BE Hub vs a classic RMM.
The category: tools sold as remote monitoring and management — agent, alerts, remote control, scripting, patching, often a customer/company model. We describe the category, not a named vendor. Last reviewed 2026-09-10.
| BE Hub | Classic RMM (category) | |
|---|---|---|
| What it is | Primary control-first RMM: monitor + remote + scripts + patch, with an investigator that cannot write | Typically the same four jobs; AI, when present, is usually an add-on or a chat helper — verify per vendor |
| Ops loop | See finding → AI pulls evidence → exact command proposed → named approve/reject → verify → audit | Typically monitor and ticket; diagnosis and the exact next command are still a person at a keyboard |
| Changes need a named approval | Always, in code. AI cannot approve its own proposal | Often a scheduled script or policy can change a machine without a per-change named approval — verify per vendor |
| Unattended remediation | Deliberately not. That is the product | Common: scripts on a schedule, policy engines, auto-remediation packs — verify per vendor |
| Remote control | Windows: watch or take control from the browser, outbound only, recorded, switchable per company | Usually yes, often more platforms; inbound or relay architecture varies — verify per vendor |
| Script library | Saved commands with variables the hub fills; a person runs them or schedules them; every run kept | Usually a script engine or component library; may ship code to the endpoint — verify per vendor |
| Patching | Inventory, approve per company, scheduled jobs with restart policy, verified report | Usually yes; verify the verify-step and third-party coverage per vendor |
| Firewalls and cellular routers | OPNsense, pfSense, VyOS, Teltonika, OpenWrt as first-class machines | Often SNMP or a separate network tool — verify per vendor |
| Agent | About 8 MB, outbound HTTPS only, signed offline updates | Size, ports and update signing vary — verify per vendor |
| Who it is sold to | Internal IT first (250–2,000, multi-site); MSPs secondary and sovereignty-led | Often MSP-first, with internal IT as a secondary pack |
| Hosting | Global product: hosted (Sydney today), on-premise, or your own cloud/region | Usually vendor SaaS; on-prem varies — verify per vendor |
| Pricing model | Hosted US$69 per named technician per month; unlimited machines; 500 BE AI runs per seat, pooled; run packs if you need more. On-prem bands are quote | Per technician, per device, or bundled with other suites — verify per vendor |
Category comparison, last reviewed 2026-09-10. The right-hand column is how this category typically behaves, not a claim about a named product. Named-product pages will be dated against that product's own documentation. Corrections via the contact form.
Choose the honest answer, not ours.
Pick a classic RMM if
You already have one that fits, your auditors accept unattended scripts, you need remote control on macOS and Linux today, or you need a feature we have deliberately left out (PSA, billing, a full automation engine). Stay if a bake-off would be theatre.
Pick BE Hub if
You want the RMM jobs in one console and one rule: AI cannot write. You need endpoints and site kit in the same loop. You will approve mutations by name, and you want to place the hub (hosted, on-prem, or your cloud) rather than inherit a vendor region.
Shadow the incumbent instead of arguing the table.
The Exit is a 21-to-30-day read-only shadow on up to 100 devices. The table is a map; the shadow is the argument.