Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Prepare signed RMM packages and remote support. Prepare native delivery and controlled device acceptance before enabling customer downloads. Current availability: Implemented; verification required. Before you start. An authorized administrator with mandatory MFA completed. The correct company and provider permissions; keep credentials out of screenshots and chat. Step 1. TLS owners open /admin/rmm-preparation. Download the preparation pack and the owner-only reference-client source ZIP. The Node 22 reference client demonstrates enrolled heartbeat, bounded inventory and approved diagnostics; it is not a signed native installer or remote desktop transport. Step 2. Build the native agent for the supported OS and architecture using controlled CI. Use OS secret storage, least privileges, visible service identity, a bounded inventory and an uninstaller. Step 3. Sign the exact binary with the TLS-controlled publisher identity. Verify Windows Authenticode, macOS signing/notarization or Linux signed repository metadata as appropriate. Record the checksum and source SHA. Step 4. Test clean installation, upgrade, rollback and uninstall on authorized synthetic devices. Create one-time company/device enrollment links; do not embed a universal credential. Step 5. Accept heartbeat, inventory, command expiry, consent, audit, credential rotation and disconnect recovery. A native agent needs a local execution journal to avoid duplicate commands after restart. Step 6. Accept the remote-session provider and transport separately. Verify customer consent, session termination and audit. A portal request is not a remote desktop connection. Step 7. Publish verified packages through Downloads & releases and use a limited rollout. Monitor check-in traffic, errors and storage. Keep the previous signed release. Step 8. Suspend faulty releases, revoke affected credentials and expire queued commands. Offboard and verify device uninstall before company purge. Now verify the result. Only the accepted company and device can enroll with its token. A cancelled, expired or unapproved command cannot execute. Uninstall removes the service and its local credential. If you get stuck. Native binaries, signing identities, provider licensing and real device acceptance are still required. iOS and Android require separate MDM and OS-permission work; desktop remote-control behavior cannot be assumed. The reference client keeps a local execution journal, rotates its credential and sends terminal command results. It does not execute arbitrary shell commands. Signed native distribution and real device acceptance remain required. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.