If you work with a managed IT provider, you have probably heard the term RMM, short for remote monitoring and management. A small piece of software, called an agent, is installed on each computer and server. It is one of the main tools that lets a provider support many devices efficiently. Because it is powerful, administrators should understand what it does and ask good questions about it.
The agent runs quietly in the background and reports back to the provider's management platform. Common functions include:
Inventory: recording the device name, operating system, hardware and installed software
Health monitoring: watching disk space, memory use, failed services and whether backups ran
Patching: installing operating system and application updates on a schedule
Alerting: notifying the provider when something looks wrong, often before staff notice
Remote support: letting a technician connect to fix a problem without traveling
Running scripts: applying settings or fixes across many devices at once
Security tool management: checking that antivirus or endpoint protection is installed and current
Many people worry that the tool lets a provider read everything on their computers. In general, an RMM agent is built for device management, not for reading documents or email. It typically collects technical details about the machine rather than the contents of files. That said, it has administrative-level access to the device, which means it could in principle be used to do much more. That is why trust in the provider and the controls around the tool matter.
Because an agent runs with high privileges on machines that may hold resident information, it falls within your security and HIPAA responsibilities. Your provider will likely be considered a business associate, so make sure a business associate agreement is in place. Then ask about the practical safeguards.
Who can access the platform, and is multi-factor authentication required for every technician?
Are technician actions logged, and can you request a record of what was done on your devices?
How are remote sessions started? Is permission requested from the user, or can technicians connect unattended? Both have uses, but you should know which applies.
What data does the agent collect, and where is it stored?
How is the platform itself secured and updated? Remote management tools have been targeted by attackers, so a provider who patches promptly matters.
What happens to the agent when you end the relationship? It should be removed and access revoked.
Is every device covered? Unmanaged computers are the ones that miss updates.
A technician connecting remotely should be expected and identifiable. Staff should feel free to ask who is connecting and why.
Anyone who gets a call asking them to install remote access software they did not expect should refuse and report it. Scammers use the same technique.
Staff should not uninstall or disable the agent. If it causes a problem, report it.
For a multi-site operator, the agent is how an issue like a full disk or a missed update is caught before it becomes an outage. It also provides the device inventory that insurers and auditors increasingly ask about, and it supports consistent patching across locations without a visit to each.
Ask for a short report: which devices have agents, which do not, who has administrative access to the platform and when that access was last reviewed. It is a ten-minute conversation that confirms the tool is doing the job you are paying for.
UnityCare IT uses remote management to support healthcare clients, and we are happy to explain exactly what is installed, what it reports and how access is controlled on your devices.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172