Skip to content
Sections
All notes

All notes · Basics

RMM, PSA and the Tools Around It

What sits next to the monitoring platform, what each is for, and the integrations that matter more than they appear.

Basics · Reference

RMM rarely stands alone. Knowing what belongs where prevents the common mistake of expecting one tool to do another's job.

The recommendations in “RMM, PSA and the Tools Around It” become sustainable only when the recurring work has visible owners and enough capacity. A team assessing the practical checklist can use time and project records to see where operational effort accumulates, without treating activity data as a substitute for technical evidence or direct discussion with technicians.

For an independent operational benchmark, compare the local practice with NIST Cybersecurity Framework; the important test is whether the control remains proportionate, documented and recoverable when the usual technician is unavailable.

PSA: the business system

Tickets, time, contracts, billing, client records.

RMM generates the work; the professional services automation tool records and bills it.

The integration between them is the one that matters most, because without it every alert becomes manual ticket entry and the time never gets captured.

Documentation platforms

Client-specific knowledge: passwords, network diagrams, procedures, the quirks.

Separate from both, and the place technicians actually look.

Its own note argues this is the highest-return investment in the stack, and it is routinely the last thing bought.

Backup and recovery

Monitored through RMM, managed separately.

The integration worth having is alerting: a failed backup should raise the same way a failed disk does.

Backups that are configured and unwatched are the commonest unpleasant discovery in this business.

Security tooling

Endpoint protection, detection and response, email filtering.

Increasingly bundled with RMM platforms, which is convenient and concentrates risk — the supply chain note covers why that matters.

Monitoring their health through RMM is reasonable. Treating RMM as the security product is not.

Remote access

Usually inside the RMM, sometimes separate.

If separate, it needs the same controls: authentication, logging, session recording where appropriate.

A second remote access tool nobody governs is a common finding in audits of this stack.

The integration that gets skipped

Alert to ticket to time to invoice.

Each hop that is manual loses time and loses billing.

Most providers have the first hop and not the rest, and the unbilled time is larger than anybody estimates.

Consolidation versus separate specialists

One vendor supplying everything simplifies integration and concentrates exposure.

Several vendors spread exposure and cost integration effort.

Neither is wrong; what matters is knowing which you chose and what it implies, which the supply chain note sets out.

What to check

Is your RMM integrated with your PSA, and at which hops?

Where does client-specific documentation live?

Do failed backups alert the same way as hardware faults?

And is there a second remote access tool nobody governs?

The point

The integration that matters is alert to ticket to time to invoice.

Most providers have the first hop and not the rest.

Underlying all of this

Everything in this collection reduces to four habits: tune until every alert is read, verify rather than assume at every stage from ring one to script execution, treat the console as the privileged system it is, and know what each client costs you. None needs a better platform, and a provider doing all four runs a quieter service than one twice its size.

The recurring pattern

The recurring pattern across every section here is the same: the appearance of control substituting for control. An unread alert queue looks like monitoring. A compliance percentage that excludes pending reboots looks like protection. A script that reports success looks like automation. In each case the provider believes a risk is handled and it is not, which is worse than knowing it is open.