Operator controls
Remote control and operator actions are governed through portal permissions, optional operator scope bindings, and protected groups that can block remote or command dispatch without the required role.
Responsible Stewardship & Security
FlowRMM is built around responsible fleet stewardship: scoped operator access, human-in-the-loop approvals for sensitive work, Governance controls for autonomy and self-elevate, and clear audit history. We give fleet caretakers the exact controls needed to safeguard client endpoints.
Cohort scope
Remote control and operator actions are governed through portal permissions, optional operator scope bindings, and protected groups that can block remote or command dispatch without the required role.
Restricted commands land on the Actions queue for Approve & run or Reject. Agents and humans share one action plane, so MCP-requested work gets the same review surface.
Four-eyes is the default: the requester cannot approve their own action. On Governance, you can allow HITL self-elevate only for selected client environments (sites inherit the parent client; Unassigned is its own environment).
Governance in the portal
Governance is the control surface for action autonomy, HITL self-elevate, tenant policy (interpreters, timeouts, output retention), and operator scope, not a claim that every future RMM compliance module is done.
Not a public promise today
We do not claim a certification or compliance outcome on this site.
No software can eliminate risk; cohort teams should evaluate controls against their own requirements.
Fleet-wide standards scorecards and deeper agentic policy libraries are still hardening, beyond the HITL and autonomy controls shown above.
Operator docs