Documentation
Using ITAI
Everything you need to install ITAI, run your first diagnosis, and understand exactly what it can and can't do on your machines.
How ITAI fits together
ITAI has two parts. The dashboard is where your team opens tickets, reviews findings and approves fixes. The receiver is a small Windows service on each device: it checks in with the dashboard, runs the commands it's allowed to, and reports back.
A diagnosis is a conversation between the two. ITAI decides what to look at next, the receiver runs that one read-only command and returns the output, and this repeats until ITAI has a finding. Changes only happen after a person approves them.
Requirements
- Windows 10 or 11, or Windows Server. macOS and Linux are on the roadmap.
- Administrator rights on the device, to install the service.
- Python 3.10 or newer, installed for all users. You don't need to install it first: if it's missing, the installer installs it (see below). It uses
winget, or python.org's official installer wherewingetisn't available, such as on Windows Server 2019. - Outbound HTTPS from the device to your ITAI dashboard. The receiver only makes outbound connections, so no inbound firewall ports are needed.
Installing ITAI
Open Install in the dashboard. Every organization has its own installer, and a device joins the organization whose installer it ran.
Option 1: one line of PowerShell
Copy the command from the Install page and paste it into PowerShell opened with Run as administrator. It looks like this, with your organization's own values filled in:
powershell -ExecutionPolicy Bypass -Command "& { ... install.ps1 ... -ApiKey '<your org key>' -BackendUrl 'https://<your dashboard>' }"
Option 2: the installer package
Download the receiver package from the Install page, unzip it on the device, then right-click Install-ITAI.bat and choose Run as administrator. Use this where copying and pasting a command isn't practical.
Either way, the installer checks for Python, writes the device's configuration and starts the ITAIReceiver service. The device appears in your dashboard within a minute.
If Python is missing, the installer lists what it needs and asks before installing it (press Enter for Yes; no answer within a minute also means Yes). Pushed from an RMM tool or run as SYSTEM, where nobody can answer, it installs Python for all users without asking and says so in its output. Python comes from winget, or from python.org's official installer, checked before it runs. If you manage Python yourself, add -NoPrereqs to the command: the installer then never installs Python, and stops with instructions if it's missing. A progress bar, and a percentage on the output line for each step, show how far along it is.
Your first ticket
- Open the device from Devices.
- Choose Deploy agent. Describe the problem the way a user would report it, for example "Printer shows offline for everyone on the second floor".
- Pick a privilege level. Local admin is the default and right for most problems.
- Start the ticket. You can watch each command and its output arrive live.
- When ITAI finishes, read the finding and the proposed plan, then approve what you're comfortable with.
Privilege levels
This is the one decision ITAI asks you to make on every ticket. It sets the account ITAI investigates and fixes things with on that device.
| Level | Use it for | Notes |
|---|---|---|
| Current user | Problems in one person's profile: an app setting, a mapped drive, a browser. | Can't see system-wide settings or other users. |
| Local admin | Most problems: services, drivers, updates, disk, network. | The default. |
| Domain service account | Problems that need domain permissions. | Not available yet. |
| SYSTEM | Deep system problems that local admin can't reach. | The highest privilege on the device. Needs an explicit confirmation each time. |
The privilege level widens what ITAI can see, not what it can do unasked. Investigation stays read-only at every level.
Reviewing a plan
A plan is a list of steps. Each one shows the exact command, a risk rating, and a rollback command that undoes it.
- Open a step to review it. Only a step you have opened can be ticked.
- Approve selected steps runs only the steps you tick, in order.
- Anything you don't approve never runs. You can close the ticket and fix it by hand instead.
- Your approval is signed with your organization's key, covers only the commands you ticked, can be used once and expires after five minutes. The device checks the signature against its copy of your organization's public key, and refuses any step that doesn't match.
- A step marked Not independently checked is one the second AI check couldn't assess. Read its command yourself: approving it records that you saw the warning.
- If fixes are turned off for this client, the plan can be read but not approved. An admin turns fixes on in Company settings.
Ticket statuses
| Status | Meaning |
|---|---|
| Queued | Waiting for the device to pick it up. |
| Running | ITAI is investigating. |
| Awaiting review | A finding and plan are ready for you. |
| Approved | Your approved steps are running. |
| Resolved by ITAI | The approved fix worked. |
| Resolved manually | A technician fixed it and closed the ticket. |
| Self-resolved | The problem went away on its own. |
| No issues found | ITAI looked and found nothing wrong. |
| Unreachable | The device didn't respond. |
| Escalated | Needs a person: ITAI couldn't reach a safe conclusion. |
Managing devices
Retiring and restoring
Retire a device you've replaced or decommissioned. It leaves the main list, stops counting toward per-device billing, and can't be targeted by tickets. Restore it at any time. Devices that stop checking in are retired automatically after 30 days; an admin can change that window.
Device profile
Each device reports its make, model, serial number, OS and build, hardware and network identity. It's refreshed on check-in and after every diagnosis, so the device page always shows the machine as it is now.
Organizations & keys
Each organization has its own installer key. Devices installed with it belong to that organization.
An MSP's dashboard calls its organizations Clients. A company's calls them Teams, such as Finance or HR. Either way they work the same.
- Rotating a key issues a new one. The old key keeps working for a short overlap so devices can pick up the new one without an outage.
- Unassigned devices land in a holding pool when they register with a key that isn't tied to one organization. An admin places them.
- Moving a device between organizations is recorded with who moved it and why. ITAI flags a device whose domain or network looks like it belongs somewhere else.
Plans, models & caps
An admin sets these under Company settings.
| Setting | What it does |
|---|---|
| Device fee | A monthly fee per active device: $1, dropping to $0.90 over 50 devices and $0.75 over 100, with a $5 monthly minimum per account. |
| AI usage | On the Managed plan, your diagnoses' AI usage is billed on top of the device fee. Bring your own AI key is coming soon. |
| AI model | The model your organization's diagnoses run on. Lighter models are faster and cheaper; the most capable ones are best for hard problems. On the Managed plan, usage is billed by the model you pick, so any model is available. |
| Monthly spend limit | The monthly AI usage at which ITAI pauses for an organization. Every organization starts at $100; change or remove it in Company settings. A diagnosis already running when it is reached may finish its current work (up to 8 more AI calls each, billed as usual). Then no new diagnosis starts and no new fix is approved or sent to a PC until the limit is raised or the month turns. A fix already on a PC finishes, restart included. Device fees aren't affected. |
| Per-ticket cap | The most AI usage a single ticket may consume. When a ticket reaches it, the diagnosis stops cleanly and tells you why. |
| Currency | Amounts shown in US dollars or euros. |
Security model
ITAI's safety doesn't depend on the AI making good choices. Five layers on the device stand between the AI and PowerShell:
- Allow-list. Investigation commands must match a read-only allow-list, or they're refused before they start.
- Constrained Language mode. Commands run in PowerShell's restricted language mode.
- Process containment. Each command runs in a Windows job object with limits on child processes and run time.
- Signed approvals. A change needs an approval signed by your dashboard. The device holds only the public key.
- Append-only transcript. Every command and its output is recorded to the ticket.
Around those layers:
- Fixes off by default. A new organization is diagnostics-only until an admin turns fixes on. Every change is recorded and shown in Company settings.
- A second check. A separate AI call, with none of the diagnosis in its context, compares each proposed step with its description. Mismatches are flagged, and a step it couldn't check needs an explicit acknowledgement to approve.
- Devices never contact the AI. The dashboard makes every AI call. Each device authenticates with its own credential.
- Retention. Tickets and transcripts are deleted 90 days after their last activity. Admins can export your data at any time, and the account owner can ask for it to be deleted.
Your data isn't used to train AI models. It's kept separate from other customers, with every record scoped to your organization.
Uninstalling
From the device page, choose Uninstall. For safety you type the device's hostname to confirm, and only admins can do it. The receiver stops, removes its service and install folder, and the device is marked uninstalled with an audit record.
Installing ITAI on the same PC again
After an uninstall from the dashboard, run the Install page's command on that PC at any time. The device comes back to your list by itself.
If ITAI was removed on the PC itself instead, for example its folder deleted by hand, the dashboard doesn't know it is gone and still holds that PC's credential. A new install under the same organization is then refused, so that no other machine can take the PC's place. Open the device's page, click Reset credential, then run the install command again.
FAQ
Can ITAI change something without asking?
No. Investigation is limited to read-only commands on the device itself. Changes run only from a plan a person approved, and the device checks the approval's signature first. For a new organization, fixes are off until an admin turns them on.
What happens if the AI suggests something harmful?
During investigation it can't run it: the command isn't on the allow-list. In a plan, you'll see the exact command, its risk rating and its rollback before deciding.
Does ITAI need inbound network access?
No. The receiver only makes outbound HTTPS connections to your dashboard.
Which AI models can we use?
You choose from the models your plan offers, from fast and economical to the most capable. Support for bringing your own AI provider account is coming.