AI-assisted monitoring for IT professionals

Alerts that arrive with a diagnosis. Fixes that wait for your approval.

Servers, desktops, firewalls, routers, across one office or a dozen customers. BE Hub watches them all, and when something goes wrong BE AI investigates, tells your team what it found, and proposes the fix. Someone approves. Nothing runs without a named approval.

No NOC, no night shift, no inbound ports. One 8 MB agent per machine.

BE Hub dashboard: 45 of 46 machines online, three needing attention, two proposals awaiting approval, fleet chart and BE AI activity
≈ 30 stypical, from alert to a written diagnosis
Every changeapproved by a named person, by design
5 OS familiesservers, desktops, firewalls and routers
from US$3 / machineper month, no minimum, BE AI included · US$5 to US$3 as the fleet grows
how it works

An investigator that reads everything and touches nothing.

01

The agent watches

A heartbeat every five minutes, and an event the moment a disk fills, a check fails or a machine reboots. Outbound only, so it works behind any router.

02

BE AI investigates

It reads the history, then asks the machine read-only questions: diagnostics, processes, services, logs, checks. It writes a plain-English conclusion with a confidence level.

03

It proposes, you approve

A change arrives as a proposal with the exact command and the reason. Approve, reject, or ask a follow-up in the same thread. The console works on a phone browser, so it can happen from anywhere.

04

Verified and recorded

The result comes back in plain language. Ask BE AI to verify the effect. Every question, call and approval is in the audit trail with a name on it.

Follow one incident from alert to fix →

Discuss on srv-books: the technician asks BE AI to list old backups first, the read-only listing runs with approval, and the delete is proposed
the console

One screen for the whole fleet, one screen for the machine in front of you.

Cropped from the real console on a fictional fleet; every screen below is the product as it ships.

Fleet list grouped by role with CPU, memory and disk per machine

Fleet. Grouped by your tags, worst first. CPU, memory and a disk sparkline on every row, a check column that says ok or how many are failing, and firewalls next to the servers they protect.

One machine's overview: tiles for CPU, memory, disk, network, uptime and checks, 24-hour sparklines, and its LAN, DNS and external addresses

Machine. Everything about one machine on one screen: live tiles, a day of CPU and disk, when the disk will be full, its addresses, then its alerts, notes and BE AI history below. Discuss, control and watch are one click away.

The approval queue: proposals awaiting approval with the exact command, the reason, and approve or reject buttons

Approvals. What BE AI wants to run, as the exact command with a reason. Approve executes it and records your name. Reject records that too. Nothing in this column has run.

Three alerts, each with the BE AI assessment written underneath

Alerts. One alert per machine and problem, with BE AI's assessment under it before anyone is woken. Rules decide who gets an email, a text, a phone call or a webhook, per customer, per severity.

Trend charts for one machine: CPU and memory, worst-volume disk, application response time

Trends. Every heartbeat for a day, hourly rollups for two years, sized so a fleet of hundreds stays quick to draw. CPU, memory, disk, application checks, ping and network per machine, plus a fleet chart on the dashboard.

Company table: machines online, proposals awaiting, failing checks, BE AI runs and cost per customer

Companies. Each customer is its own company with an install link, its own sign-ins and its own usage. Look after one office or twelve from the same place. Nobody sees anyone else's machines.

what you get

Monitoring that does the first hour of every ticket for you.

Not a script engine on the endpoint and not a patch tool. Watching, alerting, custom checks, releases, and an operator that stays inside a fixed set of tools.

Alerts that reach a person

Offline, disk, failing check, reboot, degraded ZFS pool. Email, SMS, phone call or webhook, with grace periods so a planned reboot is not a 2 am page.

Custom checks, written in a sentence

"Alert me if the S: drive is not mapped for reception." BE AI turns it into a check, you approve, the agent runs it every minute.

Nightly pass on every machine

BE AI reviews each machine once a day and only proposes when something needs a decision. Quiet machines cost you nothing.

Firewalls and routers included

OPNsense, pfSense, Teltonika 4G routers and TrueNAS are machines like any other: services, logs, cellular signal, pool health.

Hosted, on-premise, or your own cloud

The hub is one container with one data volume. Let Binary Elements host it, run it on a box in your own rack, or in the cloud account you already pay for.

Remote control, one click

Watch or take control of a Windows machine from the console, over the agent's outbound connection. No inbound port, nothing to install on your side, every session on the record. On by default per customer; switch it off for the ones who want it off.

run it where you like

Hosted by us, on your premises, or in your own cloud.

Same product, your data where you want it. One container, one volume, one outbound call to the AI API. Agents only ever need to reach your hub. Hosting options →

hosted

Binary Elements runs it

Sign in and start enrolling. Hosted in Sydney, Australia.

on-premise

A box in your rack

Any host that runs a container.

your cloud

Your cloud account

A small VM serves hundreds of machines.

security model

The AI can read. Only a person can write.

BE AI never gets a shell. It works through a fixed, allow-listed set of tools, and every mutating tool sits behind a human approval on the hub. Whether a machine allows shell commands at all is decided in its own config file, which the hub cannot change. Everything a machine reports is treated as untrusted text. Read the security model →

  • outbound-only agent, no inbound ports, no VPN
  • Ed25519-signed updates, key kept offline
  • read tools automatic, write tools approved
  • per-company isolation enforced on every request
  • full audit trail: who asked, what ran, what came back
preventative maintenance

Most outages announce themselves weeks ahead. BE Hub reads the announcement.

A nightly pass over every machine, disks with a date they will be full, services that keep restarting, machines behind on releases, patch state, checks that drift. The things a good technician would look at every morning if there were time. How the nightly pass works →

  • nightly review of every included machine, only speaks when something needs a decision
  • "full in 12 days" on every disk from a week of history
  • patch and service health recipes on request or on schedule
  • checks that watch for drift: mapped drives, printers, VPN peers
where the investigator made the difference

The same alert, with and without BE AI.

Disk full at 3 am

Threshold alert says 96%. BE Hub says 231 GB of old backups on a 500 GB volume, growing 0.9% a day, and files a listing to approve. The case →

Site down, or box down?

Uptime check says the firewall is unreachable. BE Hub says the 4G router at the same site still answers, so it is the firewall, not the carrier. The case →

The slow morning

No alert at all. Asked why logons took 40 seconds, BE AI finds the backup job that ran late and pinned the domain controller. The case →

Eight cases, side by side →

who it is for

Built for IT people: providers and in-house teams, not end users.

The IT company

Forty machines across eight customers and a phone that rings at dinner. BE AI does the first hour of every ticket before you open the laptop, and the alert already says what it found. More →

The IT team

Every customer is a company with its own install link and its own sign-in. Whoever is on call gets the text; everyone sees the same thread; every approval has a name on it. More →

In-house IT

A practice, a workshop, a warehouse, with servers nobody has time to check. Tag them by site, let the nightly pass find the disk that will be full next month, and keep approvals in your own hands. More →

questions engineers ask

Before you put an agent on a production box.

Is this an RMM?
Closer than it used to be, without the parts that need a big team. Monitoring with an investigator attached, alerts that arrive with a diagnosis, fixes a named person approves, and remote control of Windows machines from the console. No script library and no patch deployment.
Can the AI run commands on my servers?
No. It reads through a fixed set of tools and proposes changes. A named person approves each one, and the record shows who did.
Can I take control of a machine?
Yes, on Windows. Open the machine in the fleet and press control: the desktop opens in your browser over the agent's outbound connection, with no port to open and nothing to install. Watch does the same without touching anything. A signed-in person opens the session, one person controls a machine at a time, and every session is recorded with who, from where, why and how it ended. Each customer can switch it off.
Does it need inbound ports or a VPN?
No. The agent opens one outbound HTTPS connection to the hub and keeps it alive. It works behind CGNAT and on 4G routers.
Where does the data live?
Wherever you put the hub: hosted by Binary Elements in Sydney, Australia, on your own server, or in your own cloud account. It is one container and one data volume, so moving it later is a copy. Heartbeats are kept 14 days, hourly rollups two years, events a year.

Put BE Hub on ten machines this week.

A pilot takes an afternoon: one install link, your own approvals, your own data. Uninstall the agent and you are out.