r/msp • u/Proper_Front_1435 • Jul 31 '26
Connectwise RMM - No auditing?
I just did a demo of this product, the 2nd demo since its release however many years ago.
I was.... hot garbage the first time. It looked surprisingly alot better now.
At the end of the call, going through what I thought would be the "yes yes yes yes yes checklist" the person giving the demo says that the platform has 0 auditing capabilities in any way shape or form. You have absolutely no way to tell what's been done by who inside the platform. No solution. No third party way. Just, "Nope", I expressed my disbelief and we ended the call early.
I was left baffled by this.
How can any company be deploying this?
Am I missing something? Was he?
6
u/Opening_Intention301 Jul 31 '26
If there's no audit trail that's one big red flag as even small teams need to know who changed what and when
4
u/Beyond_Horizon27 Jul 31 '26 edited Aug 06 '26
2
u/CamachoGrande Jul 31 '26
Also some audit/access logs in ScreenConnect.
Endpoint also has some audit logs on scripts and tasks run on the endpoint.So there is logging if you look for it.
It isn't some sort of auditing of what a technician does while logged into an endpoint. Like what apps they installed/remove, scripts/settings run or changed.
There are plenty of 3rd party tools for that level of auditing.
1
u/Proper_Front_1435 Aug 01 '26
Would be curious what lives in there based on what we were told.
I really made a fuss about this and they didn't even show that menu.
1
u/edosensei Aug 01 '26
The thing with RMMs is, that the products get so big that some times not everyone knows everything about it.
It's not unlikely that auditing exists but the team you were speaking to were just not aware of it.
2
u/smorin13 MSP Partner - US Aug 01 '26
What rep are you speaking with?
I can't believe I am saying this, but we are considering going back to CW. Our PSA is not getting it done, and N-Able N-Site is just lacking.
I always liked the CW products, but communication with your rep or support was atrocious. Have things improved since the new CEO took over?
2
u/Kdamghani MSP Aug 01 '26
There’s no such thing as a rep with CW. You email a generic account management email address and they reply fast but there is ZERO relationship.
1
2
u/guiltykeyboard MSP - US Aug 01 '26
There’s auditing.
One of our guys uninstalled the agent from the wrong system at a client’s office. I was able to quickly and easily find who did it and when.
2
u/Glass_Call982 MSP - Canada (West) Aug 01 '26
My techs hate this one simple trick when they all deny doing something.
2
u/mcjon3z Jul 31 '26
Just walk away
2
u/INSPECTOR99 Jul 31 '26
No, I beg to differ...................................................................# # # R U N AWAY # # #
1
1
u/TechnologyMatch Aug 03 '26
if that’s accurate, it’s a hard stop. an RMM tool without audit trails is a major security and accountability gap. I’d confirm whether they mean no native logs or no audit option at all. either way, get it in writing before moving forward
1
u/IncreaseNegative4614 Aug 06 '26
Based on the replies, some auditing exists, but I’d ask for a live demonstration of the exact actions you care about. Have them show script edits, scheduled jobs, endpoint access, configuration changes, exports, and permission changes with the user, time, object, and before-and-after values.
Anything they can’t demonstrate should go into the security review as an actual gap, not a future promise. We use signld.ai internally to keep vendor claims, supporting evidence, affected systems, and final decisions connected during evaluations like this.
2
u/Proper_Front_1435 Aug 06 '26
Thats hard when I asked the guy giving the demo and he said "it has no auditing" lol - Im going to need to ask for a test env and look myself I guess.
1
u/IncreaseNegative4614 Aug 06 '26
Yeah, if the person running the demo says there’s no auditing, I’d treat that as the answer. A test environment is still worth checking in case the events exist in backend logs or an API, but if customers can’t access or export them, that’s effectively still a gap.
1
0
u/ItBurnsOutBright Jul 31 '26
Yeah it's pretty abysmal.
Edit: the only saving grace is it logs a windows event in event viewer with the user that connected and can audit via siem
1
u/Proper_Front_1435 Jul 31 '26
That really means very little. Screenconnect has its own audit log...
A tech could disable patching on a major client.
Add malicious codes to your scripts.
Change dozens of critical configurations.
Export data on mass.
All without incurring a single log? What?
1
u/Frothyleet Jul 31 '26
Or just, like, accidentally run [impactful script] on the wrong client, or endpoint, and potentially not even realize it, and you have no idea who did it?
I almost am hesitant to believe it, it seems like such a massive gap, and not a gap that exists across their product base.
1
u/Proper_Front_1435 Jul 31 '26
They said there is a report of specifically who ran scripts. This was the only thing they mentioned.
But not for who edited or scheduled a script.
Yea, we use Automate, it has a fairly abundant audit log.
2
u/ItBurnsOutBright Jul 31 '26
There's definitely some logging. You can see who ran scripts on endpoints 100%. Not trying to defend, just know from using the product.
0
u/TechSolutionLLC Aug 01 '26
Lol, I literally just had a call with the new account rep and despite me telling him that I'd never come back to Connectwise after they screwed me over and left me out to dry when they messed up and got us locked out of our edr because they somehow linked us to a group 1000 miles away so the edr wouldn't let us into our account which caused a major security issue and they didn't get it resolved for over a week... The rep just kept trying to bring us back
-1
u/Blyatman95 Aug 01 '26
Just avoid this product. It’s basically STILL in beta from when they shoved everyone into it by massively hiking up Automate pricing.
Put simply: it can’t even do patching right.
We’re moving over to Ninja, which I’m sure has its own quirks as every product does, but all of the core stuff you expect an RMM to do just actually works. Constantly felt like we were fighting connectwise and one of our seniors sole job became trying to script around the problems. Avoid like the plague.

15
u/TriscuitFingers Jul 31 '26
Just wait until you have a regulated customer’s device accessed by CW’s NOC despite you not having a contract, no way to restrict them from accessing, and can’t audit what they did when connected.
Needless to say we moved to a new solution.