sits at a level you chose. Nothing moves up on its own.

Investigate without touching anything

Processes, services, drives, adapters, printers, event log, login history, system info, installed software, file browse. Ping, traceroute and an on-demand speed test from the endpoint itself.

And a bounded packet capture from the machine in question — the same capture engine the site collector uses, one implementation rather than two. It requires a duration, a byte cap and a filter it can actually apply, and refuses a filter it cannot enforce rather than recording everything under a label saying it did not. It returns the kernel's own drop counters, so the analysis can say what it missed.

Act, on the ladder

Deploy or roll back a patch. Install third-party software. Control a service, kill a process, read and write the registry, run a script, reboot, wake on LAN.

Each with its risk tier declared before it can be invoked, and each promoted or demoted on a measured accuracy record rather than on a setting somebody changed once.

Genie decides 123456789 is the tool declared kill switch autonomy level environment prohibitions rate limits and usage counts blast radius change control the ladder what tier is it not in wayne_tools tenant stopped everything client below this tier forbidden here too much, too fast high blast, unacknowledged destructive · no window shadow logs · approve waits from the database, not the caller refused, and recorded as refused the endpoint verified, not reported the ledger records what was confirmed, not what was attempted unreadable state refuses · it is never read as permission Nine gates, one path. There is no second way to reach a verb — which is the only reason a list of forty-two means anything.

Contain, and undo it

Isolate a compromised host from the network — and restore it.

The restore verb is protected first in every boundary this platform writes. A control loose enough to refuse it would leave a machine cut off with no way back — which is the failure that turns a containment into an outage.

on the network isolated isolate_host DESTRUCTIVE restore_host ACT · protected first in every boundary A control loose enough to refuse the restore would leave a machine cut off with no way back — which is the failure that turns a containment into an outage.

Talk to the person at the desk

A notification when something was fixed. A chat when they need a hand.

Never during a presentation or a full-screen session. Never asking them to do anything technical. Never blaming them.

And always in your name rather than ours. A problem fixed before somebody noticed is your win, and your client should hear it from you.

the platform toast_cancellations somebody pressed cancel chat_replies what the user typed, and whether a channel exists terminal which security context actually ran the command THE MACHINE, AND THE PERSON AT IT an undeliverable toast never lets its action proceed A console can tell you it sent a warning. Only the agent can tell you the person cancelled. An action that proceeded after an undelivered warning is the one your client complains about.

What it deliberately cannot do

  • No keystroke logging. Not gated, not tiered — absent
  • No browsing history
  • No document or screen content capture for monitoring
  • No per-user application profiling

The health data structure has nowhere to put a user, a window title or a path. A struct with no field for it is a stronger statement than a policy, and it is enforced in the database: a signal about a person cannot be stored.

THE HEALTH RECORD host_iduuid observed_attimestamp cpu_pctsmallint mem_pctsmallint disk_free_gbinteger service_stateenum patch_stateenum uptime_sinteger FIELDS THAT DO NOT EXIST user window_title keystrokes url_visited document_path application_focus A struct with no field for it is a stronger statement than a policy. There is nowhere to put a window title, so there is no setting that turns it on.

Screen access exists, and it is not silent

Support needs to see a screen and drive a mouse, so those verbs exist. Pretending otherwise on a page about privacy would be the fastest way to lose your trust.

Opening a session is the highest tier there is — the same tier as running a script or writing to the registry. Taking control of the mouse is too. Reading a frame inside a session somebody has already consented to is not, because at that point nothing changes by looking. Every session is written to the ledger. No configuration makes them silent.

An agent that could watch an employee without a trace is a legal problem for you, not a feature — and it is the thing your client's staff will ask about first.

remote_open DESTRUCTIVE opens control of a desktop remote_frame READ looks, and changes nothing remote_close ACT ends what is happening inside a session the person agreed to Every one of the three is written to the ledger. The tier decides what it takes to invoke, never whether it is recorded. the tiers are the honest ones rather than the convenient ones — comment in agents/windows-agent/toolset.go

And it will not make the machine slow

The resource ceiling is a hard limit, checked before the work rather than after. An unmeasurable budget is treated as a breached one, and an unreadable host load backs off rather than assuming the machine is idle.

A skipped collection window is published with its reason rather than silently omitted — going quiet under load and having died produce the same absence of rows, and only one of them is fine.

NORMALHOST BUSYLOAD UNREADABLE ceiling agent budget ceiling backs off ceiling zero an unmeasurable budget COLLECTION WINDOWS skipped, and published with its reason Going quiet under load and having died produce the same absence of rows, and only one of them is fine.

Try it on your own estate

Thirty days, read-only, on your own hardware. No card, no call, and nothing to uninstall if you walk away.