9 days ago
9 days ago
Bluetrait MSP
35
BluetraitIO Features
BluetraiIO (Also known as Bluetrait MSP) is our integrated RMM + PSA platform: remote monitoring and management tool built on the Bluetrait platform (also including ticketing, billing, CRM, timesheets, knowledge base and password vault).
At a Glance
| Capability | BluetraitIO |
|---|---|
| Endpoint monitoring & alerting | ✅ CPU/RAM/disk/uptime graphs, sustained-threshold alert gating, Windows Event Log rules, monitored services with auto-restart, sensors, battery health, screenshots |
| OS patch management | ✅ Per-template schedules, categories, KB exclusions, patch-on-startup, auto-restart, full patch history |
| 3rd-party app patching | ✅ winget-based app repo with per-company approvals, auto-update, pinned versions, self-service, own schedule + history |
| Scripting & automation | ✅ 30+ typed tasks, PowerShell/command/process execution, script variables, jobs (task sequences), result capture to custom fields, scheduled jobs on templates and tags |
| Remote access | ➖ Integrations: ScreenConnect/ConnectWise Control and Splashtop deep-links; btssh SSH pins + connection logging |
| Network performance monitoring | ✅ Continuous MTR-style path monitoring (loss/latency/jitter, per-hop, route-change detection), ISP performance report |
| SNMP & agentless monitoring | ✅ SNMP templates (printers, UPS, WAN traffic), SNMP-only devices, agentless SNMP/Ping/HTTP monitors via an agent probe |
| IPAM | ✅ Subnets, allocations, overlap control, customer-facing "My Allocations" view |
| Hypervisor management | ✅ Proxmox VE: host/guest/storage inventory, guest start/stop/restart, backup status, guest-state alerts |
| Security | ✅ BitLocker recovery key escrow (audited reveal), AV inventory + managed AV telemetry, Webroot and Bitdefender deployment, agent tamper protection, Entra/Azure AD + MDM enrolment status, local account management |
| Hardware asset management | ✅ Full hardware inventory, EDID-level monitor inventory (incl. Dell service tags), printers, Dell warranty API, purchase/warranty tracking, Excel device inventory report |
| Dynamic grouping & onboarding | ✅ Tag rules over ~30 device fields, MSP rules that auto-assign company/template/tags or run jobs on new agents (incl. install tokens) |
| End-user self-service | ✅ Guest portal (approved app installs, whitelisted jobs, live status), custom tray menus |
| PSA (tickets, billing, CRM) | ✅ Ticketing with alert→ticket automation, invoices/quotes + Xero, CRM, timesheets, KB, forms, reports, password vault with OTP |
| AI features | ✅ AI Checkup per device, AI ticket assistant enriched with device + alert context |
| API & extensibility | ✅ REST API, webhooks, MCP server (AI-agent access to fleet data, tasks, vault), plugin architecture |
| Platform support | ✅ Windows, macOS, Linux (incl. Proxmox hosts), SNMP-only devices |
Where Bluetrait MSP Stands Out
- Network performance monitoring - continuous per-path loss/latency/jitter with hop ladders and an ISP performance report.
- Proxmox VE hypervisor management - inventory plus guest power control from the agent view.
- IPAM - managed subnets and allocations with a customer-facing view.
- MCP server - AI agents can query fleet health, run tasks and manage the password vault, all permission-gated.
- Deep hardware inventory - EDID-level monitor data, Dell warranty integration, replacement-planning Excel report.
- Onboarding automation - MSP rules assign company/template/tags or run jobs the moment a new agent appears.
Full Bluetrait MSP Feature List
Remote Monitoring & Alerting
- Agent check-ins with CPU, RAM, disk, disk queue, load average, uptime and clock-drift graphs
- Per-device dashboard with 20+ tabs (performance, storage, network, security, users, tasks, event log and more)
- Fleet Health dashboard: check-in freshness, disk free %, AV state, missing patches, active alerts per agent
- Alert types: CPU, memory, drive space (per mount), device offline, Windows Event Log match, service offline/missing, AV threat found, UPS, hypervisor guest state, network path degradation, agent uninstall, new program/service
- Sustained-threshold gating - require a breach to persist N minutes before a ticket is raised
- Alerts auto-create tickets (per-alert department/priority) and can auto-run a remediation job
- Windows Event Log monitoring with per-template match rules
- Monitored services with automatic restart on failure
- Hardware sensors (temperatures), battery health, optional screenshots, geolocation with maps
- Connected-time/user session history, agent and tag change audit trails, deleted-agent recovery
- AI Checkup: on-demand AI analysis of a device's collected data
Remote Access & Control
- ScreenConnect / ConnectWise Control and Splashtop one-click launch per agent
- btssh integration: per-user SSH credential pins from the password vault, remote connection attempt logging (SSH/RDP/WinRM)
- Run commands, PowerShell scripts (with input variables) and processes (as SYSTEM or current user)
- Immediate or scheduled reboot (server or machine time)
- Send messages to logged-on users with acknowledgement tracking
- Start/stop/restart services remotely
Patch & Software Management
- Windows patch management: per-template schedules, install categories, KB exclusions, patch-on-startup, auto-restart
- Fleet-wide patch catalog and complete per-agent patch history; ad-hoc patch pushes
- 3rd-party app management (winget): catalog, per-company approvals with auto-update / self-service / pinned versions, own patch schedule and history
- Software deployment: download from URL or file repository, MSI/MSU install, job import wizard
- Software inventory: programs, processes, services, operating systems - fleet-wide catalogs with drill-down; remote uninstall
- One-click or bulk agent self-upgrade (Windows, macOS, Linux)
Networking
- Network Performance Monitoring: continuous traceroute+ping per target with loss, latency, jitter, per-hop timing and route-change detection; template-driven with tunable retention
- ISP Performance report - loss/latency/jitter aggregated by ISP, ranked worst-first
- Network discovery: subnet sweeps with DNS, MAC vendor and open-port/service detection
- Agentless monitors via any agent: SNMP v1/2c/3, Ping and HTTP checks with warning/critical thresholds
- SNMP templates for printers (page counts, toner levels), UPS (voltage, load, runtime, on-battery alerts) and WAN interface traffic graphs
- Network inventory: interfaces, addresses, active connections, listening ports
- IPAM: subnets and allocations with CIDR alignment, overlap control, company ownership and a customer "My Allocations" view
- Auto-discovered customer networks keyed on gateway MAC / network / WAN IP
Security
- BitLocker disk encryption status and recovery key escrow with audited key reveal and key history
- Antivirus inventory plus managed AV telemetry (threats, scans, protection state)
- Webroot deployment and on-demand scans (Bitdefender available via a separate plugin)
- Agent tamper protection: uninstall alerts and MSI uninstall password
- Entra / Azure AD join and MDM enrolment status per device
- Local account management: create users, inventory of local users/groups/membership, enforced password complexity
- Password vault linkage: vault entries linked to agents, OTP/TOTP support
- Company-scoped technician permissions and limited-task access for end users
Automation
- Task library of 30+ typed tasks across software deployment, commands, accounts, networking, services and user interaction
- Jobs: ordered task sequences run against one agent or bulk selections
- Scheduled jobs on templates and tags, in server or machine time, with offline catch-up
- Script variables (WAN/LAN IP, template name, custom fields) injected into scripts; task output captured to custom fields
- Tags with rule-based dynamic membership over ~30 device fields
- MSP rules: auto-assign company, template, tags or run a job when a new agent enrols (install-token aware)
- Agent templates (policies) controlling every monitoring, patching and alerting behaviour; clonable
- Bulk actions: apply template, assign company, tag, run job, upgrade, CSV export
- Guest self-service portal: end users install approved apps and run whitelisted jobs with live status
- Custom tray menus with per-template branding and tokenised links
Hardware Assets & Reporting
- Full hardware inventory: model, serial, BIOS, CPU, RAM, GPUs, storage, OS install date, current user
- Monitor inventory at EDID level: serial, manufacture date, resolution, physical size, Dell service tags, driving adapter
- Printer inventory (drivers, ports, status)
- Dell TechDirect warranty lookups with caching; purchase date and warranty expiry tracking
- Device Inventory Report: 6-sheet Excel workbook per company including a "Needs Replacing" sheet
Virtualization
- Proxmox VE host inventory: version, cluster, quorum, node counts
- Guest VMs and LXC containers: status, resources, uptime, last backup and backup status
- Guest start / stop / restart from the console; fleet-wide Virtual Machines view; guest-state alerting
- Storage pool inventory
Platform & Agent Support
- Windows (richest feature set, MSI installer built on demand)
- macOS (10.15+) with self-upgrade
- Linux agents with self-upgrade
- Proxmox VE hosts (Linux agent + hypervisor collection)
- SNMP-only devices monitored through a nearby agent
Integrations & API
- REST API (agent + authenticated endpoints) and webhooks
- MCP server: permission-gated AI-agent tools for agents, fleet health, network health, app repo, tasks and vault pins
- Ticket ↔ device linkage; AI ticket assistant enriched with the submitter's devices and live alerts
- ScreenConnect, Splashtop, Webroot, Dell warranty, Entra/Azure AD
PSA Platform (Bluetrait core)
- Ticketing/helpdesk with departments, priorities and automation
- Billing: invoices, quotes, products, Xero integration
- CRM: companies, domains, projects, newsletters
- Timesheets, expenses and leave; reports and forms builder
- Knowledge base (this portal), password vault with OTP
- Auth: AD/LDAP, Entra/OIDC, Google, 2FA
Authentication & Identity
BluetraitIO supports a wide range of sign-in methods, all feeding a single permission model. Users are assigned an authentication backend per account, so local, directory and cloud identities can coexist on the same install.
Login Methods
- Local accounts
- Active Directory - LDAP/LDAPS/StartTLS options, encrypted service credentials, automatic account provisioning, and AD group → Bluetrait permission group mapping with priority ordering. Name, email and phone are re-synced from AD on every login.
- LDAP - generic LDAP bind authentication with auto-provisioning to a default group.
- Microsoft Entra ID (Azure AD) - OpenID Connect against the v2.0 endpoint using a stored Microsoft Graph connection. Single-tenant (with issuer and tenant validation) or multi-tenant mode, automatic matching by Entra object ID or email, optional auto-provisioning, and self-service account linking.
- Google and Facebook sign-in - OAuth-based login with account linking.
- Passkeys
Two-Factor Authentication
- TOTP (authenticator app) with QR code enrolment.
- 2FA can be mandated for all users or only for selected permission groups.
Session & Access Controls
- Per-permission-group login IP restrictions: CIDR-based allow-lists and deny-lists, with denied attempts logged.
- Task-based permissions.
- User impersonation for admins.
API & Integration Authentication
- MCP / OAuth 2.1 - a built-in authorization server with audience binding to the MCP endpoint, scope enforcement, token revocation, and rate limiting on client registration, MCP calls and passkey logins. Every MCP tool call runs under the token owner's normal permissions.
Audit Logging & Accountability
Security-relevant actions in BluetraitIO leaves a record with who, when and from where.
Central Event Log
- A single searchable event log.
API & Integration Logs
- API request logs - opt-in per API key: action, IP, request and response bodies, response code, success flag and timing, with passwords, tokens and secrets automatically redacted at any depth.
- Webhooks as an audit feed - login succeeded/failed/account-locked/logged-out (and ticket, user, file, email, cron events) can be streamed to external systems, e.g. a SIEM.
MSP Plugin Audit Trails
- Agent change history
- Task definition changelog
- Tag history
- Task execution history
- BitLocker key escrow auditing
- Remote connection log
- Agent connection records