Operator controls
Remote control and operator actions are governed through portal permissions, optional operator scope bindings, and protected groups that can block remote or command dispatch without the required role.
FlowRMM is built so that every consequential action has a name attached to it: scoped operator access, human-in-the-loop approvals for sensitive work, Governance controls for autonomy and self-elevate, and clear audit history. These are the controls your team needs to safeguard client endpoints, and the ones your auditor will ask about.
Cohort scope
Remote control and operator actions are governed through portal permissions, optional operator scope bindings, and protected groups that can block remote or command dispatch without the required role.
Restricted commands land on the Actions queue for Approve & run or Reject. Agents and humans share one action plane, so MCP-requested work gets the same review surface.
Four-eyes (two-person approval) is the default: the requester cannot approve their own action. On Governance, you can allow HITL self-elevate only for selected client environments (sites inherit the parent client; Unassigned is its own environment).
Governance in the portal
Governance is the control surface for action autonomy, HITL self-elevate, tenant policy (interpreters, timeouts, output retention), and operator scope, not a claim that every future RMM compliance module is done.
Public sector & government
Federal, state, local, tribal, and education teams run under different frameworks and different oversight bodies. FlowRMM is architected around the controls those programs care about: scoped access, human approval for consequential work, and attributable audit history: and we align the specifics to your authority to operate during the engagement.
Engagement model
Briefing first, then a scoped review of your framework, data sensitivity, and procurement path. We work to the assurance level your program requires.
In the product today
Federal
Our architecture follows the NIST-aligned control families federal programs are assessed against: defined boundaries, least-privilege operator access, evidence of every consequential action, and continuous reporting. We scope the authorization path with each federal partner.
Review FedRAMP 2026State, local & education
State, local, tribal, and education environments answer to a mix of GovRAMP, statewide policy, and sector rules like CJIS or HIPAA. The same boundary, evidence, and monitoring work supports whichever governing body reviews your program.
Review the GovRAMP programBring the requirement
Tell us your environment, data sensitivity, procurement framework, and the body that governs your IT program. We’ll walk your team through the controls, the audit trail, and how we meet the assurance level you’re held to.
Not a public promise today
Framework mappings and formal attestations are handled per engagement, scoped to the oversight body your program answers to.
No software can eliminate risk; cohort teams should evaluate controls against their own requirements.
Fleet-wide standards scorecards and deeper agentic policy libraries are still hardening, beyond the HITL and autonomy controls shown above.
Operator docs