9 days ago

9 days ago

Bluetrait MSP

35

BluetraitIO Features

BluetraiIO (Also known as Bluetrait MSP) is our integrated RMM + PSA platform: remote monitoring and management tool built on the Bluetrait platform (also including ticketing, billing, CRM, timesheets, knowledge base and password vault).

At a Glance

Capability BluetraitIO
Endpoint monitoring & alerting ✅ CPU/RAM/disk/uptime graphs, sustained-threshold alert gating, Windows Event Log rules, monitored services with auto-restart, sensors, battery health, screenshots
OS patch management ✅ Per-template schedules, categories, KB exclusions, patch-on-startup, auto-restart, full patch history
3rd-party app patching ✅ winget-based app repo with per-company approvals, auto-update, pinned versions, self-service, own schedule + history
Scripting & automation ✅ 30+ typed tasks, PowerShell/command/process execution, script variables, jobs (task sequences), result capture to custom fields, scheduled jobs on templates and tags
Remote access ➖ Integrations: ScreenConnect/ConnectWise Control and Splashtop deep-links; btssh SSH pins + connection logging
Network performance monitoring ✅ Continuous MTR-style path monitoring (loss/latency/jitter, per-hop, route-change detection), ISP performance report
SNMP & agentless monitoring ✅ SNMP templates (printers, UPS, WAN traffic), SNMP-only devices, agentless SNMP/Ping/HTTP monitors via an agent probe
IPAM ✅ Subnets, allocations, overlap control, customer-facing "My Allocations" view
Hypervisor management ✅ Proxmox VE: host/guest/storage inventory, guest start/stop/restart, backup status, guest-state alerts
Security ✅ BitLocker recovery key escrow (audited reveal), AV inventory + managed AV telemetry, Webroot and Bitdefender deployment, agent tamper protection, Entra/Azure AD + MDM enrolment status, local account management
Hardware asset management ✅ Full hardware inventory, EDID-level monitor inventory (incl. Dell service tags), printers, Dell warranty API, purchase/warranty tracking, Excel device inventory report
Dynamic grouping & onboarding ✅ Tag rules over ~30 device fields, MSP rules that auto-assign company/template/tags or run jobs on new agents (incl. install tokens)
End-user self-service ✅ Guest portal (approved app installs, whitelisted jobs, live status), custom tray menus
PSA (tickets, billing, CRM) ✅ Ticketing with alert→ticket automation, invoices/quotes + Xero, CRM, timesheets, KB, forms, reports, password vault with OTP
AI features ✅ AI Checkup per device, AI ticket assistant enriched with device + alert context
API & extensibility ✅ REST API, webhooks, MCP server (AI-agent access to fleet data, tasks, vault), plugin architecture
Platform support ✅ Windows, macOS, Linux (incl. Proxmox hosts), SNMP-only devices

Where Bluetrait MSP Stands Out

  • Network performance monitoring - continuous per-path loss/latency/jitter with hop ladders and an ISP performance report.
  • Proxmox VE hypervisor management - inventory plus guest power control from the agent view.
  • IPAM - managed subnets and allocations with a customer-facing view.
  • MCP server - AI agents can query fleet health, run tasks and manage the password vault, all permission-gated.
  • Deep hardware inventory - EDID-level monitor data, Dell warranty integration, replacement-planning Excel report.
  • Onboarding automation - MSP rules assign company/template/tags or run jobs the moment a new agent appears.

Full Bluetrait MSP Feature List

Remote Monitoring & Alerting

  • Agent check-ins with CPU, RAM, disk, disk queue, load average, uptime and clock-drift graphs
  • Per-device dashboard with 20+ tabs (performance, storage, network, security, users, tasks, event log and more)
  • Fleet Health dashboard: check-in freshness, disk free %, AV state, missing patches, active alerts per agent
  • Alert types: CPU, memory, drive space (per mount), device offline, Windows Event Log match, service offline/missing, AV threat found, UPS, hypervisor guest state, network path degradation, agent uninstall, new program/service
  • Sustained-threshold gating - require a breach to persist N minutes before a ticket is raised
  • Alerts auto-create tickets (per-alert department/priority) and can auto-run a remediation job
  • Windows Event Log monitoring with per-template match rules
  • Monitored services with automatic restart on failure
  • Hardware sensors (temperatures), battery health, optional screenshots, geolocation with maps
  • Connected-time/user session history, agent and tag change audit trails, deleted-agent recovery
  • AI Checkup: on-demand AI analysis of a device's collected data

Remote Access & Control

  • ScreenConnect / ConnectWise Control and Splashtop one-click launch per agent
  • btssh integration: per-user SSH credential pins from the password vault, remote connection attempt logging (SSH/RDP/WinRM)
  • Run commands, PowerShell scripts (with input variables) and processes (as SYSTEM or current user)
  • Immediate or scheduled reboot (server or machine time)
  • Send messages to logged-on users with acknowledgement tracking
  • Start/stop/restart services remotely

Patch & Software Management

  • Windows patch management: per-template schedules, install categories, KB exclusions, patch-on-startup, auto-restart
  • Fleet-wide patch catalog and complete per-agent patch history; ad-hoc patch pushes
  • 3rd-party app management (winget): catalog, per-company approvals with auto-update / self-service / pinned versions, own patch schedule and history
  • Software deployment: download from URL or file repository, MSI/MSU install, job import wizard
  • Software inventory: programs, processes, services, operating systems - fleet-wide catalogs with drill-down; remote uninstall
  • One-click or bulk agent self-upgrade (Windows, macOS, Linux)

Networking

  • Network Performance Monitoring: continuous traceroute+ping per target with loss, latency, jitter, per-hop timing and route-change detection; template-driven with tunable retention
  • ISP Performance report - loss/latency/jitter aggregated by ISP, ranked worst-first
  • Network discovery: subnet sweeps with DNS, MAC vendor and open-port/service detection
  • Agentless monitors via any agent: SNMP v1/2c/3, Ping and HTTP checks with warning/critical thresholds
  • SNMP templates for printers (page counts, toner levels), UPS (voltage, load, runtime, on-battery alerts) and WAN interface traffic graphs
  • Network inventory: interfaces, addresses, active connections, listening ports
  • IPAM: subnets and allocations with CIDR alignment, overlap control, company ownership and a customer "My Allocations" view
  • Auto-discovered customer networks keyed on gateway MAC / network / WAN IP

Security

  • BitLocker disk encryption status and recovery key escrow with audited key reveal and key history
  • Antivirus inventory plus managed AV telemetry (threats, scans, protection state)
  • Webroot deployment and on-demand scans (Bitdefender available via a separate plugin)
  • Agent tamper protection: uninstall alerts and MSI uninstall password
  • Entra / Azure AD join and MDM enrolment status per device
  • Local account management: create users, inventory of local users/groups/membership, enforced password complexity
  • Password vault linkage: vault entries linked to agents, OTP/TOTP support
  • Company-scoped technician permissions and limited-task access for end users

Automation

  • Task library of 30+ typed tasks across software deployment, commands, accounts, networking, services and user interaction
  • Jobs: ordered task sequences run against one agent or bulk selections
  • Scheduled jobs on templates and tags, in server or machine time, with offline catch-up
  • Script variables (WAN/LAN IP, template name, custom fields) injected into scripts; task output captured to custom fields
  • Tags with rule-based dynamic membership over ~30 device fields
  • MSP rules: auto-assign company, template, tags or run a job when a new agent enrols (install-token aware)
  • Agent templates (policies) controlling every monitoring, patching and alerting behaviour; clonable
  • Bulk actions: apply template, assign company, tag, run job, upgrade, CSV export
  • Guest self-service portal: end users install approved apps and run whitelisted jobs with live status
  • Custom tray menus with per-template branding and tokenised links

Hardware Assets & Reporting

  • Full hardware inventory: model, serial, BIOS, CPU, RAM, GPUs, storage, OS install date, current user
  • Monitor inventory at EDID level: serial, manufacture date, resolution, physical size, Dell service tags, driving adapter
  • Printer inventory (drivers, ports, status)
  • Dell TechDirect warranty lookups with caching; purchase date and warranty expiry tracking
  • Device Inventory Report: 6-sheet Excel workbook per company including a "Needs Replacing" sheet

Virtualization

  • Proxmox VE host inventory: version, cluster, quorum, node counts
  • Guest VMs and LXC containers: status, resources, uptime, last backup and backup status
  • Guest start / stop / restart from the console; fleet-wide Virtual Machines view; guest-state alerting
  • Storage pool inventory

Platform & Agent Support

  • Windows (richest feature set, MSI installer built on demand)
  • macOS (10.15+) with self-upgrade
  • Linux agents with self-upgrade
  • Proxmox VE hosts (Linux agent + hypervisor collection)
  • SNMP-only devices monitored through a nearby agent

Integrations & API

  • REST API (agent + authenticated endpoints) and webhooks
  • MCP server: permission-gated AI-agent tools for agents, fleet health, network health, app repo, tasks and vault pins
  • Ticket ↔ device linkage; AI ticket assistant enriched with the submitter's devices and live alerts
  • ScreenConnect, Splashtop, Webroot, Dell warranty, Entra/Azure AD

PSA Platform (Bluetrait core)

  • Ticketing/helpdesk with departments, priorities and automation
  • Billing: invoices, quotes, products, Xero integration
  • CRM: companies, domains, projects, newsletters
  • Timesheets, expenses and leave; reports and forms builder
  • Knowledge base (this portal), password vault with OTP
  • Auth: AD/LDAP, Entra/OIDC, Google, 2FA

Authentication & Identity

BluetraitIO supports a wide range of sign-in methods, all feeding a single permission model. Users are assigned an authentication backend per account, so local, directory and cloud identities can coexist on the same install.

Login Methods

  • Local accounts
  • Active Directory - LDAP/LDAPS/StartTLS options, encrypted service credentials, automatic account provisioning, and AD group → Bluetrait permission group mapping with priority ordering. Name, email and phone are re-synced from AD on every login.
  • LDAP - generic LDAP bind authentication with auto-provisioning to a default group.
  • Microsoft Entra ID (Azure AD) - OpenID Connect against the v2.0 endpoint using a stored Microsoft Graph connection. Single-tenant (with issuer and tenant validation) or multi-tenant mode, automatic matching by Entra object ID or email, optional auto-provisioning, and self-service account linking.
  • Google and Facebook sign-in - OAuth-based login with account linking.
  • Passkeys

Two-Factor Authentication

  • TOTP (authenticator app) with QR code enrolment.
  • 2FA can be mandated for all users or only for selected permission groups.

Session & Access Controls

  • Per-permission-group login IP restrictions: CIDR-based allow-lists and deny-lists, with denied attempts logged.
  • Task-based permissions.
  • User impersonation for admins.

API & Integration Authentication

  • MCP / OAuth 2.1 - a built-in authorization server with audience binding to the MCP endpoint, scope enforcement, token revocation, and rate limiting on client registration, MCP calls and passkey logins. Every MCP tool call runs under the token owner's normal permissions.

Audit Logging & Accountability

Security-relevant actions in BluetraitIO leaves a record with who, when and from where.

Central Event Log

  • A single searchable event log.

API & Integration Logs

  • API request logs - opt-in per API key: action, IP, request and response bodies, response code, success flag and timing, with passwords, tokens and secrets automatically redacted at any depth.
  • Webhooks as an audit feed - login succeeded/failed/account-locked/logged-out (and ticket, user, file, email, cron events) can be streamed to external systems, e.g. a SIEM.

MSP Plugin Audit Trails

  • Agent change history
  • Task definition changelog
  • Tag history
  • Task execution history 
  • BitLocker key escrow auditing
  • Remote connection log
  • Agent connection records