Self-hosted remote IT support · powered by AI

IT-AI

IT-AI is self-hosted, AI-powered remote IT support for your own fleet — an AI that diagnoses the problem and fixes it, once you approve. Run one hub, drop a lightweight agent on each Windows, macOS or Linux machine, and from a single dashboard — or straight from your AI — you get live screen and remote control, an interactive shell, secure file transfer, and live device health. The assistant inspects read-only, explains what's wrong in plain language, and proposes a curated fix. Nothing runs until you click Apply. Your hub, your machines — screen, shell, files and telemetry never leave your infrastructure.

Diagnose Approve Fix
Get it on GitHub Open-source agent on GitHub How it works ↓
// how it works

One hub, your fleet, a human in the loop.

Stand it up in minutes, enroll each machine with a personal token, and the AI becomes a first responder that proposes — never imposes. Every change waits for your Apply.

01
Run the hub
One binary. It starts, prints a hub ID and a dashboard URL, and that's your control plane — on your own infrastructure. The AI's API key lives here; endpoints never see it.
02
Enroll each device
Mint a personal token from the dashboard and run it-ai <hub> --relay-token htok_… on the machine. The device dials out over an HTTPS relay — no inbound ports, no NAT holes.
03
See your fleet
Every enrolled machine shows up in the dashboard — or via your AI: live screen, an interactive shell, file transfer, and a live compliance grade for each device.
04
Ask, then approve
Ask the assistant about a machine. It runs read-only checks, explains the problem in plain language, and offers an Apply card for a curated fix. Nothing runs until you approve it.
// capabilities

Everything a remote hands would do.
With an AI first responder.

Live control, a real shell, secure file transfer and device health — the RMM basics done properly — plus an AI that diagnoses and proposes approval-gated fixes, all driveable from your own AI over MCP. Self-hosted, open source, nothing routed through a vendor cloud.

AI diagnose → approval-gated fix
The assistant inspects a machine read-only, explains the issue, and proposes a curated fix — flush DNS, restart a service, kill a process, clear temp, empty the recycle bin. It runs only when you click Apply. The headline feature, and the guardrail on it.
Live remote control
Full screen view plus keyboard and mouse, cross-platform. See exactly what the user sees and take the wheel when you need to — Windows, macOS and Linux alike.
Interactive shell
A real terminal over the relay — not a canned command runner. Full interactive session on any enrolled device, with the responsiveness you'd expect from a local shell.
Secure file transfer
Stage-and-pull, SHA-256 checksummed. Push or pull files to any device without wedging the tunnel — big transfers run out of band, so control stays responsive the whole time.
Live device analysis
Encryption, firewall, antivirus, OS updates and hardware — read live from each machine and scored A to F. Compliance at a glance across the whole fleet, no separate agent to deploy.
Reverse-tunnel relay
Control machines well beyond the LAN. Devices dial out to the hub, so there are no inbound firewall ports to open and nothing to expose — the relay does the rest.
MCP-native
Drive the whole fleet from your AI — Claude and any MCP client. List devices, take a screenshot, run commands, push files, or just ask the assistant. Your AI becomes the console.
Strict ownership & isolation
Token-gated enrollment, and each user sees and controls only their own devices. Every action is audited, so remote access is accountable, not a shared skeleton key.
Self-hosted & open source
Your hub, your data — the agent, MCP server and CLI are open source under AGPL-3.0, with signed and attested binaries. No vendor cloud sees your screens, your shells, or your files.
// who it's for

One hub, three kinds of operator.

The same self-hosted engine, scoped to whoever's running it. In every case the hub is yours — screens, shells, files and telemetry stay on your infrastructure, and every fix waits for a human to approve it.

// fleets & help desks
IT & MSP teams
A fast AI first responder for a fleet of machines — it triages, explains, and proposes the fix, so the first pass is done before a technician even picks up the ticket. Every change routes through a human approval gate, and every action is audited. Reach machines anywhere over the relay, no inbound ports.
AI first-responder · approval-gated · audited
// homelab & personal
Solo & homelab
Put all your own machines under one hub and reach any of them from a browser — or from your AI — wherever you are. No vendor account, no monthly seat, no cloud in the middle. Just a hub you run and a lightweight agent per box, across Windows, macOS and Linux.
Your hub · any browser or AI · no account
// self-hosted by mandate
Security-conscious orgs
Self-hosted means no vendor cloud ever sees your screens, shells or data — and the AI's API key lives on your hub, never on the endpoints. Changes are approval-gated, access is isolated per user, and there's an audit trail behind every action. Governance you can point an auditor at.
No vendor cloud · per-user isolation · audit trail
// faq

Common questions.

Does the AI change my machines on its own?

No. IT-AI is read-only by default. The assistant inspects a machine, explains the problem, and proposes a curated fix — but every change waits for a human to click Apply. Nothing runs on its own, and every applied action is audited.

Where does my data go?

Nowhere you don't own. The hub is yours, so screen, shell, files and telemetry stay on your infrastructure. The AI's API key lives on your hub — the endpoints never see it — and there is no vendor cloud in the path.

What platforms does it support?

Windows, macOS and Linux, on both x86-64 and arm64. The agent is a single lightweight binary per device.

Do I need to open firewall ports?

No. Each device dials out to your hub over an HTTPS relay, so there are no inbound ports and no NAT holes to punch. You can reach machines well beyond the LAN without exposing them.

Is it open source?

Yes — the agent, MCP server and CLI are open source under AGPL-3.0, signed and attested. You self-host the hub. The code is on GitHub.

How is it different from TeamViewer or a classic RMM?

Three things. It's self-hosted, so nothing routes through a vendor cloud. It has a built-in AI that diagnoses problems and proposes approval-gated fixes, with a human in the loop on every change. And it's MCP-native, so your own AI can drive the whole fleet — list devices, screenshot, run commands, push files, ask the assistant.

Diagnose it.
Then approve the fix.

Self-hosted, AI-powered remote IT support — your hub, your machines, a human in the loop.

Self-host IT-AI Read the docs ↗
glick.run — AGPL-3.0