Start an evaluation
The agent
One installer, forty-two declared verbs, and remote control included — with a privacy boundary enforced in the database rather than promised in a policy.
One installer, one signed channel, no second daemon
Every action it can take is a declared verb sitting on the autonomy ladder with its risk tier. There is no back door and no unlisted capability — a verb that skipped the declaration would be invokable and ungated, which is the one thing the design does not permit.
Remote control is included, not an add-on. Attended and unattended sessions, remote shell, file transfer both ways, and chat with the person at the desk. Most MSPs pay a separate vendor per technician per month for exactly this. It is in the six dollars.
And the session never leaves your building. Every other remote-control product in this market relays through the vendor's cloud — the technician connects to their infrastructure, the endpoint connects to their infrastructure, and the two are joined somewhere you do not control.
That relay reaches every endpoint you manage. In 2024 a remote-access product used right across this industry shipped a flaw that let anybody in without a password, and it was being used against MSPs before most of them had patched it. The blast radius of that kind of flaw is every machine on every client site, through a system nobody in your building operates.
Here the relay is your own box. The agent already has a signed channel to it, and remote control runs down that same channel — no second daemon, no second update path, no second thing to trust, and no third party anywhere in the connection.
Starting a session requires a step-up authentication, and every session is on the record with who took it, which machine and when. Your client can read that record in their own portal.
Investigate without touching anything
Processes, services, drives, adapters, printers, event log, login history, system info, installed software, file browse. Ping, traceroute and an on-demand speed test from the endpoint itself.
And a bounded packet capture from the machine in question — the same capture engine the site collector uses, one implementation rather than two. It requires a duration, a byte cap and a filter it can actually apply, and refuses a filter it cannot enforce rather than recording everything under a label saying it did not. It returns the kernel's own drop counters, so the analysis can say what it missed.
Act, on the ladder
Deploy or roll back a patch. Install third-party software. Control a service, kill a process, read and write the registry, run a script, reboot, wake on LAN.
Each with its risk tier declared before it can be invoked, and each promoted or demoted on a measured accuracy record rather than on a setting somebody changed once.
Contain, and undo it
Isolate a compromised host from the network — and restore it.
The restore verb is protected first in every boundary this platform writes. A control loose enough to refuse it would leave a machine cut off with no way back — which is the failure that turns a containment into an outage.
Talk to the person at the desk
A notification when something was fixed. A chat when they need a hand.
Never during a presentation or a full-screen session. Never asking them to do anything technical. Never blaming them.
And always in your name rather than ours. A problem fixed before somebody noticed is your win, and your client should hear it from you.
What it deliberately cannot do
- No keystroke logging. Not gated, not tiered — absent
- No browsing history
- No document or screen content capture for monitoring
- No per-user application profiling
The health data structure has nowhere to put a user, a window title or a path. A struct with no field for it is a stronger statement than a policy, and it is enforced in the database: a signal about a person cannot be stored.
Screen access exists, and it is not silent
Support needs to see a screen and drive a mouse, so those verbs exist. Pretending otherwise on a page about privacy would be the fastest way to lose your trust.
Opening a session is the highest tier there is — the same tier as running a script or writing to the registry. Taking control of the mouse is too. Reading a frame inside a session somebody has already consented to is not, because at that point nothing changes by looking. Every session is written to the ledger. No configuration makes them silent.
An agent that could watch an employee without a trace is a legal problem for you, not a feature — and it is the thing your client's staff will ask about first.
And it will not make the machine slow
The resource ceiling is a hard limit, checked before the work rather than after. An unmeasurable budget is treated as a breached one, and an unreadable host load backs off rather than assuming the machine is idle.
A skipped collection window is published with its reason rather than silently omitted — going quiet under load and having died produce the same absence of rows, and only one of them is fine.
Try it on your own estate
Thirty days, read-only, on your own hardware. No card, no call, and nothing to uninstall if you walk away.