Service Desk — daily operations
How to work tickets, the alert hub and monitoring rules in one place.
Service Desk overview
Section titled “Service Desk overview”RMM → Service Desk is the technician’s daily hub: open tickets, active alerts, monitoring rules and notification routing. Start on the overview — see what is on fire now.
- Open RMM → Service Desk.
- Check open ticket count and active alerts.
- Handle critical alerts first, then the ticket queue by priority.
- Tabs: Overview, Tickets, Alert hub, Monitoring rules, Routing and notifications.
- Alert = system signal; ticket = work you drive to closure.
- Bell: Alerts / Tickets / Windows / Remote cards filter the inbox (the count matches the rows). The queue is Open and In progress — a reply or “In progress” does not remove the ticket, only resolve or close does. Windows is Support UI (
windows_app) only. A bar ticket does not vanish into alert noise or after your reply. Full queues: footer (Open alerts / Open tickets). - The alert list and detail show company, location, and the CRM contact linked to the device (MSP / multi-company).
- A Backup failed alert names the job (for example OPTIMA SQL), the source, and the cause. The Backup job link opens that job in Backup & recovery.
- The alert list omits the install dump and the full process snapshot — open the alert card for KB result / top processes.
Working a ticket
Section titled “Working a ticket”On a ticket set status and priority, assign a technician, jump to the device (Workbench) and — when the customer needs it on a report — link a CRM case.
A ticket from CVE or an auto-alert is internal work: Internal badge, title CVE-… — security vulnerability. It is not shown in the customer portal as a report and does not need a CRM case.
- Service Desk → Tickets → open a ticket.
- Confirm device / customer and set status (e.g. in progress).
- Do the work (update, script, remote desktop) from the device card. With a linked host, Ask for remote access puts a prompt on the Support UI bar.
- Close the ticket after verification; if the customer needs it reported — create or update a CRM case.
- New ticket form: Esc or a click on the dimmed backdrop closes it (an open device or contact list closes first). The CRM contact starts empty — type at least 2 characters and pick a person (the company is shown next to the name). A CRM case turns on only when the contact or the computer already has a company. A ticket from the panel assigns you as caretaker — Assigned technician shows name and login email, and you can pick someone else. Portal, Windows-bar and alert tickets go automatically to the device caretaker, or to the company caretaker when the device has none (field on the company card in My companies). With no caretaker the ticket stays in the Unassigned queue. Turn the rule off for the whole IT company in Service Desk → SLA and hours → Assigning new tickets (on by default). The list Source filter includes Portal (
/user/tickets), phone, email, or the Windows bar. - A ticket without device context is hard to diagnose — always check the Endpoints link.
- Work order follows the SLA deadline: on the ticket list pick Sorting → SLA deadline (most urgent), while the Ticket queue card in Service Desk and the phone app queue are ordered that way by default. First response counts until it is given, then resolution; paused SLAs and resolved or closed tickets go last. Sorting → Priority runs from critical down to low.
- Comments and attachments load when you expand the row thread or open the ticket card — the queue list does not embed them. A team reply is To customer. A message the customer wrote (portal or Windows bar) is From customer, with their name or “Customer (Windows bar)” — not “Unknown”. On the ticket card, Reporter is the CRM first and last name (even when the bar stored only an e-mail); the click opens that contact. Company opens the CRM client. On a wide screen the thread sits on the right, beside those details; a long conversation scrolls inside its own frame and the reply box always stays below it. The thread opens on the newest message. The top of the card has Assign to me, In progress and Resolve; under More: Significant incident, Pause SLA, Clear assignment, Merge into another and Close without resolving (asks for confirmation — the customer cannot follow up on a closed ticket from the Windows bar). Change Priority and Assigned technician right in the card details; the reporter’s e-mail and phone are clickable. When two people at the company share that address, the card keeps the e-mail unless the computer is linked to one of them.
- Sound and browser notifications for new tickets are on the ticket list (separate from alerts). Ticket email — Settings → Preferences (goes to the account email, not the alert override; the phone banner is independent). Computer = Web Push (Calendar or Settings → Preferences → Computer and phone notifications). Phone = technician app: sign in with the same email and password as the panel. A different sound = a different Android channel (alert / Windows ticket / other tickets / visits / tasks). Categories and sounds live in the app (menu → Notifications, Preview); turn off leftover Chrome on the phone from the device list in the panel. In the app: Search (hosts, tickets, alerts, clients, tasks, phone number), Tasks (client follow-up — title, due date, owner, mark done), Queue (filters Assigned to me / Waiting / Unassigned / Z paska Windows; rows show SLA; ordering follows the SLA deadline — nearest or already breached first, first response until it is given, paused SLAs last). Alerts: Acknowledge on the row, filter Needs ack. New ticket from the queue, an endpoint, an alert, or a client linked to RMM. Clients card: W serwisie (manufacturer and model, open service cases with protocol; tapping a case opens it in the full panel), plus open tickets, endpoints, and alerts when the firm is linked to RMM; the managed-care or repair role is shown at the top. The same badge (Opieka IT / Serwis komputerowy) appears in the Clients list and in Search results, so you see it before opening the card. Ticket card: priority, reopen, photo, Assign to me, Remote / AnyDesk when a host is linked. Endpoints and Clients: 20 per page, Previous / Next at the top and the bottom, Search covers the whole set. Endpoints: pending OS KBs, Restart, Remote, AnyDesk when the host has an ID). App lock (fingerprint / PIN) prompts on every open (menu → Account). Android asks for notifications only after sign-in (queue card or menu → Notifications). Identify callers is under menu → Account. Turn on caller ID asks Android for Call log and Phone and waits for Allow — it does not open app info while that sheet is still up. After a deny: Allow again or Open settings. Android asks separately for Call log and Phone; the battery sheet waits until both Allow taps are done. On Samsung/Xiaomi a card then sends you to never-sleep / autostart. “Who is calling” is a banner only — the app does not replace Phone and is not set as a default app. Client numbers live on the phone (clients, locations, contacts) and sync in the background and from Account → Synchronizuj książkę numerów — a new card in the panel lands on the next sync. A server restart or a brief network drop does not hide a name the app already has and does not force a full email login. A banner with just the number and a session message means the number was already read, but that number is not in the on-device book yet (or the session really expired). The queue card only disappears after both grants (Call log and Phone) — one Allow does not close the card or open the battery sheet. If Android still has no access, Account has Open settings and Check again (after a manual grant), plus a diagnostics line to quote when reporting a problem. The ringing number is matched in CRM — no manual pairing. Each call gets its own banner — even if you leave the first one in the tray (or swipe it away), the next call still shows who is ringing. Sign-in stays on the phone; reopening asks for fingerprint / PIN or the panel password on the lock screen (a full email login only after Sign out or a password change). Assigned to me is ticket ownership, not a banner inbox; Waiting is a public customer reply; Unassigned is the no-owner queue. Covers Windows, portal, panel, and customer replies. The Android Back button works like Back (closes the card or menu, or returns to the queue; on the queue it hides the app). Tap opens the ticket in the app; ticket, visit, and endpoint cards include phone / email when those fields exist on the ticket or the client / location.
- Many similar alerts often become one ticket + one CRM case.
Ticket sources in the staff bell
Section titled “Ticket sources in the staff bell”The header bell (not the ticket-list sound) labels tickets by how they arrived: Windows app, Portal, Email, Phone, or New ticket. The Windows card keeps Support UI tickets only; All and Tickets still show them after you reply, while status is Open or In progress. CRM due items in the same panel are Task / Head out / Visit — see Calendar, tasks and deadlines.
Follow-up from the bar and merge
Section titled “Follow-up from the bar and merge”Before it creates a ticket, the Windows bar asks when this PC already has an open one, or one resolved less than 14 days ago. The button and the follow-up window show the ticket title, not only the number.
- Append — same issue, same number. A resolved ticket returns to the queue as open, and the resolution SLA starts again. The first response stays.
- This is a new problem — a separate ticket.
- Closed tickets are skipped. The next click starts a new ticket.
A duplicate that already exists: open it and use More → Merge into another. Enter the number that stays (without “T-”). This ticket closes, and the description, messages and files land as an internal note on the one that stays. If that one was resolved, it returns to the queue too.
Red dot on the bar
Section titled “Red dot on the bar”The red dot is this computer’s queue: a ticket or a follow-up has not reached the panel yet. The tooltip says it will send on its own; a click retries. Deleting or closing the ticket in the panel does not clear the dot. If the ticket is already gone, retry cannot succeed.
To drop it from the computer’s queue: close the bar, delete the folder C:\ProgramData\RMMAgent\support-outbox, and start the bar again. That clears only unsent items on this PC. It does not delete tickets that are already in the panel.
Remote access (Support UI consent)
Section titled “Remote access (Support UI consent)”On a ticket with a linked device, Ask for remote access sends a prompt to the Support UI bar on that PC. That is user consent — it does not open AnyDesk / remote desktop by itself.
- Open a ticket with a host (or the device workbench).
- Click Ask for remote access. The user sees the prompt on the bar.
- After decline, expiry, or cancel, use Ask again — one new request, no second ticket.
- Without an assigned device the request is not sent — attach an endpoint first.
- Status shows the consent window (from–until), scheduled start, and expiry.
Bulk actions on the ticket list
Section titled “Bulk actions on the ticket list”When a dozen tickets need the same handling (queue clean-up, shift handover, closing a series caused by one outage), select them on the list instead of opening each one.
- Service Desk → Tickets → tick the checkbox on the rows. The header checkbox selects everything you currently see — the current page with active filters, not the whole queue.
- A Bulk actions bar appears above the list with the selected count.
- Pick a Status and click Set status, or pick a person (or Unassigned to clear ownership) and click Assign.
- When it finishes you get a summary (e.g. “Updated 8 of 8”), the selection clears, and the list refreshes.
- Closing always asks for confirmation; Resolved asks when more than 5 tickets are selected. Other status changes apply immediately.
- Tickets are updated in batches of 5. If some fail (missing permission, ticket already gone) you get “Updated X, failed: Y” — repeat the action on what is left.
- The selection only covers rows actually present on the list. Deleting a ticket (including by someone else), changing filters, sorting, or page drops the missing rows from the counter — no leftover “ghost” selection after a deleted ticket.
- Clear selection drops everything without changing any ticket. The selection does not carry across pages — run the action on one page of the queue.
- Bulk actions change status and assignment. Deletion stays per ticket, from the row’s three-dot menu.
Bulk actions on the alert list
Section titled “Bulk actions on the alert list”When the same signal is firing on many PCs, or you want to acknowledge / resolve a series at once, select them in the hub instead of opening each one.
- Service Desk → Alert hub → tick the checkbox on the rows. The header checkbox selects everything you currently see — the current page with active filters, not the whole queue.
- A bar appears above the list with the Selected count.
- Acknowledge works only for active alerts. Resolve and Remediate also work for acknowledged ones. Delete asks for confirmation. Assign selected to me / Clear assignment changes the owner.
- When it finishes you get a summary (e.g. “Done: 8 OK, 0 failed.”), the selection clears, and the list refreshes.
- If a button is greyed out or the toast says “No matching alerts”, the selection does not have the status that action needs — change the filter or deselect resolved rows.
- The Same problem on multiple PCs block groups hosts without AI. Select group puts the whole cluster on the bulk bar; AI analysis is group triage — scripts and full diagnosis stay on the alert card / device.
- The Assigned to me filter narrows the list to your alerts before you tick rows.
Phone app and packages
Section titled “Phone app and packages”The technician app uses the same commercial package as the panel. Serwis (crm_desk) and a post-trial account without a package do not show Endpoints, RMM tickets, device alerts, or Remote/Restart — the queue is open service cases, plus Clients, Route, and caller ID. Starter and above get the fleet, same as the web shell. Account shows the package name and the language (match the phone / Polish / English — the caller banner follows that choice); upgrades happen in the full panel (Plans and billing). On a ring the app shows who is calling and the firm, not the whole company PC history. Equipment appears when it is in the workshop or the case belongs to that person.
Phone app: Endpoints and Clients
Section titled “Phone app: Endpoints and Clients”On the Serwis package the menu has no Endpoints — Clients, cases and Route stay (see above). On Starter+ the Endpoints and Clients lists show 20 rows per page. Previous / Next sit at the top and the bottom of the list — on a phone you do not scroll every row to change page. The range (e.g. Endpoints 1–20 of 47) is above the list. Search covers the whole set, not only the current page.
Monitoring rules and routing
Section titled “Monitoring rules and routing”Rules decide when an alert is created (thresholds, missing heartbeat, backup failure). Routing decides who gets notified. At the start enable a few high-value rules, not everything.
Entry points: Service Desk → Rules or Alerts → Device rules (/rmm/alerts/rules). Both screens have ? Help (same guide: how device rules work).
On Device rules you also get an Alert noise policy (MSP defaults): it skips common Event Log noise (Google/Edge Update, Bitdefender EPProtectedService / ESET), TiWorker CPU warnings, and BEST/Defender scans even at ≥95% CPU. The ransomware heuristic pages only with impact (encryption / shadow copy), not cmd.exe alone — on Protection an open cmd is not a row (like Atera / Ninja). The same problem on one PC (the same service) stays one card in the hub — later days do not pile extra resolved rows. Bitdefender quarantine is the same pattern: isolated files stay on the Protection tab; the hub gets one card only when remove or restore is pending or failed (deep-link to the quarantine list).
Event 7036 (service entered the stopped/running state) does not create an alert. Failed start (7000) and unexpected termination (7031/7034) still do.
Check Rules immediately starts evaluating this company’s enabled rules (a “Check started” toast; work continues in the background). New alerts appear in the alerts hub. The scheduler already does this on a timer — you do not need to click it daily. That is not the same as “Review rules” on the Service Desk overview (that only opens this tab).
- Start with: missing heartbeat, failed backup, critical disk / service.
- QNAP / Synology / iDRAC / HPE: after you add the SNMP device, disk+volume and unreachable rules are created for you. Low NAS volume space (default ≤15% / ≤5%) and Veeam Warning also alert and email.
- Service stopped on one PC: Device scope → type at least 2 characters (name / company) → Enter or click the PC (the computer list then collapses) → filter the service under the name field (SQL hosts often have 200+; without a filter you see the first 80) and click / Enter. Or run Scan services if the list is empty. The name field filters that list — there is no second computer picker. Enabled must stay on for an alert and notification. Leave “Ignore Manual / Disabled” checked (the default) — it alerts only for Automatic services. Auto-resolve closes the alert when the service is Running again. Device offline uses minutes without heartbeat, not a dummy “90” threshold. Includes an RD Licensing (
TermServLicensing) template. Device/location rules belong to the host’s company (so a platform admin picking a PC in another firm still evaluates correctly). Very short Automatic stops may not alert if the agent or Windows recovery restarts the service first. - Form (every type): instead of greater/less than you see When to alert. Enabled must stay on for an alert and notification (emails: Routing tab). Check interval, description, and SNMP OIDs live under Advanced — 300 s / 0 s is usually enough.
- CPU / RAM / disk / temperature (PC and SNMP) and SNMP interface errors: alarm threshold and resolve threshold sit side by side (e.g. CPU 90 / 70; disk — resolve threshold higher than the alarm).
- Service stopped, device offline, CVE, SMART, pending updates, interface Down, device unreachable, NAS disk health: no separate resolve threshold — auto-resolve closes the alert when the state recovers (service Running, heartbeat, interface Up, and so on).
- After enabling a rule, confirm the alert appears and email arrives.
- Noisy thresholds = raise the threshold or narrow device scope.