Comparison charts are written by whoever wins them. Here are the questions we think actually separate these products, with our own answers — including where ours is a no.
The big platforms in this market were assembled. Remote management from one company, service desk from another, documentation from a third, each with its own database, its own permission model and its own release cycle. Joining them up afterwards is genuinely hard, so mostly what gets joined up is the login page.
That isn’t a criticism of the engineers involved — it’s a structural constraint. It is also why the same handful of things stay stubbornly manual no matter how many products you buy from the same logo.
Including us. If a vendor can’t answer one of these crisply, that is itself the answer.
Three approval modes you set per conversation — ask every step, approve the plan once, or run unattended. Destructive commands hit a floor that unattended mode cannot cross. You see the risk level and the exact command before anything runs, and you can skip, reorder, redirect or stop mid-run.
None. Open-weight models on infrastructure we run, or your own if you would rather host them. There is no OpenAI, Anthropic or Azure OpenAI account anywhere in the product. Worth asking everyone this one — the answer is often in a sub-processor list rather than the sales deck.
Yes. Credentials come out of the vault and are injected into the session server-side, so the plaintext never reaches the browser. This is only possible because the vault and the remote access are the same product.
Live. We deliberately retired the sync that mirrored devices between products — there is nothing duplicated, so there is nothing to drift.
None on a managed endpoint. It dials out over TLS and keeps one socket open. A collector reaching devices that cannot run an agent binds a local port, and a machine you nominate as a trap receiver listens for SNMP traps. Both are optional and scoped to hardware you choose.
Sign-ins cannot be altered or deleted through any interface. Service desk history is append-only, enforced by the database rather than by application code. Credential reveals record who, when, from where and which permission allowed it. It is append-only, not hash-chained — we will not call it tamper-proof.
No. Single-tenant per customer, always — self-hosted or hosted by us on infrastructure dedicated to you. There is no multi-tenant mode to opt out of.
Not today. You can track time against tickets and generate invoices from it at the contract rate, then push those to QuickBooks Online to send and collect. Automated recurring agreement billing is on the roadmap, not in the product. If that is the centre of your month-end, weigh it heavily.
Your data sits in your own single-tenant database, and the audit trail and documentation export. What you cannot do is take one module elsewhere — they run on the shared platform. That is the trade for everything else on this site, and it should be a conscious choice rather than a surprise.
Not yet. Nobody re-keys thousands of articles by hand, so if you are migrating a large documentation estate this one shapes the timeline more than the decision.
If any of these is a hard requirement today, we are probably not your answer yet. Better to find that out now than three months into an implementation.
Bring the list to a call. Bring the same list to everyone else on your shortlist. It’s a better use of an hour than a feature matrix.