Metahuman Network presents

Welcome to the Combine.

Every Mac, Windows and Linux device in your fleet steps onto the field, gets measured, scored and ranked, and you always know who's game-ready.

MBP-DESIGN-04

macOS 15 · Pos. Designer · #04

Live
94 Combine Score
A
  • CPU
    18%
  • Memory
    54%
  • Disk
    37%
  • Network
    96
  • Uptime
    99

Every device
gets a score.

See · The Drills

Six events.
Every device runs them.

  1. Lane 01 40-Yard Dash

    30s

    Metrics on a 30-second clock.

    CPU, memory, every attached drive, latency, packet loss and uptime. Retime any org or device from 10 s to an hour, and all three agents pick it up live.

  2. Lane 02 Vertical Leap

    0–100

    One Combine Score per device.

    Weighted health across CPU, memory, disk, availability and network, graded A through F, so you can tell at a glance who’s game-ready.

  3. Lane 03 Shuttle Run

    3OS

    Native agents on every platform.

    A signed and notarized Swift agent for macOS, a code-signed .NET service for Windows, and a static Go binary for Linux on amd64 and arm64. Each one is built for its own OS, not ported.

  4. Lane 04 Endurance

    400days

    Fleet history that lasts the season.

    Hour-level SLA uptime from durable rollups, and about 13 months of hourly history. Look back at 24 hours, 7 days, 30 days, or the whole year.

  5. Lane 05 Film Study

    6h

    Vulnerability scouting, around the clock.

    Installed software is matched against CVE rules, with an automatic NIST NVD sync every six hours. Findings are ranked by severity for each device.

  6. Lane 06 Scouting Report

    Live

    Sees the trouble before it lands.

    Disk-fill projections, anomaly and memory-leak detection that names the culprit process, and a live stream from any device when you need it right now.

See · The Draft Board

Your fleet,
ranked.

Combine Scores roll up into a live leaderboard, a heatmap and SLA views covering 24 hours, 7 days and 30 days. The top performers and the ones that need coaching show up right away.

  • Leaderboard Every device ranked by health, with trend.
  • Heatmap The whole fleet on one screen.
  • SLA / Uptime Hour-level history for about 400 days.
RankDeviceScoreGrade
  1. MBP-DESIGN-04macOS 96
  2. WS-FINANCE-11Windows 92
  3. srv-edge-02Linux 89
  4. MBA-SALES-07macOS 84
  5. LT-OPS-19Windows 77
  6. srv-build-01Linux 68

The Roster

See it. Manage it.
Protect it.

Each tier is named for what you get. See your whole fleet with Combine. Manage it with CombineRMM. Protect it by adding Guard. Same scoring, same dashboard, same team colors.

COMBINE 01

See.

Combine

Sees everything. Touches nothing.

Read-only by design. Combine watches, scores and alerts on every device, and never changes a thing on any of them. Every feature is included, and the first 100 endpoints are free.

RMM 02

Manage.

CombineRMM · includes See

Everything Combine does, and it makes the play.

Everything in Combine, plus terminal, native screen share with vendor guests, scripts and automations, patching, policies and key escrow. Every action is gated and audited.

Add-on for CombineRMM
GUARD 03

Protect.

Combine Guard · add-on

Spots the threat, then shuts it down.

A per-device security add-on for CombineRMM. It catches persistence, ransomware and dead antivirus, then responds: isolate, quarantine, kill. It also locks down apps, USB storage and admin rights.

Stat sheet SeeCombine ManageCombineRMM Protect+ Guard
Metrics, Combine Score & Draft Board
Alerting, anomaly & memory-leak detection
Security posture, AV/EDR detection & vulnerabilities
Inventory, warranty & backup monitoring
API, webhooks, Prometheus & ticketing
Remote terminal & file transfer —
Screen share with vendor guests & chat —
Scripts, automations & self-service IT Tools —
Patching, reboots & policy baselines —
FileVault & BitLocker key escrow —
Playbooks per client, group & device — Incl. Guard plays
Threat board & EDR connectors —
Persistence, ransomware & AV-health detection — —
Cases, isolate, quarantine & triage — —
App, USB, admin-rights & network controls — —
Footprint on devices Read-only Step-up gated Step-up gated

Each device runs one agent: Combine or CombineRMM. Moving a device up to management means swapping the agent through the same enrollment flow. Guard switches on for any CombineRMM device that has a Guard seat, with no new install.

Manage · CombineRMM

Make the play.

When a device needs more than a scouting report, CombineRMM steps in with a live terminal, native screen share, scripts, patching and policy. It all runs in the same dashboard you already know, or from an iPad.

MBA-SALES-07 · Terminal Audited

Manage · Screen share

Call in a specialist.

Stuck on a printer driver or a line-of-business app? Bring the vendor's support engineer straight into the session. They watch, you pass them the ball, and you're right there the whole time.

  • Invite by email linkThe guest accepts an agreement before they see a single pixel.
  • Hand off, take backGive the vendor control, then take it back with one click, live.
  • You stay on the fieldA signed-in technician has to be present the whole time. Up to 3 guests can join.
  • Strict by defaultGuests can’t join unattended, VNC-fallback or curtained sessions, and every session is audited.
  • 01

    Terminal & files

    A real shell in the browser (PTY on macOS and Linux, ConPTY PowerShell on Windows), plus chunked file upload and download over the same brokered session.

  • 02

    Native screen share

    macOS and Windows, with no VNC needed. Multi-monitor, a privacy curtain, annotations and a laser pointer, drag-and-drop file send, and tech-to-user chat.

  • 03

    Scripts & automations

    bash, zsh, PowerShell and Python, run as the system or as the signed-in user. Schedule them across a group or the whole fleet, and offline devices catch up when they reconnect.

  • 04

    Patching

    Windows Update Agent and winget, softwareupdate, and apt, dnf, yum or zypper. Install now or pre-stage, with deferrals, deadlines and a reboot policy users can postpone.

  • 05

    Policies & baselines

    Firewall, encryption, screen lock, password rules, AirDrop, camera and Bluetooth restrictions and more, checked every 15 minutes with auto-remediation. Group them into CIS, HIPAA, PCI, SOC 2 or Essential 8 baselines.

  • 06

    Key escrow

    FileVault and BitLocker recovery keys, captured without fleet-wide credentials and encrypted at rest. Revealing one takes an admin, a step-up and an audit entry.

  • 07

    Threats board

    One board for detections from Defender for Endpoint, SentinelOne, Huntress, GravityZone, CrowdStrike Falcon and Malwarebytes, plus a custom ingest API.

  • 08

    Self-service IT Tools

    Admin-curated fixes in the macOS menu bar and the Windows tray. Users can also file a support request and get the ticket number back.

  • 09

    iPad tech app

    Terminal, touch screen share, scripts, patching and key reveal from an iPad. Every action needs a fresh Face ID check.

Protect · Combine Guard

The Defense.

Guard is CombineRMM's defensive coordinator. It reads the play, calls it, and stops it, from ransomware to rogue startup items to a USB stick that shouldn't be there.

Play-by-play Replay
  1. 0:00

    Decoy renamed

    !Accounts-2026.xlsx → !Accounts-2026.xlsx.locked on LT-OPS-19

  2. 0:09

    Critical · Possible ransomware

    Running processes captured · MITRE ATT&CK T1486

  3. 0:09

    Auto-response · Device isolated

    Only CombineRMM is reachable. The user is notified.

  4. 0:10

    Case #1007 opened

    Assigned to on-call · status Contained

  5. 0:42

    Triage collected

    Processes, connections, startup items and logs saved as evidence

Isolation releases with one click, or with a local access code if the node can't be reached.
  • Ransomware canaries

    Hidden decoy files sit in the folders that matter. If one gets encrypted or renamed, a critical alert fires within seconds, and Guard can isolate the device on its own.

  • Persistence watch

    New launch agents, Run keys, services and cron jobs get flagged when they appear, with signing status and MITRE ATT&CK mapping.

  • Antivirus health

    Defender, XProtect and third-party EDR are checked continuously. “No active antivirus” opens a case, and detections read in plain English.

  • One-click response

    Isolate the network, quarantine or retrieve a file, kill a process tree, or collect triage. Offline devices queue actions until they reconnect.

  • App control

    Audit what runs, allow it in one click, then enforce. On Linux, unapproved programs are blocked before they start.

  • USB storage control

    Audit, read-only or block, with exceptions for approved drives by serial number. Keyboards and docks keep working.

  • Just-in-time admin

    Users ask for admin from the menu bar or tray. You approve a time-boxed grant, and it expires on schedule even if the device is offline.

  • Threat intel built in

    About 1.1 million malware hashes and 100K network IOCs from abuse.ch feed detection and network blocking. Air-gapped nodes can import a bundle.

An add-on for CombineRMM: +$1.00 per endpoint per month at the limited-time Founding Supporter rate, locked in for life (list $1.50). Each response action needs an admin and a step-up re-auth, and is audited.

Manage + Protect · Playbooks

Draw it up once.
Run it everywhere.

A Playbook is a named, versioned bundle of plays, like Finance laptops, Kiosk lockdown or Dev workstations. It holds configuration, protection, controls, automatic response and scripts. Assign one to a client, a device group or a single device.

Finance laptops

v7 · published · Screen lock 10 → 5 min since v6

Publish v8
  • Screen lock5 min · password required
  • Disk encryptionFileVault / BitLocker required
  • Password policy14 characters · lockout after 5
  • Automatic updatesInstall · 3-day deferral
  • BaselineCIS Level 1

Stack the plays.

The most specific scope wins. Allow and block rules add up. Every device shows you exactly where each setting came from.

  1. FleetMSP baseline
    Screen lock 15 minApp control auditBlock known-malicious
  2. Org · Acme FinanceFinance laptops
    Screen lock 5 minUSB read-only+ block dropbox.comAuto-isolate
  3. Group · Trading deskTrading desk
    App control enforce+ allow Bloomberg
  4. Device · LT-FIN-07Device override
    + allow 1 USB drive
LT-FIN-07Device page · Playbook
Resolved
  • Screen lock 5 min from Finance laptops · org
  • Firewall On · stealth from MSP baseline · fleet
  • USB storage Read-only + 1 allowed drive added by LT-FIN-07 · device
  • App control Enforce from Trading desk · group
  • Allowed apps OS vendor + Bloomberg added by Trading desk · group
  • Network block Known-malicious + dropbox.com added by Finance laptops · org
  • Canaries On · auto-isolate from Finance laptops · org
  • Automations + printer mapping added by Finance laptops · org

The Officials

Fair play,
enforced.

  • Step-up re-auth

    Every write action needs an admin, an RMM-licensed device, and a fresh re-authentication within the last 5 minutes. Isolation can require a second admin’s approval.

  • Full audit trail

    Who, which device, when, how long, and what happened. Every session and action is a durable record.

  • True org isolation

    Devices, alerts, rules and settings are scoped to each client. Client admins see only their own fleet.

  • SSO, passkeys & 2FA

    Each org brings its own OIDC provider (Entra, Google, Okta, Auth0, Keycloak) or SAML 2.0 IdP. TOTP, passkeys and passkey-only sign-in are built in.

  • No inbound ports

    Remote sessions run through a broker on the node, so agents never accept inbound connections. Agents are code-signed, and the macOS pkg is notarized.

  • Air-gap ready

    Self-hosted nodes take offline license activation and CVE imports, serve their own installers and updates, and never disable themselves if a license check fails.

OpenAPIPrometheusGrafanaWebhooksSlackServiceNowJiraZendeskMHN Service DeskBigQuerySnowflakeRedshiftDropsuiteUniFiDefender for EndpointSentinelOneCrowdStrikeHuntressGravityZoneMalwarebytesOIDCSAML 2.0MITRE ATT&CK

Home or Away

Play in our stadium.
Or build your own.

Cloud

Hosted on Metahuman nodes

Each org gets an enrollment token with pre-filled installers, MDM profiles and one-line install commands. Devices land in the right org on a capacity-matched node, with zero touch. Updates roll out in staged batches, canary first.

Self-hosted

Your node, your rules

Run the node on your own infrastructure with the full feature set. Offline license activation and CVE imports keep air-gapped fleets current, and the node serves its own installers and updates. It never disables itself if a license check fails.

  • macOS Swift agentSigned + notarized .pkg .mobileconfig via MDM
  • Windows .NET agentCode-signed MSI + tray app Registry policy
  • Linux Go agent.deb · static, amd64 + arm64 config.json

Contracts

Pick your position.

Combine is free for your first 100 endpoints, with every feature. CombineRMM and Guard are available at limited-time Founding Supporter rates.

Join while founding pricing lasts and your rate is locked in for life on the plan you buy.

See

Combine

Free first 100 endpoints, then $0.50 per endpoint / month
  • Every feature included, with no tiers
  • Metrics, Combine Score & Draft Board
  • Alerting, anomaly & leak detection
  • Security posture & vulnerabilities
  • Inventory, warranty & backup monitoring
  • API, webhooks, Prometheus & ticketing
  • Multi-client orgs, SSO & 2FA
  • Cloud or self-hosted, air-gap ready
Get your free key
Founding rate · limited time

Manage

CombineRMM

$1.25 per endpoint / month · list $2.00
  • Everything in See
  • Terminal, files & native screen share
  • Vendor guests on screen share
  • Scripts, automations & IT Tools tray
  • Playbooks per client & device group
  • Patching, reboot policy & baselines
  • FileVault & BitLocker key escrow
  • Threats board & EDR connectors
  • iPad technician app
Lock in founding rate
Founding rate · limited time

Protect

+ Combine Guard add-on

+$1.00 per endpoint / month on CombineRMM · list $1.50

Manage + Protect: $2.25 / month · list $3.50

  • Everything in Manage
  • Ransomware canaries & auto-isolate
  • Persistence & AV-health detection
  • Cases with one-click response
  • App control & USB storage control
  • Just-in-time admin rights
  • Network blocking with threat intel
  • Guard plays in every Playbook
Add Guard
250 endpoints

See · Combine

$75

per month · first 100 free

Manage · CombineRMM

$313

per month · list $500

Manage + Protect

$563

per month · list $875

Prices in USD per endpoint. Annual billing is ten months' price for twelve months of service. CombineRMM and Guard figures show limited-time Founding Supporter rates, with list prices struck through. Founding pricing will end, but anyone who joins before then keeps their rate for life on the plan they purchased. Self-hosted and air-gapped nodes run the same full feature set. Talk to us about large fleets.

Draft Day

Make the team.

Combine is free for your first 100 endpoints, with every feature, and you'll see your first Combine Score within minutes of install. Bring in CombineRMM and Guard when you're ready.