Isolation by default
A workspace is a hard boundary. Operators, clients, sites, devices, and sessions belong to a tenant and do not leak across one.
Security & trust
CoreTech RMM can reboot machines, push software, run remote sessions, and deploy operating systems. Capabilities like that are only safe when isolation, least privilege, approval, and evidence are part of the data model — not settings someone might forget to turn on.
Principles
A workspace is a hard boundary. Operators, clients, sites, devices, and sessions belong to a tenant and do not leak across one.
Roles scope what an operator can see and do down to client and site level, so technicians get exactly the reach a job needs.
New devices and elevated actions can pass through an approval gate before they ever touch production.
Remote sessions, endpoint actions, and deployments are recorded as history the next operator — or an auditor — can read.
Access & identity
Access is modeled, not improvised. Tenant, client, site, and role boundaries are first-class concepts, and people enter through scoped invitations rather than shared logins.
Devices & transport
Agents identify themselves cryptographically and devices are admitted deliberately. A machine you have not approved does not silently become something you operate.
Auditability
Audit is not a separate logging product bolted on later. Operational actions are written as history at the point they occur, so accountability survives staff turnover and post-incident review.
Operational safety
Remote support, reboot, patching, and deployment surface the target, its client, and its policy before the action runs.
Sessions that need elevated rights show it, so technicians and reviewers can tell routine work from privileged work.
Failed updates and jobs are not swept under a green dashboard — they stay in the queue until they are resolved.
Compliance posture
We would rather tell you the truth than imply a badge we have not earned. Here is the current state of our formal posture.
See it in context
We will show isolation, approval, remote session accountability, and audit evidence using the same workspace your technicians would use day to day.