PSAAutotask PSA
Where the work comes from. Projects sync from Autotask, each filed under its client, so nobody types or imports them.
- Active customer organizations, as the clients projects belong to
- Their projects, including completed ones: those are the work Hotam verifies
- Each project's description, which becomes its scope
- Start date, end date and percent complete, shown for reference only
AccessA dedicated API user the MSP creates in Autotask. We recommend limiting it to viewing organizations and projects.Known limitTasks, tickets, products sold and user-defined fields are not read yet. Requirements come from the project description for now.
RMMNinjaOne
Where the device facts come from: which computers and servers are there, and what state they are in.
- Each client's approved Windows, Mac and Linux workstations and servers
- Whether the NinjaOne agent is installed
- Whether monitoring is active: online and not in maintenance mode
- BitLocker disk encryption, enabled only when every volume is fully encrypted and protected
AccessAn API client app with the Monitoring scope only, which is read-only. No Management or Control scope.Known limitDisk encryption is reported from BitLocker only. FileVault and Linux encryption are not in NinjaOne's API, so those checks show Unknown.
Microsoft and identityMicrosoft 365
Where the user facts come from, read from each client's tenant through Microsoft Graph.
- Users, and whether each account exists and is enabled
- Assigned licenses, and seats purchased per plan
- Whether each user is registered for multi-factor authentication
- Domains, and whether each is verified
AccessAn app registration with Microsoft Graph read permissions only, approved by an admin in each client tenant. Deleting the app in a tenant removes access.Known limitMFA means registered, not enforced on every sign-in. Conditional Access is not evaluated yet.
DocumentationIT Glue
Where the documentation check comes from: do the records a project promised actually exist?
- Each client's documents and flexible assets, by name
- Whether each record is archived, and when it was last updated
- Never document content, asset fields or passwords
AccessAn API key the MSP creates in IT Glue, with password access left off. Hotam only sends read requests.Known limitHotam counts records that exist. It cannot tell whether a record's content is complete, so an empty document still counts.