Shipped and live
Nominate one always-on machine at a site as its relay and reach the kit that will never take an agent: switches, firewalls, NAS boxes, printers, and the servers you have not installed on yet. Discovery already records which machine can see which device, and the vault already holds the logins, so the relay runs the command and reports the result back. Windows relays talk PowerShell over WinRM, Linux and network kit over SSH. A target only appears if that relay is the machine that discovered it, every command waits for a human to approve it, and the password is never written into the command: the relay fetches it at the moment it runs and the access lands in the vault audit trail.
Connect QuickBooks Online in Settings, map each client to a QuickBooks customer once, and push a month's billable time straight in as a draft invoice, line by line, matching the CSV to the penny. Built on the time tracking and rates that shipped earlier in July.
Reusable reply templates you insert straight into the ticket reply box, and a one-click Great / Okay / Poor rating in the resolved-ticket email. No login for the client, and their rating lands on the ticket, so you can prove the service is good rather than assert it.
Log time against tickets in one tap, set an hourly rate per client, and pull a monthly billing summary with a per-client CSV export any accounting package imports. The hours you work become the invoice you send.
Monitor your clients' websites and public services: uptime, response time and SSL certificate expiry. Downtime raises a ticket automatically, and so does a certificate about to lapse.
Isolate a compromised device from the network with one click, keeping only the Helios connection alive, and trigger Microsoft Defender quick or full scans on demand. The security page went from read-only to actionable.
Agents passively map each client's network, and Helios identifies what it finds by vendor and device type: printers, NAS boxes, network kit. New hardware on a client network is flagged the day it appears.
Helios now reads Veeam and Acronis directly, on top of the agent-level checks. It tracks when each job last produced a restore point, not just when it last ran, so a job that fails every night stops looking healthy.
Helio now reads back over a device's Windows error and warning history, grouped by how often each problem recurs, so it can answer what happened on a given day and tie a crash or slowdown to what the OS logged at the time.
Plain-language docs for every part of the platform at /docs: monitoring, patching, service desk, Helio AI, portals, integrations, API and the security model. Limits stated, reasoning included.
A documented, key-scoped REST API over your clients, devices, tickets and alerts. Create keys in Settings, pick their scopes, and read the interactive reference at /api/v1/docs.
Runbooks, notes and structured documentation living beside the credential vault, so everything a tech needs about a client is in one place.
Your clients' users describe a problem in plain English. Helio checks their company's devices and tickets, walks them through safe fixes, and raises a properly-written ticket when a human should take over.
One consistent visual language across every screen of the app and portal.
Helio diagnoses a device end to end, proposes and applies a fix, then verifies it worked. Novel or risky actions always wait for a technician's approval.
Inbound email is triaged and answered by Helio in seconds, with per-tenant control over how autonomous it is allowed to be.
Monitoring, inventory and patching for Linux alongside Windows, Windows Server and macOS. All agents are CI-built.
Alert fires, matching playbook runs, ticket documents it, and verified fixes close themselves. Over twenty built-in playbooks, plus your own, and Helio saves new fixes that worked as reusable playbooks.
Agent-level detection of Windows Backup, Veeam, Acronis and more, with staleness alerts so a quietly failing backup cannot hide.
Winget-driven updates for everyday apps next to Windows Update, with per-client schedules and compliance scoring.
Trend-based warnings days before a disk fills, and a per-device health score that rolls up into client and estate views.
Licences, MFA coverage, mailbox and OneDrive health, inactive users, and Defender threats surfacing as tickets, per client.
Client-facing portals on your own domain with your branding, plus AI-drafted quarterly business reviews you can edit and print.
Passkey login, mandatory 2FA for admins, encrypted credential vault, full tenant isolation, and one-click remote access with no second vendor.
Next up
The same one-click invoice export that now ships for QuickBooks, for Xero books: map clients once, push each month's billing in as draft invoices. The connection layer is already built provider-generic, so this is wiring, not a rebuild.
Entra ID single sign-on for technician accounts. Most Helios teams live in Microsoft 365 already, so signing in should be one click with the account they already secure.
A relay currently trusts whatever key or certificate a target presents the first time it connects, which means trusting the local network. The fingerprint is recorded with every command so a change is visible, but pinning it per target is the honest fix and it is the next thing on this feature.
The watching half of the same idea: now that a site can have a relay, poll the printers, switches and NAS boxes it can see for toner, port status and capacity, so they are monitored as well as reachable.
iOS and Android alongside desktop platforms. Being scoped; honest status is that desktop estates come first.