Keel
Open-source remote monitoring and management you self-host. Multi-tenant control plane, Go agents for Windows and Linux, and a React technician console — site-scoped permissions and signed jobs, without a closed SaaS RMM.
Who it’s for
MSPs, internal IT, and operators who want monitoring, remote control, automation, patching, and policy — and who will host and harden the control plane themselves.
How it works
You run the control plane. Agents enroll with a one-liner, connect outbound over WebSocket (no inbound agent ports), and pick up signed jobs. Technicians work from a console with folders, sites, and RBAC. License is AGPL-3.0; public GitHub is coming soon.
Access and fleet
- Multi-tenant organizations with site-centric ownership, folders, sharing, and cascading grants
- RBAC presets, optional TOTP, and an audit log
- Enrollment via install scripts, hosted agent binaries, presence, and inventory
- Agent self-update with versioned Windows and Linux packages
Remote control
- Signed job queue — durable, ephemeral, or replaceable
- One-shot PowerShell, CMD, and Bash; interactive shell (xterm)
- Windows process, service, registry, event log, and local users/groups
- File explorer with mkdir, rename, copy, move, delete, and chunked transfer (up to 100 MB), plus a shared file repository
Software and patching
- Windows software via winget — install, uninstall, updates
- Windows Update policies, catalog, and patch runs targeted by site, folder, or device
- Automation steps for software, Microsoft 365 / Office LTSC (ODT), and reboot (silent or end-user prompt)
Monitoring
- Disk, CPU, memory, offline, SMART, service state, process presence, file watches, and uptime
- Per-monitor email and web push (SMS coming soon); installable console PWA
- End-user reboot prompts via a desktop notifier on managed PCs
Security
- Agents connect outbound over WebSocket — no inbound agent ports
- Jobs and sessions are Ed25519-signed; enrollment tokens enroll devices, never run jobs
- httpOnly cookies and Argon2id password hashing
- You host and harden the control plane
Automation and policy
- Versioned script library (parameters, run-as system or user, Monaco editor) and schedules
- Visual automation builder — onboard, schedule, monitor, online, webhook, and manual triggers
- 75+ item Windows configuration catalog with site/folder/device targeting; apply/unapply when devices move
- Active Directory via gateway devices — list and link GPOs (no ADMX editor)
How to proceed
Keel is designed to be self-hosted under AGPL-3.0. For ZapTech website practices, see our Privacy Policy.
Request more info
Want a walkthrough, deployment notes, or to see whether Keel fits your environment? Send a note and we will follow up.