Your whole fleet’s vital signs. One dashboard.
Cross-Platform Agents
Native signed agents for macOS, Windows, and Linux
Combine Score
Fleet health scored 0–100 and graded A–F
Smart Alerting
Thresholds, anomaly detection, and process watches
Monitoring-Only by Design
Observes and reports — never controls your devices
The whole fleet, at a glance.
Combine Score & Draft Board
Every device earns a Combine Score — a weighted 0–100 health grade across CPU, memory, disk, availability, and network — rolled up into an A–F letter.
The Draft Board ranks your whole fleet as a leaderboard, heatmap, or SLA/uptime view over 24 hours, 7 days, or 30 days. Problem machines can’t hide.
Native Agents for Every Platform
Signed and notarized .pkg on macOS, MSI on Windows, and a single static ~9 MB Go binary on Linux — no runtime dependencies, reporting over HTTPS about every 30 seconds.
Retune collection intervals live without reinstalling, spot agent version drift at a glance, and tag, assign, or clean up devices in bulk.
Alerting That Cuts the Noise
Threshold rules, escalating offline alerts, and process watches that raise and clear themselves — plus Pro-tier anomaly detection and memory-leak detection with culprit-process awareness.
Flap suppression and escalation policies keep it quiet; email, Slack, webhooks, and scheduled digests keep everyone informed.
Security Posture & CVE Matching
Installed software is matched against NIST NVD CVE feeds — auto-synced every 6 hours — into per-device, severity-ranked findings.
Encryption, patch state, AV/EDR, and firewall status round out the picture, alongside disk SMART, thermals, and battery health.
Certificates, Assets & Compliance
Watch TLS certificate and domain expiry — checked daily, with alerts under 30 days — track hardware and software inventory, search installed software fleet-wide, and monitor backups, watchdogs, and event logs.
Warranty and AppleCare tracking plus IP-based geolocation help you keep tabs on the physical fleet, too.
Built for MSPs & IT Teams
Multi-Tenant by Default
Super-admin oversight with fully isolated per-org client admins — every device, alert, and setting is org-scoped.
SSO & RBAC
OIDC and SAML 2.0 (Entra, Google, Okta, Auth0, Keycloak) with admin, member, and viewer roles and a full audit trail.
White-Label Theming
Custom palettes, branding, and an opt-in public status page — make every client’s dashboard look like theirs.
The full feature list.
-
Dashboard
- • Fleet tiles the moment you log in: total, online, and offline agents plus open alerts
- • License usage bar — seats in use vs. your plan
- • Fleet-wide averages for CPU, memory, storage, and gateway latency
- • Devices-by-OS breakdown across Windows, macOS, and Linux
- • 24-hour fleet CPU & memory trend charts
-
Draft Board
- • Combine Score: weighted 0–100 health grade per device (CPU, memory, disk, availability, network), lettered A–F
- • Leaderboard, Heatmap, and SLA/Uptime views over 24 h, 7 d, or 30 d
- • Fleet average score and grade distribution at a glance
- • Per-device breakdown bars with 24-hour trend arrows
- • Hour-granularity rollups retained for roughly 400 days
-
Agents
- • Native agents: signed & notarized .pkg (macOS), MSI (Windows), and a single ~9 MB static Go binary (Linux .deb)
- • Metrics over HTTPS about every 30 seconds, plus a live WebSocket command channel
- • Collection interval tunable from 10 to 3600 seconds per org or device — re-times live, no reinstall
- • Agent version-drift view with up-to-date/outdated counts; devices and metrics CSV export
- • Search, filters, and saved presets; bulk tag, set-owner, restart, uninstall, or delete
- • Stable machine-id identity prevents duplicate devices
- • Per-device drill-down: processes, crashes, logs, user presence, and jetsam/OOM kills
-
Compare
- • Side-by-side comparison of two to four devices
- • Values that differ across the selected devices are highlighted automatically
-
Alerts
- • Critical, high, warning, and info severities with acknowledge and acknowledge-all
- • Escalating offline alerts by minutes offline — auto-clearing when the device reconnects
- • Ticketing hand-off to Metahuman Helpdesk, ServiceNow, Jira, or Zendesk
- • Full alert history with CSV export
-
Alert Rules
- • Per-metric threshold rules scoped to the whole fleet, a tag, or a single device
- • Anomaly detection (Pro): per-device CPU/memory baselines with tunable σ sensitivity and culprit-process awareness
- • Memory-leak detection (Pro) via regression on per-process memory growth
- • Flap suppression and tiered escalation policies keep alerting quiet
- • Configurable offline-alert tiers
-
Notifications
- • Email, Slack, and HMAC-signed webhook channels — with retry and auto-disable
- • Scheduled digest summaries
- • Native desktop notifications on macOS, Windows, and Linux endpoints
-
Maintenance
- • Maintenance windows silence alerts during planned work
- • Scheduled per org, alongside escalation policies and digests
-
Process Watches
- • Must-run rules alert the moment a critical process stops
- • Must-not-run rules alert when banned software appears
- • Alerts raise and clear themselves automatically
-
Certificates (Pro)
- • TLS certificate and domain expiry watching for any hostname — checked daily
- • Alerts fire when under 30 days remain
- • Days-left, expiry date, and issuer tracked per host with custom labels
-
App Network
- • Per-application network telemetry: bytes, latency, and connection counts
- • TCP retransmits surfaced as an early signal of connection trouble
- • Sits alongside per-process memory for full per-app context
-
Assets
- • Hardware and software inventory per device, including every fixed and attached volume
- • Warranty / AppleCare tracking (Pro) via provider lookup, estimate, or manual entry
- • IP-based geolocation to help recover lost or stolen devices
-
Fleet Software (Pro)
- • Search any installed software across the entire fleet by name
- • See exactly which devices have it and which versions they run
-
Compliance (Pro)
- • Flag any device running banned software
- • Flag devices running an app below a minimum version
- • Flag in-scope devices missing required apps — AV/EDR, backup clients, and the like
-
Vulnerabilities
- • Installed software matched against CVE rules into per-device, severity-ranked findings
- • NVD (NIST) auto-sync every 6 hours converts CPE version ranges into org-scoped findings
- • Summary tiles: findings, affected devices, and critical / high / medium counts
-
Mailboxes (Pro)
- • Per-org mailbox health monitoring
- • Toggle per tenant; agents pick up changes on their next cycle