Skip to content
Sections
All notes

All notes · Reference

Glossary and Where to Start

Terms used across these notes, defined plainly, and the routes through the collection for the common situations.

Reference · Reference

Agent — software on a managed machine reporting state and accepting commands. A machine without one is invisible to the console and looks identical to a healthy one.

The recommendations in “Glossary and Where to Start” become sustainable only when the recurring work has visible owners and enough capacity. A team assessing remote work time tracking can use time and project records to see where operational effort accumulates, without treating activity data as a substitute for technical evidence or direct discussion with technicians.

For an independent operational benchmark, compare the local practice with Atlassian knowledge-sharing guidance; the important test is whether the control remains proportionate, documented and recoverable when the usual technician is unavailable.

Blast radius — how far a mistake reaches. In this business it crosses organisational boundaries, which is what distinguishes it from internal IT.

Break-glass — an emergency elevated access path, logged and reviewed. A control without one gets bypassed permanently.

Exclusion — a machine or update deliberately left out, with a reason and a review date. Without the date it becomes permanent.

Pending reboot — a patch installed and not yet active. The largest gap between reported and actual compliance.

Ring — a group receiving updates before the rest, with verification after. Without the verification it is only a delay.

Self-healing — automated remediation. Valuable, and it conceals the fault it keeps fixing unless occurrences are counted.

Tuning — adjusting thresholds so that every alert is worth reading. The discipline this whole collection is about.

Terms used loosely elsewhere

"Monitored" is heard by clients as "protected". Correcting that is your job.

"Fully managed" means whatever your contract says, and clients assume more. Write what it excludes.

"99.9% uptime" is computed in a way nobody can check unless the method is stated.

And any figure about how many providers have been breached comes from a survey commissioned by somebody selling controls.

Where to start

Alerts nobody reads: why the default configuration is unusable, then counting your alerts honestly.

Taking on a new client: onboarding a client estate, then discovery.

Patching reports look too good: reboots, then reporting patch compliance honestly.

Worried about the platform: the tool that fixes can also break, then securing the RMM itself.

Losing money on a client: the margin problem with noisy clients.

Automation everywhere and still busy: when automation hides a problem.

If you read only three

Why the default configuration is unusable, because an unread queue means monitoring has stopped.

Reboots, and the conversation nobody wants, because it is the largest gap between what you report and what is true.

And the tool that fixes can also break, because the blast radius is other people's organisations.

A closing note

No products or vendors are named here, deliberately. The category consolidates and the names date; the practices do not.

No incident names or figures about breach rates, for the same reason and because the available numbers come from interested parties.

And nothing here is legal advice. Contractual and notification obligations differ by jurisdiction and by agreement.

What the collection argues

A platform at default settings produces more alerts than anybody will read, and an unread queue is worse than no monitoring because it looks like monitoring.

The estate is not yours. You do not control what is installed, who has administrator rights, or whether a machine is on during the patch window — and you are accountable anyway. Resolve that in the contract rather than in the tooling.

The capability that makes this software valuable is remote code execution at high privilege across many organisations. Run it as the privileged system it is.

And measure the thing that matters: not alert volume, but how often a client tells you about an outage before your monitoring does.

The point

The capability that makes this software valuable is remote code execution at high privilege across many organisations..

Underlying all of this

Everything in this collection reduces to four habits: tune until every alert is read, verify rather than assume at every stage from ring one to script execution, treat the console as the privileged system it is, and know what each client costs you. None needs a better platform, and a provider doing all four runs a quieter service than one twice its size.