Purpose: Onboarding resources for the migration off NinjaOne (RMM) and onto the in-house stack. Engineers should work through these before the cutover. Deadline context: NinjaOne renews end June — TacticalRMM + ITFlow go live together (devices + ticketing in conjunction).
How to use this: Read the official docs first (they're the source of truth), watch the video walkthroughs for the visual feel, then practise in the live demos before touching production. Tick off the checklist at the bottom.
- Clients → Sites → Agents hierarchy (maps to our 70 clients / their locations / their devices).
- Agent installation methods — the deployment URL + silent install (this is how 350 devices get migrated; ties into the TacticalRMM policy rollout).
- MeshCentral integration — this is the remote-access/remote-desktop piece (the NinjaOne remote-control replacement). Take-over, remote shell, file transfer.
- Automation Policies — checks, tasks, patch policy (the monitoring + patching that replaces NinjaOne's).
- Alerts — how failures notify us.
- TacticalRMM Discord (community support, very active): linked from https://docs.tacticalrmm.com/
- Our own instance:
rmm.xzopiasecure.com (Server 1, live) — use a test client/site, not production, until trained.
- Public demo: https://demo.itflow.org (or via the GitHub repo link) — Username:
demo@demo.com | Password: demo
- Safe sandbox — click around, raise test tickets, build a test invoice, no risk.
- Full setup + Web UI + Admin overview (~50 min, chaptered): search "ITFlow Awesome Open Source" on YouTube — covers Setup Wizard (31:45), Web UI Overview (36:25), Administration Menu (41:45). The install portion is less relevant (ours is already deployed) — skip to ~31:45 for the UI/usage walkthrough, which is the part engineers need.
- ITFlow install video tutorial (forum thread with link): https://forum.itflow.org/d/623-itflow-script-installation-video-tutorial
- Ticket lifecycle: New → (work logged) → Resolved → Closed. Resolved tickets auto-close after 72 hrs (configurable); can be re-opened in that window.
- Clients / Contacts / Assets — how client records, their people, and their kit are structured (this is the documentation side that replaces scattered notes).
- Time tracking on tickets — logging time worked (feeds billing and reporting).
- Billing basics — quotes, invoices, recurring invoices (the accounting side; ties into Xero).
- Client portal — what the client sees when they raise/track tickets.
- Email-to-ticket — inbound email auto-creating tickets (core to daily flow).
- ITFlow public demo first (link above), then our instance
psa.xzopiasecure.com (Server 2, live) with a test client.
ITFlow is the system-of-record for managed (active, paying) clients. Once a client is onboarded, ITFlow owns:
- Company record (name, address, primary contact, contract)
- Operational contacts — billing contact, technical contact, portal-user accounts
- Assets / devices (what kit a client has; ties to TacticalRMM agent records)
- Contracts and SLAs (what service level they're on)
- Tickets (support requests and projects)
- Invoices and billing history
Twenty CRM is the system-of-record for the sales pipeline + relationship layer — prospects, leads, opportunities, deals, pipeline stage, and sales notes. A company that isn't yet a paying client belongs in Twenty, not ITFlow.
Lifecycle handoff: A prospect starts as a Company + People + Opportunity in Twenty. When the Opportunity is Won → the client is onboarded → the canonical operational record moves to ITFlow. Twenty keeps the sales history for that contact.
The one-line test: "Support or billing for an existing client?" → ITFlow. "A prospect, a deal, or the sales relationship?" → Twenty.
There is no automated sync between the two tools yet — it's manual discipline for now.
TacticalRMM handles the machines (monitoring, patching, remote access, alerts). ITFlow handles the work (tickets, time, billing, client records). The link: a TacticalRMM alert auto-creates an ITFlow ticket, an engineer remotes in via TacticalRMM/MeshCentral, fixes it, logs time in ITFlow, and the resolution can later feed an auto-KB article. That's why NinjaOne can't be half-replaced — you need device visibility AND ticketing live at the same time, or engineers are working blind. Both go live together before the NinjaOne renewal.
- TacticalRMM Getting Started + How It All Works docs (30 min read)
- TacticalRMM Front-End Walkthrough video (orientation)
- ITFlow public demo — log in, raise a few test tickets, look at billing (hands-on, ~30 min)
- ITFlow UI walkthrough video (from ~31:45)
- ITFlow Tickets docs — understand the lifecycle properly
- TacticalRMM Agent Installation docs — understand how device migration will work
- Hands-on in our live instances with a test client only — do NOT touch production client data until signed off
- Both tools are source-available/open-source — community support (Discord for TacticalRMM, forum for ITFlow) is the support channel; no vendor hotline. Search docs/forum first.
- Our instances are already deployed and hardened — engineers are learning to use them, not install them, so skip install-focused sections of videos.
- Capture any gaps or "how do I…" questions during training → they become candidates for our own internal BookStack runbooks (
docs.xzopiasecure.com).
Xzopia Limited (NI620366) | Engineer training resources compiled 08 Jun 2026, data-ownership boundary added 15 Jun 2026 | Review before TacticalRMM/ITFlow cutover (NinjaOne renewal end June)
Source of truth is the repo — promote via Claude Code; do not hand-edit in the wiki.