Remote Console Scope & Future Modules
Examples use the fictional Acme MSP / Acme Corp / Acme HQ world (one operator-org pattern that also fits internal IT and small teams). Hostnames like
acme-wks-01stand in for your endpoints. Portal URLs usehttps://portal.example.comas a stand-in.
Cohort 01 is Remote Console first for operators (MSPs, internal IT, and small teams): enroll endpoints, connect, operate with clear control, and keep a record. Billing is $99 per month or $1 per enrolled endpoint, whichever is more. See Cohort pricing. Future RMM modules are called out as later work, not present claims.
FlowRMM V1 ships as FlowRMM Remote Console: safe, accountable remote operations for operators. It gives operators the endpoint access and action controls they need today, with human approval and audit history where work carries risk. Full RMM capabilities (monitoring, alerts, Intune orchestration, patching at scale) are future modules, not V1 positioning.
FlowRMM gives operators a safer remote console for the AI era. View endpoints, run commands, copy files, deploy packages, and let AI queue remediations without bypassing human approval.
Positioning
| Do | Do not |
|---|---|
| Remote control, interactive console, file copy | Compete with NinjaOne / full RMM on day one |
| MCP-assisted workflows that use human approval | PSA, ticketing, or "we do everything" |
| Runbooks included where they naturally exist | Over-market automation before packaging is final |
| Clear audit history + human approval for risky actions | Pretend enterprise governance is complete |
| Named, transactional HITL trails (request → plan → approve → execute → verify → resolve) | Ship approval queues that only show Entra GUIDs |
Auditable visibility is core, not polish. Onboarding (deploy Graph secrets + day-0 Grant + Portal users) must leave the tenant able to attribute every Actions transaction to people and agents. See Operator Actions & HITL.
Packaging matrix
| Surface | Tier | Entitlement feature | Notes |
|---|---|---|---|
| Environment graph | Core | inventory.read |
Primary operator entry |
| Clients & sites hierarchy admin | Core | inventory.read |
Route /clients + nav; create/rename clients, sites, assign endpoints |
| Remote viewer / control / console / file copy | Core | remote.view, remote.control, remote.console, remote.fileCopy |
Session workspace at /remote/:id |
| Safe-by-default governance | Core | governance.scope |
RBAC/least privilege, operator scope bindings, protected groups, session/action audit visibility, safe limits, four-eyes defaults, and read-only automation/compliance posture. /governance remains visible; scope and protected-group cards stay editable. |
| Ask (plain-English endpoint search) | Deferred | ask.use |
Off on remote_console for go-to-market; enable when LLM_URL (e.g. Microsoft Foundry) is ready. Prod nav also requires VITE_FLOWRMM_SHOW_ASK=true at image build time. |
MCP /api/v1/mcp |
Core | agentic.use + operator roles |
Alert tools require monitoring.use |
| Actions / HITL approval queue | Core | actions.use |
Unified operator action plane |
| Activity (sessions + shaped timeline; technical raw audit retained) | Core | remote.audit.read |
Portal /activity (/audit redirects); /api/v1/audit/* |
| Runbooks / automation | Included-for-now | automation.use |
Nav label "Runbooks"; not over-marketed |
| Packages catalog / deploy | Included-for-now | packages.use |
Pilot decision: nav hidden in production unless VITE_FLOWRMM_SHOW_PACKAGES=true; entitlement remains on remote_console for API/runbook deploy |
| Installers / enrollment | Core | installers.use |
|
Billing (/billing, inline day-0 checkout) |
Core | billing.manage + Admin/Billing app role |
Reachable while unlicensed; Admin performs first instance claim |
| Portal settings | Core | Scoped settings / policy / API-key roles | Billing-only users do not inherit Settings or operator surfaces |
| Docs | Core | docs.read |
Always on; individual docs carry a package (see Docs packages) |
| Ops Knowledge (tenant customer/ops notes) | Core | opsdocs.use |
Portal /knowledge (Ops spaces); /ops-docs compatibility redirect; Postgres folders + markdown + typed relationships; MCP writes via HITL; not product Docs |
| Dashboard monitoring widgets | Preview | monitoring.use / alerts.use |
Off until Admin Hub → Preview features; not a SKU |
| Azure Graph onboarding panel | Module: RMM | graph.manage |
Per-client Azure button on /clients; /api/v1/clients/*/azure-tenant* requires graph.manage |
| Cloud ops (CIPP) | Module: RMM | graph.manage |
Admin → Integrations → Cloud ops; CIPP connector + tenantFilter mapping; not GDAP; wipe/retire/compliance refresh stay Graph intune_command |
| PSA / Flow CRM escalations | Module: RMM | psa.manage |
Provider-neutral work-item delivery for monitoring escalations; Flow CRM is the first adapter (related documentation) |
| Alerts / Monitoring pages | Preview | alerts.use / monitoring.use |
Off until Admin Hub → Preview features; Graph/PSA stay module-gated. Packaged collectors are the floor; app-specific checks are tenant skills promoted from a completed repair (monitor + hashed runbook + autonomy), not extra catalog SKUs. |
| Automation & Compliance | Paid capability | governance.advanced |
Edit tenant control policy, Action autonomy, HITL self-elevate exceptions, Agentic Policy Builder, durable role bindings, WORM/SIEM audit controls, and advanced compliance workflows/reporting. Included in paid pilots; Core remains visible but read-only after pilot. |
| Intune / Autopilot / GDAP / patching at scale | Module: RMM | (future plan) | MVP 2 threads: do not block Remote Console launch |
Related guides
Want hands-on help evaluating Cohort 01? Book a demo or apply for Cohort 01.