Settings, API Keys & Tenancy
Each tenant stays isolated. In the Acme example, operators manage API keys and portal roles for their own org — never share keys across unrelated environments.
Tenant boundaries
Operational APIs, telemetry, commands, and remote sessions stay inside one tenant. Treat your operator org (illustrated here as Acme MSP) as its own world: do not reuse keys, tokens, or automation credentials across unrelated customer or business environments.
API keys
On Settings, operators can mint API keys for automation and MCP clients:
- Raw keys are shown once at creation: store them in your secret manager.
- Prefer least privilege (read inventory first; add remote or actions scopes only when needed).
- Revoke keys when a integration ends or a laptop/staff change creates risk.
For MCP connection patterns, see Agent Execution & MCP Control.
Governance-related settings
Cohort 01 teams use Governance for HITL self-elevate, action autonomy, and related operator controls. Treat agent-update rings and maintenance windows as operational posture: not a promise of fleet patching or monitoring modules.
Details for approvals live in Operator Actions & Human Approval.
Related guides
- Get Started with FlowRMM Remote Console
- Operator Actions & Human Approval
- Agent Installers & Enrollment Security
Want hands-on help evaluating Cohort 01? Book a demo or apply for Cohort 01.