Enabled automatically when you turn on RMM script execution on the workflow’s Integrations tab — there’s no separate toggle in the tool list. Requires a connected RMM that supports script execution (NinjaOne, Datto RMM, N-Sight, ConnectWise Automate, ConnectWise Asio, Kaseya VSA X; more in progress). For read-only device and monitoring data, see RMM API.
What It Does
- Search your RMM’s script library by description and match it to the ticket’s issue
- Resolve the ticket’s configuration item to the right RMM device
- With several RMMs connected, run on the exact RMM the device belongs to — if a device ID matches devices in more than one RMM, the agent is shown the candidates and picks one explicitly instead of guessing
- Run the script on that device
- Wait for the job to complete and read its output
- Verify the issue is resolved, then take follow-up action — close and notify, escalate, or try another fix
Burst Protection
RMM devices run one job at a time, and RMM platforms expire jobs that don’t start in time (Datto RMM: 60 minutes). When many jobs target the same device at once — end-of-month change requests, bulk maintenance — Neo holds the excess in a dispatch queue and releases each job as the device frees up, so every job runs inside its execution window instead of expiring in the device’s backlog. Queued jobs show as queued in Executions and dispatch automatically — no action needed. A job that can’t be dispatched within 8 hours (device offline or saturated) is marked failed with a clear reason.Completed with no output. Occasionally a job finishes but returns no logs or output — the script produced nothing, the device didn’t report its result back, or the run logs are unavailable. Neo flags this case explicitly instead of treating the empty result as success, so the agent re-runs the job, checks the device’s connectivity in the RMM, or escalates to a technician rather than closing a ticket on a result it couldn’t verify.
A script the RMM keeps refusing. Datto RMM can reject a script submission with a plain server error and no reason, which usually clears in minutes — Neo retries and carries on. When the same script and device have been rejected repeatedly for over a day, Neo stops retrying and escalates instead. Open the component in Datto RMM and check that it still exists, is permitted on that device, and has the variables the agent supplies.
A server error on submission. An RMM can report a server error after it has already queued the run, so a submission that fails this way may still execute. Neo treats the outcome as unverified instead of assuming the run was rejected. Check the device’s scheduled jobs and script history in the RMM before running the script again.
A script NinjaOne accepted but Neo can’t track. NinjaOne confirms a script run without returning a job ID, so Neo identifies the run by matching it against the device’s activity feed straight afterwards. If NinjaOne hasn’t published that activity in time — a lagging feed, or a script renamed in NinjaOne since Neo last synced your script library — Neo has no handle to poll for the result. Neo says NinjaOne accepted the run and its state cannot be read, and tells the agent not to start a second copy until someone reads the outcome, because the two would collide. Check the device’s activity feed in NinjaOne for the outcome, and re-sync your script library if the name has changed.
Safety
When technician approval is enabled for this tool, the agent must obtain an actual approved Technician-in-the-Loop request before a script runs — it requests approval first, then executes once approved. Marking a script “pre-approved, no approval needed” in custom instructions does not waive this: custom instructions guide which scripts the agent prefers, but they can’t bypass the approval requirement. To let specific known-safe scripts run without a per-run approval, add them to Pre-approved scripts on the RMM’s script-execution permission group — matched exactly on the script and its variables — rather than relying on a note. Everything not on the allowlist still requires approval, so you keep the guard where it matters while letting routine read-only diagnostics run immediately.
Where approval is set. Approval for script execution comes from Require Technician Approval on the permission group that grants scripting for your RMM — Datto RMM Jobs, NinjaOne / VSA X / CW Asio Automation, N-Sight Tasks, CW Automate Script Execution. Turning it on there gates script runs as well as that RMM’s API calls. If you connect several RMMs and any one of them has approval on, script execution asks for approval on all of them — the agent has a single approval setting covering every RMM.
Which devices the agent can target. A chat agent can run a script on any device in your synced inventory that belongs to an RMM you have enabled script execution for — a technician naming a machine in chat is the instruction, and no ticket is required. An automation with a ticket can only act on devices belonging to the ticket’s company, so it can’t reach another customer’s machine. A run without a ticket — a chat turn, or a scheduled agent with no ticket in context — skips that company scope, so target the device explicitly.
Enabling one RMM does not enable the others. Script execution is granted per RMM. If you enable it on ConnectWise Automate but not on NinjaOne, the agent can run scripts on Automate devices only. When it targets a NinjaOne device it stops and tells the technician that an administrator must enable NinjaOne script execution on that agent first — it will not fall back to another RMM. This matters most when one customer’s machines are split across two RMMs, because the agent picks the device by name and the device decides which RMM the script runs on.
ConnectWise Automate — script priority. Automate runs scheduled scripts by priority (1 lowest, 15 highest). Neo submits Automate scripts at 15 (highest) by default, so remediation runs right away instead of waiting behind lower-priority queued work. To make a specific script yield to your other Automate jobs instead, tell the agent in custom instructions to run it at a lower priority — for example, “run cleanup scripts at priority 5.” Other RMMs ignore this setting.If your Automate server fails the submission with a server-side error, Neo may run the script through Automate’s batch endpoint instead, at the same priority. The agent’s run notes say when that happened.
ConnectWise Asio. Neo runs Asio scripts by scheduling them on the endpoint. The agent reads each script’s parameters and fills them in — including the built-in “PowerShell script” template, whose
body parameter takes an entire ad-hoc PowerShell payload (for example, download an installer and run a silent install). Grant the Automation permission group Read & Write to allow execution. Newly connected or changed scripts expose their parameters after the next RMM sync.How to Configure
1
Connect an RMM that supports script execution
Set up NinjaOne, Datto RMM, or N-Sight.
2
Enable RMM script execution
On the workflow’s Integrations tab, turn on script execution for that RMM.
3
Set approval requirements
Start with Require Technician Approval on for that RMM’s script-execution permission group — the same toggle you used in the previous step. To skip approval for known-safe scripts, add each one under Pre-approved scripts on the same group. Add custom instructions about which scripts to prefer or avoid.
4
Watch the results
Review every run in Executions before widening automation.
