Cohort 01 · Remote Console

FlowRMM

Control. Approve. Own.

One operator. A book of companies. Computers your agents can reach, with humans who approve every move. Deployed in your own Azure tenant.

Jamie at the clinic POS says the printer is down. FlowRMM already knows the fix, your LLM or SLM, talking over MCP. Alex decides whether Restart-PrintSpooler may run. A named action travels the wire, the printer comes back, and Jamie confirms. That is FlowRMM: how your model reaches a real computer, with a person on the gate. Not a full RMM. Homepage plays rotate printer, OneDrive, VPN, and a site circuit that needs the client VP.

  • Remote Console V1Windows and macOS view/control; Linux console and commands
  • Human gateFour-eyes by default for consequential actions
  • Your boundaryCredentials, streams, and audit stay in your Azure tenant
  • Honest scopeMonitoring and fleet patching are not Cohort 01 claims

Live product stage

The same path, in the portal.Not a mockup.

Remote Console on a real enrolled endpoint. Get on the machine, queue a named action, keep the trail.

LIVEacme-mac-01 / remote console
Remote Console (macOS): browser remote desktop, console, and handoff status on an enrolled endpoint. Click to expand.
Shipping today · In scope

What you can actually run

  • Browser-native remote desktop & terminal sessions
  • Named actions on one computer (winget, PowerShell, shell)
  • Approval policy: four-eyes on high-risk work, auto-run only on low-impact scripts you choose
  • Native MCP so an agent can inspect and queue: a person still approves
  • Mobile-friendly triage from any modern browser
  • A book of companies: client, site, and the computers at each
Your tenant

Your Azure. Your keys. Your approval.

  • Runs in your Azure: Deploy inside the tenant you already govern: VNet isolation, Entra ID, Conditional Access.
  • Bring your LLM: ChatGPT, Claude, or a local SLM: if it speaks MCP, it can inspect endpoints and queue a named action. Nothing consequential runs until someone approves it.
  • Triage from a browser: Approve, inspect fleet state, and open a session from a phone. No operator desktop client.

Flow Personal

Your computers. One simple place.

Create a passkey account, add a computer you own, then connect from your browser or phone. Your phone is a viewer and uses no computer slot.

Personal Free · $0

Two owned computers, indefinitely. No payment card required.

Personal Plus · $5/month

Ten computers total, in USD before applicable tax. Upgrade in your account when you need more computers.

Both plans include passkeys and the same available remote-control capabilities. No connection, minute, or session-duration charges. Available capabilities depend on your computer, permissions, and desktop session. Plus renews monthly until canceled; access continues through the paid period.

For adults in the United States using their own U.S. computers. Terms · Privacy and support

Connect your AI

Your AI. The right connection.

MCP connects a compatible AI app to FlowRMM. The Agent Plugin adds our operating instructions and the connection URL. You still sign in and review the requested access.

Flow Personal

Connect to your own computers with your Personal passkey. Your AI can inspect their status, request commands, capture screenshots, and request desktop input. Commands and input wait for your approval by default.

https://personal.flowrmm.com/api/v1/mcpDownload Personal Agent Plugin

Or paste the MCP URL into your AI app. Sign in and approve the connection; screenshots are included in that consent. Your Free or Plus computer limits still apply.

FlowRMM Business

Business connects to your organization’s own portal. Ask your administrator for its URL, then add /api/v1/mcp.

https://<your-business-portal>/api/v1/mcp

Download the Agent Plugin from that portal’s Installers page for a package with the correct URL. Sign in with your organization’s account. Its roles, licensed tools, and approval policies determine what your AI can do.

Each Business deployment has its own connection. The Personal URL reaches your Personal computers only.

Plugin downloads contain no credentials and grant no extra access. Availability depends on your AI app’s MCP or Agent Plugin support.

Architecture & security

No vendor-side broker holds your keys.

Hosting FlowRMM in your own Azure tenant keeps endpoint credentials, session streams, and audit logs inside the perimeter your team already governs.

  • Your perimeter

    Credentials, streams, and logs stay in tenant, behind your existing network and identity controls.

  • Microsoft Sentinel

    Forward session, control, and action events into the SIEM your SOC already watches.

  • Azure Key Vault

    Secret custody and rotation stay under your own vault policy, not ours.

Operator path

See it. Decide. Prove it.

Intelligence is cheap. Permission, execution, and proof are the product.

01 / 03

See it

session.live

The person at the keyboard reports it, or you open Remote Console from the browser and look yourself.

02 / 03

Decide if it runs

action.queued

A named action is staged. Policy says whether Alex can approve it, or whether a second person has to.

03 / 03

Prove it

audit.written

The box goes green and the person confirms. Session and action history stay with the team.

Endpoints: enrolled inventory, check-ins, and client / site context before you connect.
Actions: MCP-queued winget uninstall of Google Chrome on Windows (CAKE-PC), approved, executed, exit 0.

Product tour · Acme demo tenant

See the console in action.

Real operator-portal screenshots. Click any shot to expand it.

Slide 1 of 5
01 / Live Desktop & Terminal
WindowsmacOSLinux (console)

In-Browser Remote Console for Windows and macOS

Connect to a user session or a background shell without installing a desktop client.

FlowRMM provides browser-native remote desktop and terminal sessions on enrolled endpoints. Operators can view display streams, take keyboard/mouse control, or launch elevated diagnostic consoles on demand. Linux endpoints run the same agent for console and command work; remote view depends on the desktop session available.

  • Zero client downloads for operators: the full console runs in a standard web browser.
  • Multi-monitor displays, full-color rendering, and responsive keyboard and mouse input.
  • A session timeline records who connected, when, how long the session ran, and how it ended.
Console view:
LIVEacme / remote-console
Remote Console (macOS): In-browser screen control, input stream, and session diagnostics on Acme HQ workstation.

Principle

Your LLM can know the fix. A person decides if it runs. The trail shows who approved it.

The FlowRMM operating principle

Governance & HITL

Humans stay in the loop before consequential work runs.

Governance sets who can approve what: four-eyes by default, optional self-elevate by client environment, and action autonomy that can auto-approve only low-impact kinds. High-risk actions stay human-gated.

More on the Security approach or the HITL operator guide.

Evaluating FlowRMM for a federal, state, local, tribal, or education environment? Review our public-sector readiness and certification path.

Flow · HITLreq_9a3f · 00:14
REQUESToperatorAPPROVEfour-eyesEXECUTEendpoint
t+00 requestedt+04 approvedt+09 exit 0
HITL self-elevate: four-eyes stays default; allow-listed environments when an operator may approve their own request.
Action autonomy: pick low-impact action kinds and environments; high-risk work still needs a person.

Example path

How Acme removes Chrome on a Windows endpoint.

One ticket, four handoffs: queue, approve, execute, record.

  1. 01Queue

    Operator queues a winget uninstall for an Acme Corp workstation.

  2. 02Approve

    A human Approves & runs the action, with four-eyes when policy says so.

  3. 03Execute

    The Windows agent runs the command and returns stdout + exit code.

  4. 04Record

    The timeline keeps the handoff for the next operator on the ticket.

Public docs

Operator guides for the Cohort 01 path.

Enroll an Acme-style endpoint, open Remote Console, and practice Approve & run. It is the same narrative as the marketing pages, written for operators.

Closed pilot · Limited seats

Bring a real ticket queue. We will build with you.

Cohort 01 is not a webinar funnel. It is a fit-checked pilot with the people shipping the product.

  1. 01Fit

    We look at your environment, the workflow you care about, and whether Cohort 01 is the right test.

  2. 02Pilot

    You run the remote-console path with direct access to the people shipping the product.

  3. 03Feedback

    What breaks in your shop shapes what we harden next, not a survey nobody reads.

Next step

See it on a live endpoint.

Book a 30-minute walkthrough of the path you just watched: get on the machine, stage a named action, decide if it runs. Cohort 01 is $99 per month or $1 per enrolled endpoint, whichever is more. The call is the product, not a deck.

Fast path · 30 min

Book a Demo

Live product walkthrough for your workflow.

Not ready for a call? Apply in the form. Want to hang out first? Discord is open.

Cohort 01 · if a call is the wrong next step

By submitting, you’re asking us to contact you about Cohort 01. This is an early-access application, not a purchase or contract.