How TechBomby runs managed IT
Most small businesses get IT one of two ways: call someone when something breaks, or pay enterprise prices for enterprise service they don't need. We do something different — the same RMM and security tools enterprise MSPs run, packaged + priced for the 5-50 employee business.
What our RMM agent actually collects
Our monitoring agent is designed to watch endpoint health + security state — not staff activity. Here's exactly what's collected and what's not. If anything changes, we tell you in writing first.
What we collect
- CPU + memory usage trends
- Disk space + SMART drive-health status
- Operating system version + patch level
- Antivirus / EDR state + firewall status
- Installed application names + versions (inventory, not contents)
- Network connection summary (which networks endpoints are on)
- Security event logs (Compliance + Security; via Wazuh)
What we don't collect
- File contents on endpoints
- Screen captures or screenshots
- Keystrokes / staff productivity surveillance
- Email content, message bodies, attachments
- Browsing history beyond security-relevant DNS queries
- Audio / video from device cameras + microphones
The 30-day calibration period
Every new customer gets a 30-day calibration period. The reason: your finance laptop running QuickBooks 50 hours a week is different from your lobby tablet that comes out for visitor sign-in. Applying identical thresholds across all endpoints means alerting constantly on false positives.
During the first 30 days we observe each endpoint's actual usage pattern — when it comes online, typical resource profile, network it lives on. End of period: we tune alert thresholds per endpoint. From day 31 onward, alerts represent real signal — not noise.
Hire a new employee? Replace a server? Open a new office? Tell us. We re-calibrate that endpoint or location without restarting the whole period.
How we classify endpoints
After calibration, each endpoint falls into one of five categories. Classification determines polling cadence + how we interpret silence.
Always-on
Servers, NAS, smart-home hubs, security appliances. Polled continuously; missed check-ins are immediate alerts.
Production
Daily-use staff endpoints — workstations, primary laptops. Polled during business hours; off-hours absence is normal.
Mobile
Field laptops, traveling devices, mobile phones in inventory. Tagged with mobile patterns so airport Wi-Fi doesn't fire alerts.
Backup/secondary
Disaster-recovery servers, spare workstations, training endpoints. Polled when present; long absences expected.
Seasonal
Tax-season laptops, summer-only operations gear, household snowbird devices. Tagged with active windows.
Classification governs monitoring methodology, not pricing. Backup/secondary endpoints cost the same per-month as production ones — they just aren't constantly polled.
What you can expect each month
- Day 1. Monthly per-location health + security report emailed. Includes endpoint count + uptime, security update compliance, AV/EDR state, prior-month incidents, recommendations.
- Throughout. Continuous RMM monitoring. Patches deployed as endpoints come online. Tickets triaged in real time. DNS filtering + EDR alerts handled.
- On demand. Helpdesk for your staff. Standard tickets get same-evening or next-evening response. Critical issues get priority within our working window.
- Quarterly (Managed / Co-Manage / Compliance). Stack review. We surface what to budget for the next quarter, what to retire, what to upgrade.
- Annually (Secure). Third-party penetration test + remediation roadmap. Audit-evidence package for HIPAA / PCI / SOC2 customers.
What we don't do
Honest scope: we'd rather tell you up front what falls outside the service than promise things we can't deliver.
- On-site work outside Polk County and adjacent (unless on a Project engagement)
- Hardware replacement parts (we recommend, you purchase; we install if on-site)
- Warranty mediation with manufacturers (Apple, Dell, Cisco, etc.) — we coach you through it
- App-specific training for your staff (QuickBooks training, Photoshop classes, etc.)
- Structured wiring beyond patch panels (call a low-voltage electrician)
- Account recovery for accounts we did not set up — we coach, we don't impersonate
- Custom software development
When something is outside our scope, we say so and recommend who to call. Most of the time we already have a name for you.
How signup works
- 01. A paid assessment of your setup. We document what you have, identify gaps, and give you a written scope. The fee credits toward any work you approve.
- 02. Service agreement + first-month invoice through Stripe. Both reviewable before you commit.
- 03. 60-90 minute setup session (longer for multi-site). Install RMM agents, document asset inventory, configure backup verification.
- 04. You see exactly what we have access to + can revoke any agent at any time.
- 05. 30-day calibration period begins. We learn your usage patterns + tune thresholds. Reports start at month 1.
FAQ
What exactly does the RMM agent collect from our endpoints?
Health metrics: CPU + memory usage, disk space + SMART status, OS version + patch state, antivirus status, installed application inventory (names + versions, not contents), network connection summary. We do NOT collect file contents, screen captures, keystrokes, email bodies, or browsing history.
Can you see our screens?
Not without explicit approval each time. Remote-support tooling (MeshCentral) is permission-gated — every session requires the user to click "Allow" on their device. No silent screen access.
Why a 30-day calibration period?
Your finance laptop running QuickBooks 50 hours a week is different from the lobby tablet that comes out for visitor sign-in. During the first 30 days we observe how each device is actually used and tune thresholds. From day 31 alerts represent real signal — not noise.
How do you handle devices that travel a lot?
The agent reports back over any internet connection. We tag mobile-pattern devices so joining a new airport Wi-Fi or hotel network isn't flagged as an incident.
What about field offices or multi-site businesses?
Each location gets its own Zabbix monitoring + reporting. You can view a single dashboard across all sites OR get separate reports per location. Same approach for backup verification + security stack.
What does a typical month look like?
Day 1 of each month: per-location health + security report emailed. Throughout the month: continuous monitoring + alerts, security updates installed as devices come online, tickets triaged in real time. Quarterly: stack review call + written recommendations. Annually (Compliance + Security, in development): pen test + audit-evidence package.
Will your agent slow our endpoints down?
It shouldn't. TacticalRMM agent is single-digit-percent CPU + a few hundred MB RAM. If a specific endpoint runs slower after install, tell us — that's diagnostic information we want.
What happens during onboarding?
Five-step flow: (1) Paid assessment of your environment (fee credited toward work you approve). (2) Service agreement + first month's invoice through Stripe. (3) 60-90 minute setup session — install agents, document asset inventory, configure backup verification. (4) You see exactly what we have access to + can revoke any agent at any time. (5) Day 31 the calibration period ends and you get your first full monthly report.
How do you handle our existing in-house IT person?
Co-Manage tier is the play. They keep the customer-facing IT role; we cover the layers they don't want to babysit (after-hours, security stack, backups, tool licensing). Quarterly we meet with them on strategy. We never bypass them on customer comms unless they explicitly ask us to.
Can you support our specific vendor software?
For mainstream apps (M365, Google Workspace, QuickBooks, Salesforce, Adobe, common EHRs, common legal practice mgmt) — yes. For very niche vertical software, we vendor-liaise rather than support directly, and we're honest about the line.
What's NOT in scope?
On-site work outside Polk County and adjacent (unless Project engagement). Hardware replacement parts. Warranty mediation. App-specific training. Structured wiring beyond patch panels. Account recovery for accounts we did not set up.
Can you add or remove endpoints mid-month?
Yes — within reason. Net-new + net-deletions reconcile on the next monthly invoice. We don't play games with proration; if a customer churns mid-month we don't bill the rest.
What about backups + disaster recovery?
Backup verification is included in Manage + Co-Manage + Secure. We don't SELL backup software — we verify whatever you're using (Veeam, Datto, Acronis, etc.) is actually restorable. Project engagements include DR plan documentation.
Still have questions?
A paid assessment answers most of them — clear scope, straight pricing, fee credited toward any work you approve.
hello@techbomby.com · (863) 320-1236
Evening & weekend appointments