Resource
How RMM and PSA tools work
Every managed provider installs an agent on your machines. It is reasonable to want to know what that software does, what it can see, and what happens to it when the relationship ends. None of it is secret and most providers simply never explain it.
What each system does
Two separate platforms are involved and they do different jobs. Providers rarely distinguish them, which makes the conversation confusing.
| System | What it does |
|---|---|
| RMM agentA small background service on every managed device | Monitors health, applies patches, allows remote access |
| Patch managementWhy patching happens on a cycle rather than ad hoc | Schedules and reports operating system and application updates |
| Remote controlShould require your consent for an attended session | Lets a technician see and control the screen |
| ScriptingHow one change reaches 80 devices in minutes | Runs automated fixes across many machines at once |
| PSA ticketingThe source of your monthly reporting | Records requests, time and resolution |
| Asset inventoryThe raw material for a refresh budget | Tracks hardware, software and warranty status |
Reasonable questions to ask
Six questions any provider should answer without hesitation.
- Can a technician connect without me knowing, or does an attended session require consent?
- Is remote access logged, and can I see the log?
- Does the agent read file contents, or only system state?
- What happens to the agent if we leave, and who removes it?
- Is the monitoring data retained after the relationship ends?
- Which staff at your company can access our environment, and is that access reviewed?
Why tooling is a third of the value
Any provider can buy the same platforms. The licences are not the differentiator and the demo will look identical everywhere.
What differs is what happens with the output. Monitoring that nobody reviews is noise. Patch reports nobody reads are a filing exercise. Ticket data that never gets analysed for recurring causes means the same fault closes every month forever.
When comparing providers, ask what they do with the data rather than which platform they run. The answers separate them quickly.
Common questions
Answered before you ask.
Can our provider read our files?
The agent monitors system state rather than file contents, but a technician with remote access to a machine can see whatever is on the screen, which in practice means they can see files if they open them. That is why attended sessions requiring your consent, and logged access, matter more than the technical capability question.
Does the agent slow machines down?
Modern agents are light and the noticeable slowdowns in most environments come from old hardware or unpatched systems rather than management software. If a machine got slower after onboarding it is worth raising, because it usually indicates a conflict rather than normal overhead.
What happens to the agent when we leave?
It should be removed as part of offboarding, and the agreement should say so with a timeframe. Ask this before signing rather than at the end, because an agent left in place on machines a provider no longer supports is a genuine security issue.
Related
Read next.
IT support and help desk
Tiered support with published response targets, remote and onsite.
Network and infrastructure
Firewalls, switching, Wi-Fi, servers and remote access, monitored.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
What is a managed service provider
The definition, what an MSP does day to day, and how the model differs from hourly IT support.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.