When the agent uses a script
The agent writes a script when your request needs:- The same lookup across many clients, such as “list every open ticket older than 14 days, per client”.
- Counting, grouping, or joining results, such as “how many Microsoft 365 licenses does each client pay for in Pax8 compared to what’s assigned?”.
- A CSV report, such as “export every ConnectWise RMM device with its last check-in time”.
What a script can read
A script can only run a short, reviewed list of read tools:- ConnectWise PSA — ticket lookups and most list reads. Configuration lists are excluded because they can hold passwords.
- ConnectWise RMM — list reads and script task results.
- Pax8 — list and detail reads.
- Microsoft 365 — Microsoft Graph list reads.
Dry runs: nothing changes until you approve
By default, every script runs as a dry run. If the program tries a write, such as adding a ticket note or starting an RMM script, Rallied records the change instead of making it. The agent then lists what would have changed and says plainly that nothing was changed. Scripts can never reset or send credentials. Rallied refuses those calls outright, even in a dry run.Approving a script for bulk changes
After a dry run that recorded changes, the agent asks for one approval for the whole program. This covers every client it touches, instead of one approval per change.1
Ask for the change
Describe the bulk change, for example “add an internal note to every open ticket from Contoso that’s waiting on the customer”. The agent writes the program and dry-runs it.
2
Review the approval card
An Approval request card appears in the chat. It shows:
- The full program, with line numbers. Any script body sent to an RMM (PowerShell or Bash) appears as one readable block.
- Flagged lines — read these twice for lines that need a closer look.
- The write tools and Clients it covers.
- The Validity of the approval.
- An Approval fingerprint that identifies this exact program.
3
Approve or deny
Select Approve script to run it, or Deny to stop it. Only a click on the card counts. Typing “approved” in the chat doesn’t approve anything. The card expires if you don’t decide within one hour.
4
Read the run report
Rallied runs the same program again with its writes turned on. When it finishes, Rallied posts a run report to the chat. The report lists each change per client and tool as done, already done, failed, or unknown. A change counts as made only once the report says done.
Only the person who asked for the script can approve, deny, or revoke it. That applies to platform admins too.
- The approval covers exactly what the card showed. If the program tries another tool or another client, Rallied refuses that write and the program continues. The report lists it as outside the approval.
- Writes are never repeated. If the program runs again, changes it already made are skipped. A change marked unknown might have gone through. Rallied never resends it, so check it yourself.
- Plan Mode pauses the run. If your MSP switches to Plan Mode, the approved script pauses until you return to Execute Mode.
- Revoke at any time. Select Revoke on the card to stop everything that would run under the approval. Deleting the thread also revokes it.
How long an approval lasts
The agent picks a validity based on what you ask for. The card shows the one it picked:Fixing an approved script
If an approved run fails, for example because of a wrong parameter, ask the agent to fix it. The agent dry-runs the corrected program and compares it with the approved one:- If the fix stays within the same tools, clients, and connections, and doesn’t change what is sent to a customer or person, Rallied applies it. Rallied then posts the difference to the chat and the run continues. Changes already made aren’t repeated.
- Otherwise, a correction card shows only what changed. Select Approve correction to apply it.
Recurring scripts
Ask for a schedule to have an approved script run on its own:- The first run starts when you approve. After that, the same program runs each period on fresh data. It picks up new devices and, for approvals covering all clients, new clients.
- Each run posts its own report, including what’s new since the previous run.
- The card lists past runs, and Rallied posts a notice in the thread seven days before the schedule ends.
- A recurring script can’t be run on demand. Select Revoke on the card to stop all future runs.
Scripts that read credentials
ConnectWise RMM task results can contain credentials, such as a BitLocker recovery key or a LAPS password. A script can read these results and save them to a file for you. When it does:- The agent doesn’t see the script’s output. It gets only the status, file names, and row counts.
- The same applies if Rallied finds a credential anywhere in a script’s output.
- The file is encrypted, only you can download it, and Rallied logs every download.
- Rallied deletes the file after 24 hours.
Downloading files from Chat
Every file the agent shares appears as a file card under its message. This includes script CSVs and files the agent creates during the conversation. Select the download button on the card to save the file. The Files menu lists every file shared in the thread. Files are only available to the person who owns the thread. They’re kept for 30 days. Sensitive files are kept for 24 hours and labeled on the card:
If a file contains one of Rallied’s own platform secrets, Rallied withholds it and doesn’t store it.
Limits
If a script runs out of time, Rallied keeps the files written so far and marks them partial. Ask the agent to split the work into fewer clients per run.
Related
- Chat with your agent — where you ask for scripts and approve them.
- Approval settings — the same tool policies apply to every script call.
- Plan Mode — pauses approved scripts for your MSP.