Responsible Stewardship & Security

Accountability is a product requirement, not a badge.

FlowRMM is built around responsible fleet stewardship: scoped operator access, human-in-the-loop approvals for sensitive work, Governance controls for autonomy and self-elevate, and clear audit history. We give fleet caretakers the exact controls needed to safeguard client endpoints.

Governance: Action autonomy: only selected low-impact kinds can auto-approve; high-risk stays human-gated. Click to expand.

Cohort scope

What we are putting in customers’ hands now.

Operator controls

Remote control and operator actions are governed through portal permissions, optional operator scope bindings, and protected groups that can block remote or command dispatch without the required role.

HITL approvals

Restricted commands land on the Actions queue for Approve & run or Reject. Agents and humans share one action plane, so MCP-requested work gets the same review surface.

Four-eyes & self-elevate

Four-eyes is the default: the requester cannot approve their own action. On Governance, you can allow HITL self-elevate only for selected client environments (sites inherit the parent client; Unassigned is its own environment).

Governance in the portal

Where human-in-the-loop is configured.

Governance is the control surface for action autonomy, HITL self-elevate, tenant policy (interpreters, timeouts, output retention), and operator scope, not a claim that every future RMM compliance module is done.

HITL self-elevate: choose environments where self-approval is allowed; everything else stays four-eyes.
Actions: review surface for MCP- and operator-requested work; this run removed Google Chrome on CAKE-PC with exit 0.

Not a public promise today

Deliberately outside the first cohort’s product claim.

Compliance certification

We do not claim a certification or compliance outcome on this site.

Absolute security guarantees

No software can eliminate risk; cohort teams should evaluate controls against their own requirements.

Broader compliance packaging

Fleet-wide standards scorecards and deeper agentic policy libraries are still hardening, beyond the HITL and autonomy controls shown above.