# Add a Pay Now button
Source: https://help.gorelo.io/add-a-pay-now-button
Add a Pay Now button to Gorelo invoices that links to QuickBooks, Xero, or a custom payment URL so clients can pay invoices instantly online.
Add a "Pay Now" button on invoices.
For example, "Standard".
Toggle on **Show Pay Now**.
Select either:
* QuickBooks/Xero (based on your accounting integration): this option embeds the native payment link, which takes the user to QuickBooks or Xero respectively.
* Custom Link: this option allows you to use a custom URL with variables for the Invoice Number `{{invoicenumber}}` and Total Amount `{{totalamount}}`. For example: [**Benji Pays**](https://support.benjipays.com/support/solutions/articles/150000181442-custom-payment-links-for-any-psa-or-erp-crm)
All Invoice PDFs generated with the selected template (Standard) will now show a ‘Pay Now’ button that’s linked to your chosen method.
# How alerts work
Source: https://help.gorelo.io/alerts-overview
Learn how Gorelo alerts surface asset, uptime, and script issues so you can create tickets, dismiss occurrences, and subscribe to critical notifications.
[Agent Assets](/group-assets-with-tags), [Uptime](/create-an-uptime-check), and [Scripts](/write-and-test-a-script) are all capable of generating Alerts. Once Gorelo generates an Alert, you can either:
1. Create a ticket from it.
2. Dismiss the particular occurrence of the alert.
## Use alerts
Use a sample command to test alerts.
Use generated alerts to create a ticket.
Dismiss from the alert menu.
Filter data using alerts.
# Other ways to deploy the Gorelo Agent
Source: https://help.gorelo.io/alternatives-to-deploy-the-gorelo-agent
Deploy the Gorelo Agent using third-party tools like ImmyBot, Action1, and NinjaOne for environments where PowerShell or manual installs aren't an option.
Select Installer **Type = None**.
* Select **Add version to new software**.
* Under **Software Info**, add:
* Name = Gorelo
* Select **Custom Detection Script**.
* Add a **New** script with the default settings.
```powershell theme={null}
$registryPath = "HKLM:\SOFTWARE\Gorelo"
$valueName = "AgentVersion"
try {
$version = Get-ItemPropertyValue -Path $registryPath -Name $valueName -ErrorAction Stop
Write-Output $version
} catch {
Write-Error "Unable to read version: $($_.Exception.Message)"
exit 1
}
```
* Select **Custom Detection Script**.
* Add a **New** script and paste the Agent Asset [**installation command**](/install-the-gorelo-agent) from your Gorelo tenant.
* Version String = 8.42.0.0
Add this new software to your deployments page and then adopt the asset in Gorelo. Use a specific client/location installation command to skip the adoption requirement.
You can use a provisioning package to wipe Windows and install fresh with the Gorelo Agent.
1. Navigate to the [**Asset List**](https://app.gorelo.io/Asset/asset-list)
2. Click **+ Assets** in the top right and then **Agent Asset**.
3. Select Client/Location (optional) and then **Request Agent.**
4. Copy the PowerShell script and save it somewhere as `GoreloInstall.ps1`.
1. Install [**Windows Configuration Designer**](https://apps.microsoft.com/detail/9nblggh4tx22) from the Microsoft Store.
2. Open Windows Configuration Designer and select **Provision desktop devices**.
3. Enter the project **name**, choose a location for the project folder.
4. Click **Finish.**
5. Follow the Wizard and configure anything you feel necessary.
6. Enter the **Device name**, toggle on **Remove pre-installed software** (wipes the device).
7. Click **Next.**
8. Enter **Set up network** details or toggle off for wired connections only — and click **Next.**
7. Select **Local Admin** and enter details.
8. Click **Next**.
9. Add an application with the below details:
* **Application name**: Gorelo Install
* **Installer path**: Browse to the previously created GoreloInstall.ps1
* **Command line arguments:**
`powershell.exe -executionpolicy bypass -file "goreloinstall.ps1"`
10. Click **Next**.
11. Click **Add**.
12. Click **Next**.
You can use Intune to deploy the Gorelo Agent after Autopilot has completed its run.
1. Navigate to the **[Asset List](https://app.gorelo.io/Asset/asset-list).**
2. Click **+ Assets** in the top right and then **Agent Asset**.
3. Select Client/Location (optional) and then **Request Agent.**
4. Copy the PowerShell script and save it somewhere as `GoreloInstall.ps1`.
1. Open [**Intune**](https://intune.microsoft.com/) and log in with a Global Administrator account.
2. Navigate to **Devices** in the left menu and then **Manage devices** > **Scripts and remediations.**
3. Select the **Platform scripts** tab at the top.
4. Click the **+ Add** button and select Windows 10 and later.
* **Name**: GoreloInstall
5. Click **Next.**
* **Script location:** upload the GoreloInstall.ps1 script.
* **Run this script using the logged on credentials**: No.
* **Enforce script signature check**: No.
* **Run script in 64 bit PowerShell Host**: Yes.
6. Click **Next**.
* **Included groups**: Select the specific groups.
7. Click **Next**.
8. Review the details and click **Add**.
# Antivirus tab shows old entries
Source: https://help.gorelo.io/antivirus-tab-shows-old-entries
Clear stale antivirus entries from the Gorelo Antivirus tab by removing remnants in the Windows Security Center using WBEMTEST and PowerShell.
## Problem
You’ve uninstalled the old antivirus and yet it continues to show in the antivirus tab.
## Solution
Remnants of the old antivirus are still in the Windows Security Center. Follow these steps:
1. Open an elevated PowerShell window
2. Run the WMI tester command
```powershell theme={null}
WBEMTEST
```
3. Click **Connect.**
4. Enter `root/securitycenter2` in the Namespace field and click **Connect.**
5. In the **IWbemServices** section, click **Query**.
6. Input `SELECT * from Antivirusproduct` and click **Apply.**
7. Double-click the object and scroll down to **displayName** to see the AV name.
8. Delete the old objects.
# Approve and invoice
Source: https://help.gorelo.io/approve-and-invoice
Review and approve time entries and products in Gorelo before they flow onto a contract or invoice, then bill clients accurately for all completed work.
## Time entries and products
You land on the **Waiting to Approve** tab, which shows everything that needs approval before flowing to a contract or invoice.
After that, click **Approve** when you’re happy with everything on the ticket.
Tips!
* The **Contract** column will show **(N/A)** if it’s not associated with a contract and is just using default labor rates.
* The Work Type will show in red if the time entry is outside of your configured Business Hours.
* You can partially bill for time and products on Unclosed tickets by toggling on ‘Show Unclosed’ up the top-right of the **Waiting to Approve** screen.
You see everything that has been approved and is waiting to be added to an invoice.
Choose either:
* individual tickets
* all tickets for a client
Use it to:
* **Generate Invoice**: this will create a new invoice with the selected ticket time/products.
* **Add to Invoice**: this will allow you to select an existing invoice and add the selected ticket time/products.
* **Write off**: this will write off the ticket time/products and no invoice will be generated.
Fill in the details and either:
* Click **Save** to generate a draft invoice.
* Toggle **Approve and Send** if you’d like to create an approved invoice and send to the selected contact.
To send an invoice, the client must have **Billing Contacts** set. If this isn't set, you can add one from the invoice:
1. On the invoice, click the client’s name
2. From the **Location** table, click the **three dots** icon and then click **Edit location**.
3. In the **Billing Contacts** field, select an existing contact or add a new one.
4. Save and go back to your invoice to send it.
# Assign a contact to a client
Source: https://help.gorelo.io/assign-contact-to-client
Automatically associate inbound emails and tickets with the right client in Gorelo using email address rules, contact mappings, and domain assignments.
Inbound emails that generate tickets can be automatically associated with a client (and location) using different methods. These methods apply in the following order of priority.
## Associate tickets with email addresses
You can automatically associate tickets with a client directly from the email address settings. Any email sent to this address will create a ticket associated with the selected client.
1. Navigate to **Settings** > **Email** > [**Settings**](https://app.gorelo.io/admin/admin-settings#email#settings).
2. Edit the desired email address.
3. Expand the **Automatically Apply** section.
4. Select the client.
5. Click **Save**.
## Associate tickets with contacts
You can automatically associate tickets with a client based on a contact’s email address.
1. Navigate to the **[Contacts list](https://app.gorelo.io/crm/contact-list).**
2. Click **+ Contact** up the top right.
3. Fill in these details:
* **First Name**
* **Primary Email**
* **Client**
4. Click **Create**.
When an email arrives from the specified **Primary Email** (or alias), Gorelo creates a ticket associated with the chosen client. If the contact has a location specified, Gorelo will automatically associate the ticket with that location as well.
## Associate a domain with a client
The simplest and most common method is to associate an entire domain with a client. All incoming emails from that domain will be associated with the specified client.
1. Navigate to the **[Clients list](https://app.gorelo.io/crm/client-list).**
2. Edit the relevant client.
3. In the ‘Domains’ section (right side), click **+ Domain**.
4. Enter the domain name, then click **Add**.
[**Stripped domains (unassociated senders)**](/stip-contacts-from-a-domain) override all previous associations. Emails from these domains will not be associated with any client or contact when tickets are created.
# Schedule tickets creation
Source: https://help.gorelo.io/automated-ticket-schedule
Schedule tickets in Gorelo to be created automatically on a daily, weekly, or monthly cadence with preset titles, groups, actions, and client assignments.
1. Navigate to Settings —> Automation —> [**Scheduled Tickets**](https://app.gorelo.io/Admin/admin-settings#automation#scheduledtickets)
2. Click ‘**+Automation Rule**’ in the top-right
3. Enter the details you want on the resulting ticket:
* **Title**: this will be the title of the ticket
* **Group**: this will be the default assigned group and govern visibility/permissions
* **Description**: this will appear as a private comment on the ticket (optional)
* **Actions**: these are additional actions such as assigning users, checklists, tags and more (optional)
* **Client Selection**: this allows you to select which clients the ticket will be automatically created for
* **Schedule**: this sets the cadence of either daily, weekly or monthly
Tips!
* Run Time is based on the organization Time Zone
Settings → General → [**Organization**](https://app.gorelo.io/Admin/admin-settings#general#organization)→ Business Hours
# Automate tags on tickets
Source: https://help.gorelo.io/automated-ticket-tags
Use Gorelo AI to automatically apply up to three tags to new tickets based on the subject and first inbound comment, eliminating manual tagging work.
Auto Ticket Tags will look at a ticket’s subject and first inbound public comment, then pick up to three tags you’ve nominated as AI tags. It takes the guesswork out of organizing new tickets so you can stay focused on the real work without worrying about manual tagging.
## Enable auto ticket tags
1. Go to **Settings → AI → Auto Ticket Tags**
2. Toggle **Auto Ticket Tags** on
3. Select the tags you want evaluated by AI
4. Select how many tags you want suggested: 1, 2, or 3
5. If you want tags to apply themselves automatically, toggle on **Apply Tags**
## How it works
* AI looks at the ticket’s subject and first inbound public comment
* It compares that info against the name and description of any tags you’ve nominated
* You can create or edit tags under **Settings → Tags → Ticket Tags**
## Create tags for AI use
1. Head to **Settings → Tags → Ticket Tags**.
2. Click **Create a Ticket Tag** (if you need a new one) or **Edit** (if you’re changing an existing tag).
3. Enter the tag name and description (emojis are supported)
4. Check **Mark as AI tag** so it can be picked up by the Auto Ticket Tags feature.
5. Save your changes.
* Keep your tag titles and descriptions clear and specific. It helps the AI match them more accurately.
* If you’re trying to test how the AI will tag, just send a test ticket with a relevant subject and comment to see if it picks the right ones.
## Example tags
| **Name** | **Description** |
| :---------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Access | User access related requests including password resets, account creation/deletion, or permission changes. Examples: forgotten passwords, new user setup, or access denied messages. |
| Backup | Data backup and recovery related issues including failed backups, restore requests, or backup system alerts. Examples: backup failure notifications, file restore requests, or backup storage capacity issues. |
| Email | All email-related issues including Microsoft 365, Exchange, spam filtering, signatures or email client issues. Examples: cannot send/receive emails, missing emails, mailbox quota issues, or Outlook problems. |
| Mobile | Mobile device issues including phones, tablets, MDM, or mobile app problems. Examples: cannot sync email on phone, MDM enrollment issues, or mobile app failures. |
| Network | Issues related to internet connectivity, WiFi, switches, firewalls, routers, VPN connections, or network performance issues. Examples include: slow internet, cannot connect to WiFi, VPN disconnecting, or network outages. |
| Print/Scan | Issues with network printers, local printers, multi-function devices, and scanning equipment. Examples: cannot print, print quality problems, printer offline, scan failures, or driver issues. |
| Security | Security-related incidents, alerts, or requests including virus infections, suspicious activities, security policy changes, or compliance matters. Examples: virus alerts, suspicious emails, ransomware, or security policy violations. |
| Server | Issues involving physical or virtual servers, including performance problems, services not running, server hardware failures, or server maintenance. Examples: server offline, service crashes, disk space alerts, or slow server response. |
| Software | Issues with business applications, software installations, updates, Microsoft Office like Word/Excel, or licensing. Examples: application errors, software not working, update failures, or license activation issues. |
| Voice | Issues with VoIP phones, phone systems, PBX, softphones, and video conferencing. Examples: phone not registering, poor call quality, voicemail, or conference room systems. |
| Web | Issues with websites, DNS, domains, SSL certificates, and hosting. Examples: site down, certificate expired, DNS errors, or domain renewals |
| Workstation | Desktop and laptop computer issues including hardware failures, operating system problems, or performance issues. Examples: blue screens, slow computer, hardware not working, or Windows updates. |
# Automatically assign a ticket type
Source: https://help.gorelo.io/automated-ticket-types
Use Gorelo AI to automatically assign the most relevant Ticket Type based on a ticket's subject and first inbound public comment for faster sorting.
Auto Ticket Types help you cut through the noise and sort tickets faster. It looks at the subject and first inbound public comment, then picks the most relevant ticket type — automatically.
You need to enable [**Ticket Types**](/sort-with-tickets-types) before you can use the AI feature.
## Turn on auto ticket types (via AI)
1. Navigate to **Settings → AI →** [**Auto Ticket Types**](https://app.gorelo.io/admin/admin-settings#ai#types)
2. Toggle **Auto Ticket Types** on
3. Select the Ticket Types you would like to be assigned automatically
4. Click ‘Update’
## How it works
* AI checks the **ticket subject** and **first inbound public comment**
* It compares the wording to the **name and description** of the types you’ve selected
* The best match gets picked
- Use distinct names and descriptions so the AI can tell them apart easily
- Want to test it? Just submit a dummy ticket with a realistic subject/comment combo and see what type it picks
- If you’ve got similar types, tweak the descriptions to make them more specific
# Reuse tasks with checklist templates
Source: https://help.gorelo.io/checklists
Save recurring task steps as reusable checklist templates in Gorelo projects to standardize onboarding, hardware setup, and other workflows.
Technical Preview
Project tasks in Gorelo can contain checklists that help you break down complex, multi-step engagements into granular, manageable actions. Once you create a checklist, you have the option to save it as a template to reuse it in another task or project. To do so, follow these steps:
## Requirements
* [A Gorelo subscription](https://www.gorelo.io/pricing/)
* [An existing project](/create-a-project) with a task in it
Select a recurring task you need to complete, like:
* A client onboarding
* A hardware configuration
* An organization setup
* A new user enrollment
## Create the checklist template
From the project's dashboard (**TABLE** or **BOARD**), click the task's name to open the details.
From the tabs menu, expand the additional options by clicking the **+** icon.
Fill in the following fields:
* **Name:** The name of this checklist.
* **Template:** Leave it blank.
Click **Save**.
Add a first item with the following fields:
* **Item:** What to do. Can be text, URLs, and contain emojis.
* **Assignee** (optional): Who has to do the action.
* **Due date** (optional): The deadline for the action. Leave it empty to reuse the checklist later.
Press **Enter** or click the **✓** icon to save it, then add another item.
Once you complete the items list, click the icon to save this checklist. Fill in the following fields:
* **Name**: The name of the template
* **Visibility**: Who can access the checklist. Select between:
* **Public**: The client can access it from the project.
* **Private**: Only you and your team can access it.
Once you save the checklist, the **Checklist** menu displays it in your checklist templates list when you create another task. You can add this template to the task in one click instead of inputting the items manually.
## Save the project as a template
You can save the entire project as a template in a similar way. Project templates help you standardize workflows and deliver consistent service across clients. To do so:
* Navigate to your project's dashboard.
* Click the three dots menu.
* Select **Save as a template**.
Next time you create a project, you can select this template to have an entire multi-step process ready to be tracked and completed.
Gorelo ships predefined **checklist** templates that appear alongside your custom ones when you add a checklist to a task. **Project** templates are not prebuilt. They only exist after you or a teammate saves a project as a template using the steps above.
# Client Portal
Source: https://help.gorelo.io/client-portal
Use the Gorelo Client Portal to communicate with clients, share updates, and give them visibility into projects, tickets, and documents you manage.
The **Client Portal** in Gorelo is a self-service interface that gives your clients transparency and direct engagement with your services. Clients manage their own support needs, which reduces manual communication for your team.
## Core capabilities
* **Ticket management:** Clients can view their existing tickets or submit new ones directly through the Client Portal. Gorelo enhances real-time engagement with features like the " is typing" indicator.
* **Project visibility:** You can share project progress and basic information with clients by using the **Share with field** on the Project detail page.
* **Resource access:** If you share a [document](/documents-overview) in the Client Portal, clients can access it there.
* **Financial and usage tracking:** Clients can see their [invoice](/invoices-overview) list, check for "Awaiting payment" statuses, and view remaining [block or limited hours](/set-a-labor-rate).
* **Quick Connect downloads:** Clients can download your remote management tools directly on their machines.
## Authentication and security
* **Access methods:** End users can authenticate via Microsoft 365 SSO or by receiving a magic link via email.
* **Registration:** To log in, the user's email address must already be registered as a **contact** in your Gorelo tenant.
* **Secure links:** For quick access to specific items, you can generate public doc links that allow anyone with the URL to view a document without needing to authenticate.
## Extended visibility via contact tags
You can grant clients access to specific reports and data sets by applying predefined contact tags to their records:
* `Portal - All Assets`: Allows the contact to view the asset summary report, including device health and warranty stats.
* `Portal - All Tickets`: Grants access to the [ticket summary report](/summarize-ticket).
* `Portal - All Invoices`: Allows the contact to see all organization invoices rather than just those sent to them individually.
## Customization and UI
You can customize the Client Portal from **Settings** > **Portal** with the following options:
* A custom URL (contact Gorelo support to activate this option)
* Custom branding colors and favicons
* Default light or dark mode
## FAQ
You can't use the magic link option if your client's email address isn't yet registered as a contact in Gorelo. Add the contact connected to the client, then try again.
The portal only supports English.
# How contacts work in Gorelo
Source: https://help.gorelo.io/contacts-overview
Contacts represent the people at your client organizations in Gorelo. Learn how contacts link to tickets, approvals, emails, and the Client Portal.
## What are contacts useful for
Use contacts in Gorelo to manage:
* Communication around tickets
* Asset associations
* Invoice recipients
* [Client Portal](/client-portal) permissions
## Create and synchronize contacts
You can import contacts in Gorelo and synchronize them with external tools such as:
* **[M365 & CyberDrain Improved Partner Portal (CIPP) Sync](#microsoft-365-sync-via-cipp):** Syncs licensed M365 users into Gorelo.
* **Manual and CSV files:** Manually add contacts or bulk import them from a CSV file.
* **API:** Send POST or PATCH requests to the `https://api..gorelo.io/v1/contacts` [Gorelo API](/api-overview) endpoint.
When an unknown sender emails your support address, Gorelo automatically attempts to create a new contact record for them by parsing their name from the email headers. If Gorelo can't identify a last name from an incoming email, it leaves the last name field blank, keeping your contact database clean from duplicate names.
## Import contacts
You can import your existing contacts as a CSV file in **Settings** > **Import** > select **Contacts**. To do so, the CSV must fulfill the following requirements:
* The [client associated with each contact](/assign-contact-to-client) in the CSV file must already exist in Gorelo.
* The client names in the CSV must match exactly the client names in Gorelo.
* Client names in Gorelo must be unique.
* Gorelo limits each import to a maximum of 1000 contacts.
## Microsoft 365 sync via CIPP
Gorelo integrates Microsoft 365 via CyberDrain Improved Partner Portal **(CIPP)** to automate directory management and streamline contract billing.
To set this up, configure API credentials within Gorelo’s integrations settings, such as:
* Tenant ID
* Application ID
* Secret
* API URL
Once active, Gorelo runs an automatic sync every 24 hours.
Follow the CIPP guide to generate your credentials:
Create an API client, generate credentials and sync with Gorelo.
Gorelo's CIPP integration targets users with active, billable software licenses in Microsoft 365. The following list describes which users are included in the sync and which ones aren't:
* **Synced (Licensed):** Any end user assigned an active Microsoft 365 license (such as Microsoft 365 Business Premium or Exchange Online P1) automatically pulls into Gorelo as an active contact under their respective client organization.
* **Excluded (Unlicensed):** The native CIPP sync ignores unlicensed mailboxes (shared mailboxes, aliases) and doesn't create any separate contact.
### Dynamic quantities and contacts
Gorelo restricts native syncing to licensed users to fuel [Dynamic Quantities](/track-unbilled-items-with-dynamic-quantities) in your client contracts.
By syncing licensed seats via CIPP, you can configure mapping rules in your contracts that automatically calculate billing based on active users. Consider the following scenario:
1. A client hires a new employee and assigns them an M365 license.
2. CIPP syncs the user into Gorelo.
3. Gorelo automatically increments the contract seat count on your next billing run.
This directly prevents untracked user additions and reduces the time you would spend manually auditing license counts at the end of the month. Additionally, Gorelo supports multi-selecting CIPP/M365 criteria to aggregate unique contacts into a single billable item.
## FAQ
Yes. You can manually merge these two records within Gorelo. The native CIPP sync keeps updating the primary licensed contact without overriding or breaking the merge.
Yes. CIPP pulls both in as separate contacts. You can safely merge these duplicates in Gorelo to keep ticket histories unified under a single contact record.
Yes. You can manually create a contact record for that address.
# Could not create SSL/TLS secure channel
Source: https://help.gorelo.io/could-not-create-ssl-tls-secure-channel
Fix the PowerShell 'Could not create SSL/TLS secure channel' error by enabling TLS 1.2 in your session or system-wide for Invoke-WebRequest scripts.
## Problem
When running a PowerShell script that uses `Invoke-WebRequest`, the following error may appear:
```powershell theme={null}
Invoke-WebRequest : The request was aborted: Could not create SSL/TLS secure channel.
```
This occurs because the script is attempting to connect to a server using secure protocols (TLS/SSL), but the required protocols (like TLS 1.2) are not enabled on the system.
## Solutions
To quickly fix this issue in the current session, you can enable the necessary protocols by running the following command in your PowerShell session:
```powershell theme={null}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls11 -bor ` [Net.SecurityProtocolType]::Tls12 -bor ` [Net.SecurityProtocolType]::Tls -bor ` [Net.SecurityProtocolType]::Ssl3
```
However, this fix is temporary and needs to be reapplied in every new PowerShell session.
To permanently resolve this issue and ensure all .NET-based applications, including PowerShell, use secure protocols by default, update the system registry.
### Steps to Fix:
1. Open an **elevated PowerShell session** (Run as Administrator).
2. Run the following commands to update the registry:
```powershell theme={null}
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319" -Name "SchUseStrongCrypto" -Value 1 -Type DWord
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319" -Name "SystemDefaultTlsVersions" -Value 1 -Type DWord
```
3. Also apply the changes to the 64-bit .NET Framework registry key:
```text theme={null}
Set-ItemProperty -Path "HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319" -Name "SchUseStrongCrypto" -Value 1 -Type DWord
Set-ItemProperty -Path "HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319" -Name "SystemDefaultTlsVersions" -Value 1 -Type DWord
```
4. Restart the system to ensure the changes take effect.
## Explanation of registry keys
| Registry Setting | Description |
| ---------------------------- | -------------------------------------------------------------------------------------------------------- |
| **SchUseStrongCrypto** | Forces the .NET Framework to use strong cryptographic protocols (e.g., TLS 1.2). |
| **SystemDefaultTlsVersions** | Ensures .NET applications use the system-default TLS version, allowing them to adapt to newer protocols. |
## If the error persists
If the error persists, consider the following actions to ensure secure connections for all .NET applications without requiring manual intervention in each session:
* Ensure your system supports TLS 1.2 and that it is enabled in the operating system.
* Upgrade to PowerShell Core or PowerShell 7, which default to modern security protocols.
# Create a separate conversation on the same ticket
Source: https://help.gorelo.io/create-a-new-thread
Use Third-Party Conversations in Gorelo to start a separate email thread on the same ticket, keeping vendor communication organized without exposing the client.
Create a Third-Party Conversation to start a new email thread while keeping it on the same ticket for context. For example, contact LOB application support for a client without losing the ticket history.
This creates a new conversation thread, separate from the Public thread. With a new Third Party Conversation thread, you don't include the recipients (in To/Cc) previously included in the ticket.
## Create a third-party conversation
1. Create or navigate to an existing ticket
2. Click the **+** button in the timeline tab and add a **Third Party Conversation**
3. Search from existing contacts or type a name/email
* (Optional) Add Cc’s via the ‘Add more detail’ dropdown
* Public comment thread can be added via the ‘Add more detail’ dropdown
1. Click ‘**Save**’
2. Type your email in the expanded **Third Party Conversation** comment box and click ‘**Post**’ (note the purple tab color)
## Thread visibility
Threads have different visibility levels:
* **Private:** visible only by you and your team from the Gorelo admin interface.
* **Public:** visible by your contact by email.
* **Thread:** visible by a third party by email.
# Create a project
Source: https://help.gorelo.io/create-a-project
Create a project in Gorelo to organize multi-step client work with tasks, timelines, and collaboration. Set the client, contract, dates, and team owners.
Technical Preview
This tutorial guides you through creating a new project from scratch.
## Requirements
* [A Gorelo subscription](https://www.gorelo.io/pricing/).
* [An existing client](/assign-contact-to-client).
* [A project lead added to Gorelo](/quickstart#set-up-your-organization) (if it isn't you).
From the [Gorelo app](https://app.gorelo.io/), open the lateral menu and click **Projects**. The section displays a list of all projects in Gorelo. To add a new one, click **+ Project**.
* **Title**.
* **Description** (optional).
* **Client**: select from the drop-down menu.
* **Location**: automatically filled according to the selected client, edit it as needed.
* **Lead**: select from the drop-down menu to assign someone from your team who's in charge of the project.
* **Type**: select from the drop-down menu.
* **Tags** (optional): select a tag from the list.
* **Group**: select who Gorelo will notify of the project's updates.
Click **Create**. Gorelo now displays your project's empty dashboard.
From the project right-hand lateral menu, add a due date for this project. From this menu, you can also change the project's details as it evolves.
Navigate to the **TABLE** tab. You can choose how Gorelo displays the project dashboard.
Sections can be useful to group tasks by scope or areas. If you need custom sections, click **+ ADD SECTION.** Add as many sections as you need for this project.
If you prefer to see the project's tasks by statuses, click **Group by** and select **Statuses**. The sections now automatically group tasks by statuses.
Under the relevant section/status, click **Add task** and fill in the following fields:
* The task title.
* The section/status for the task.
* One or more assignees (optional).
* A due date (optional).
* The priority level (select **No Priority** if it doesn't apply).
* Click the disk icon to save the task.
Add the task to your calendar:
1. Click the task to open it.
2. Navigate to the right-hand menu and scroll to the bottom.
3. Click **ADD TO CALENDAR**.
## Next steps
Now that you have the basic project structure ready, learn how to set up task details and save the project as a template for future reuse:
Learn how to create and use checklists to ease task completion for you and your team.
Create and save project templates for recurring projects like onboarding, offboarding, and security audits.
# Create an approval workflow
Source: https://help.gorelo.io/create-an-approval-workflow
Set up approval workflows in Gorelo using Contact Tags marked as approvers so clients can approve purchases, access requests, and other ticket actions.
Use approvals when you need a contact to approve something, such as a new laptop purchase or access to a specific SharePoint site.
To designate an individual contact at a client as an approver, assign them a Contact Tag that is ***marked as an approver***.
## Create an *Approver* tag
1. Navigate to Settings > [**Tags**](https://app.gorelo.io/Admin/admin-settings#tagmanagementsettings) > Contact Tags.
2. Create a **Contact Tag** (down the bottom).
* **Name**: this is the name of the tag (for example, ‘✅Special’).
* **Mark as Approver**: this is where you will configure it as an Approver tag, tick this box.
* **Description**: this is where you can describe the tag in more detail. It’s internal and only visible here.
## Designate a contact as an approver
1. Navigate to the **[Contact list](https://app-preview.gorelo.io/CRM/contact-list).**
2. Click the Contact you wish to designate as an Approver.
3. From the **Contact Tags** dropdown, select the newly created ‘✅Special’ tag.
4. In the **Description** field, describe anything extra related to what they can/can’t approve (or leave blank), e.g., *can only approve Engineering related requests.*
5. Click **Update**.
## Start the approval flow
1. Create or navigate to an existing ticket (make sure the client has at least one contact with an Approver tag).
2. Click the **+** button in the timeline tab and add an **Approval**.
3. Select one or multiple contacts that you’d like to email.
4. Type the approval comment.
5. Click **Submit** to send the email.
The selected Contacts will receive an email with the comment you typed and **YES/NO** buttons to approve or deny the approval request.
# Create an uptime check
Source: https://help.gorelo.io/create-an-uptime-check
Create ICMP, HTTP, or TCP uptime checks in Gorelo to monitor websites and connections, with custom check frequency, regions, rechecks, and alert tags.
Gorelo can check internet connections via ICMP and websites via HTTP to alert you when they’re offline. To create an uptime check:
1. Navigate to **[Uptime](https://app.gorelo.io/Asset/check-list)** from the main menu.
2. Click **+Uptime** in the top right.
3. Fill each required field:
* **Type**: pick from ICMP (ping), HTTP or TCP
* **IP/URL**: specify the IP or URL you want to check
* **Client and Location**: associate the check with a Client and Location
* **Description**: give the check a description (optional)
* **Check Frequency**: how often the check will run (in minutes)
* **Rechecks**: how many times the recheck will run after initial failure but before it alerts (every 15 seconds)
* **Region**: where the check will come from. Options are Seattle, Sydney, UK, and Frankfurt.
* **ISP Connection Link**: an external URL that works as a quick shortcut from the list and ticket detail (optional)
* **Tags**: an easy way to categorize and group checks (optional)
4. Click **Add** at the bottom.
\
**Dedicated IP addresses**
* Seattle: `4.155.147.168`
* Sydney: `4.197.194.140`
* London: `52.151.97.9`
## Choose a check type when ICMP is blocked
If the target router or firewall has "respond to ping" disabled, an ICMP check reports as offline even when the connection is up. Use one of these check types instead:
* **TCP**: point the check at an IP or hostname reachable through the network, and a port that is open and listening (for example, a device or service behind the router).
* **HTTP**: point the check at a public URL that returns a successful response.
## Automatically adopt agent asset via uptime
Gorelo can automatically adopt generic agent assets based on the WAN IP when they first check in. If this WAN IP is in Gorelo as an uptime check and **Adopt Client Assets** is toggled on, Gorelo automatically adopts these assets under the appropriate client/location.
# Create an expiration rule for tickets
Source: https://help.gorelo.io/create-expiration-rule
Create expiration rules in Gorelo to generate alerts when domains, warranties, or contracts approach expiry, with multiple thresholds and client filters.
You can create expiration rules to alert when certain things are expiring: domains, warranty, and contracts.
1. Navigate to Settings —> Automation —> [**Expirations**](https://app.gorelo.io/admin/admin-settings#automation#expirations)
2. Click ‘**+Add Expiration**’ in the top-right
3. Enter details to configure the expiration rule:
* **Title**: this will be the name of the rule (does not appear in the alert)
* **Expiration Type**: this determines what date field the rule applies to such as
domains, warranty, and contracts.
* **Client Selection**: this allows you to include/exclude which clients the rule will apply to
* **Hardware Type**: this is only for the Warranty Expiration type and allows you to filter by specific hardware types
* **Add Alert**: this allows you to add multiple thresholds for generating an alert based on days remaining
Tips!
* Alerts will trigger based on the organization Time Zone\
(Settings → General → [**Organization**](https://app.gorelo.io/Admin/admin-settings#general#organization)→ Business Hours)
* 12:00 AM – Asset Warranty
* 1:00 AM – Domain Expiration
* 2:00 AM – Contract Expiration
# Create a form
Source: https://help.gorelo.io/create-form
Create a form in Gorelo to capture client information, build it with question and answer blocks, mark required fields, and publish it for self-service use.
To create a form:
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu.
2. Click **Create form** down the bottom-left.
3. Give the form a title (this is what the client will see).
4. Create a new field block by clicking the + button or typing `/`.
5. Select **Question + Short Answer.**
6. Give the field block a title of **First Name.**
7. Click the **required** toggle to make this field mandatory.
8. Click **Save** up the top right.
9. Click **Preview** up the top right to see what the form will look like.
10. Click **Go Back** up the top right to navigate back to the Form editor and continue with additional fields.
# Create a structured document
Source: https://help.gorelo.io/create-structured-document
Create a structured document template in Gorelo with question-and-answer fields, then generate consistent entries for printers, racks, applications, and more.
A structured document comes in two parts — the structured document template and the entries it generates. You first need to create a template before you can generate entries from it.
## Create a structured document template
1. Navigate to **Settings** > **[Documents](https://app.gorelo.io/Admin/admin-settings#documentstructure).**
2. Click **Create structured document** down the bottom-left.
3. Give the Structured Document a title (this will be used as the name in the left menu and supports emojis).
4. Build out your structured document template with question/answer fields by typing ‘/’ or clicking the + button on hover.
5. Select the fields you’d like to show in the list of entries.
6. Select a field you’d like to use as the title of the entry.
7. Click **Save** up the top-right.
**Tips!**
* The Question name becomes the title of the column
* The little star in the top-right corner of the field will make it a required field
* Assets/Contacts/Documents/Uptime fields will allow you to select existing items for the associated client
* Conditional Logic allows you to show/hide fields
* The 3-dot menu allows you to restore previous versions of the structured document template
## Structured document entry
1. Navigate to [**Documents**](https://app.gorelo.io/Document/document-list) in the main menu.
2. Set your **Client Focus**.
3. Select your **Structured Document** title from the left menu.
4. Click **New** to create an entry.
5. Fill in the required fields and click **Save.**
6. You will now see a new entry in the list.
# Automatically solve and close
Source: https://help.gorelo.io/create-ticket-shortcut
Build Ticket Shortcuts in Gorelo to automate repetitive actions like canned responses, solve-and-close workflows, and project baselines from one click.
Ticket Shortcuts keep things consistent and save time by automating actions. You can use Ticket Shortcuts for something as basic as a canned response or even something more complex like a project baseline.
## Create a ticket shortcut
1. Navigate to **Settings** —> **Tickets** —> [**Shortcuts**](https://app.gorelo.io/Admin/admin-settings#ticket#shortcuts)
2. Click ‘**Add Shortcut**’ up the top-right
3. Fill in the necessary fields:
* **Name**: this is the name of the shortcut and will be used to search for it (on the Ticket Detail)
* **Description**: this is where you can describe the shortcut in extra detail. It will show when hovering the ℹ️ icon next to the name when searching for it (on the Ticket Detail)
* **Visibility**: this defines who can see/use the shortcut
* **Public**: everyone in your organization
* **Private**: only you
* **Groups**: only users in the specified groups
4. Add the **Actions** (see examples below)
5. Click ‘**Create**’
## Example: Solve and close a ticket
* Immediately mark as **Solved**
* Immediately insert **public comment** draft
* Wait 72 hours
* Mark as **Closed** (if the ticket hasn't recieved any public comment)
# Create a ticket from an alert
Source: https://help.gorelo.io/create-tickets-from-alert
Convert a Gorelo alert into a ticket from the Alerts list so technicians can investigate the issue, track resolution, and bill any associated work.
1. Navigate to the [**Alerts List**](https://app.gorelo.io/Alert/alerts) from the main menu.
2. In the Everything view, you should see the newly generated alert with the following details (but a different asset name):
([**Generate a test alert**](/generate-a-test-alert) if you do not see anything).
3. Click the **Create Ticket** button on the far right:
4. Fill in the appropriate details and click **Create**.
# Create an unstructured document
Source: https://help.gorelo.io/create-unstructured-document
Create a free-form unstructured document in Gorelo for how-to guides and notes, with formatting, attachments, headings, and nested document hierarchies.
1. Navigate to [**Documents**](https://app.gorelo.io/Document/document-list) in the main menu
(These are your internal organization documents and do not belong to any specific client)
2. Click ‘Create a document’ down the bottom-left to create a new top-level document
3. Give the document a title
4. Add content to the document by typing whatever you want, or add a block by typing forward slash ‘/’, like formatting, code, table, image carousel, etc.
5. Click **Save**.
**Tips!**
* Nested documents can be created via the 3-dot menu on each document
* A blank document with nested documents will display the nested documents in a list
* Formatting text as a heading will then display the heading in the contents bar on the far right
* Drag-and-drop attachments directly onto the document while editing to upload (they appear in the bottom-left of the document)
## The 3 dots menu
The 3-dots menu allows for extra functionality. This can be accessed via the hover 3-dot in the document list or via the 3-dot menu on the far-right of each document.
* **Star**: this allows you to star your favorite documents for easier access
* **New nested document**: this creates a new nested document below your selection
* **Copy link**: this copies a direct link to this document for use in Teams etc. (user must have access to Gorelo to use this)
* **Duplicate**: this duplicates the current document and places it at the same level
* **Move**: this allows you to move a document anywhere in Gorelo (including to other Clients)
* **Archive**: this archives the document (accessible via the Archive button down the bottom left)
* **Open in new tab**: this opens the document in a new Gorelo tab
* **Restore previous version**: this allows you to see previous version history and restore
* **Make public**: this publishes the document to the Client Portal\
(your organization documents will be published to the portal for ALL clients, documents under specific clients will only be published to the portal for that specific client)
# CRM overview
Source: https://help.gorelo.io/crm
Organize clients, locations, and contacts in the Gorelo CRM with custom fields, tags, domain tracking, templates, and Client Portal access.
The **Service Delivery** module in Gorelo provides a series of Customer Relationship Management (CRM) features to centralize and simplify the organization of your clients and different contacts. Gorelo organizes the CRM feature using the following hierarchy:
* **Clients:** The top-level organization
* **Locations:** Physical addresses or branches
* **Contacts:** The individual people belonging to those organizations
This structure ensures that you can attribute assets, contracts, and invoices to the correct entity. Gorelo provides tags to filter access to data and to the [Client Portal](/client-portal).
## Core features
| Features | Use this to... | Examples |
| --------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| [**Organization and profile management**](/assign-contact-to-client) | Manage full client profiles. | - Names
- Multiple physical locations
- Primary contact designation
|
| [**Custom fields**](/install-via-custom-fields) | Store and filter unique metadata. | - Tax IDs
- License keys
- Specific internal notes
|
| [**Contact tags and permissions**](/client-portal#extended-visibility-via-contact-tags) | Assign predefined tags to contacts. | - `Primary`
- `Approver`
- `Billing`
- `Portal`
|
| [**Domain and asset tracking**](/create-expiration-rule) | Automatically track client domain information and set expiration rules. | - Expiration dates and registrars
- Generate alerts when domains or warranties are about to expire
|
| **Client banners and alerts** | Create visual cues to alert staff to critical information. | - Outstanding bills
- Specific support instructions
- A new [document](/documents-overview) is available
|
| [**Templates**](/checklists#save-the-project-as-a-template) | Standardize processes with Project templates and tickets shortcuts. | - New client onboarding
- Periodic maintenance
|
| [**Data portability**](/contacts-overview#import-contacts) | Bulk-import/export clients, contacts, and products. | |
| [**Client Portal**](/client-portal) | Provide a self-service interface to communicate with your clients. | Clients can: - Submit tickets.
- View project progress.
- Access public documentation.
- Pay invoices.
|
| **Recycle bin** | Recover deleted items within a specific timeframe you set. | |
# Send emails from your custom domain
Source: https://help.gorelo.io/custom-domain
Add a custom domain in Gorelo to send ticket and billing emails from your own branded address, with DNS records to verify the domain in Mailgun.
## Add a custom domain
1. Navigate to Settings —> Email —> [**Settings**](https://app.gorelo.io/Admin/admin-settings#email#settings)
2. Click **Add Domain** in the top-right corner
3. Enter your domain name
4. Add the DNS records to your DNS provider and click Verify (note the ‘gorelo.’ subdomain on everything).
## Add/edit a custom email address
Adding a custom domain will automatically create two custom email addresses that you can make changes to.
* **help@** will be created as your default ticketing email address
* **accounts@** will be created as your default billing email address (outbound only)
1. Navigate to Settings —> Email —> [**Settings**](https://app.gorelo.io/Admin/admin-settings#email#settings)
2. Click the edit button on the far right of the help@ email address
3. Update any fields you need to:
* **Configuration**
* **Display name:** This is what appears as the name in Outlook/Gmail etc. when an email is received from this address.
* **Email**: This is what appears as the From address and Reply-to in Outlook/Gmail etc.
* **Group**: These groups will be automatically added to all tickets that are created from inbound emails to this address. Outbound sending is also limited to just these groups.
* You can also **Automatically apply** clients, tags and users.
* **Auto Response**
* ‘*Contacts will receive an email when a new Ticket is created by them through email*’\
Toggle this on to generate an automatic response when a new ticket is received\
This is the **Ticket Created Email** template
* ‘*Contacts will receive an email when a Ticket is merged*’ Toggle this on to generate an automatic response when a ticket has been merged (contacts of the source ticket)
* ‘*Contacts will receive the emails for the ticket statuses selected below*’\
Toggle this on to generate an automatic response when a ticket status is changed to any of the selected.\
This is the **Ticket Status Updated** template
* Email Template Management
* Select either **Ticket Created Email** or **Ticket Status Updated** from the dropdown
* **Preview** shows you what the email will look like
* **Template** is HTML and allows full customisation
* **Variables** lists the available variables for both the subject and body of the email
4. Click Save
5. Test sending an email from an unrelated email account (e.g., Gmail) directly to the Forwarding Address
## Forward emails to Gorelo
1. Navigate to Settings —> Email —> [**Settings**](https://app.gorelo.io/Admin/admin-settings#email#settings)
2. Copy the **Forwarding Address** of your default ticketing email address, e.g., [**help@gorelo.gorelodomain.com**](mailto:help@gorelo.gorelodomain.com)
3. Navigate to your email provider
4. Find the matching mailbox (without the gorelo. subdomain), e.g., [**help@gorelodomain.com**](mailto:help@gorelodomain.com)
5. Configure this mailbox to forward to the Forwarding Address, e.g., [**help@gorelo.gorelodomain.com**](mailto:help@gorelo.gorelodomain.com)
6. Test sending an email from an unrelated email account (e.g., Gmail) to the matching mailbox, e.g., [**help@gorelodomain.com**](mailto:help@gorelodomain.com)
Tips!
* Make sure your email provider allows forwarding to external domains (on an individual mailbox level for security).
* Forwarding vs. Redirect — if you’re doing this via a rule in Outlook, then use ‘Redirect to’
## Troubleshooting
### Emails are rejected/quarantined/marked as spam
Some SPF and DMARC configurations don't play well with mail that's forwarded or sent on your behalf—which is how Gorelo handles outbound emails. This can happen even after a DNS records successful verification.
Adjusting SPF and DMARC **doesn't weaken your protection**: it allows legitimate mail flow through services like Gorelo without being accidentally blocked by your anti-spoofing protections.
The following settings are the most likely to break delivery:
| Setting | Value | Result |
| ---------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Hardfail SPF | `-all` | Tells receiving servers to *reject* any message that doesn't come from a listed sender. |
| Strict DMARC alignment | `adkim=s aspf=s` | Requires an exact match from the domain that signed the message (via SPF or DKIM), which fails whenever mail is signed by a subdomain or sent on your behalf. |
#### Recommended alternatives
Change your SPF and DMARC configuration to the following setting.
Changes apply to your **root domain**, not the 'gorelo' subdomain you verified records for.
| Setting | Value | Result |
| ----------------------- | ---------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| Softfail SPF | `~all` | Unauthorized senders are still flagged, but the message isn't outright rejected: downstream filters and DMARC have the final say. |
| Relaxed DMARC alignment | `adkim=r aspf=r` | Allows subdomains to align with the parent domain. Your DMARC policy (`p=quarantine` or `p=reject`) still applies. |
#### Results
After changing your settings, you should obtain the following configuration within your DNS registrar:
| Record | Before | After |
| ----------- | ------------------------------------------- | ------------------------------------------- |
| TXT (SPF) | `v=spf1 include: -all` | `v=spf1 include: ~all` |
| TXT (DMARC) | `v=DMARC1; p=quarantine; adkim=s; aspf=s` | `v=DMARC1; p=quarantine; adkim=r; aspf=r` |
Alternatively, you can also **omit the DMARC configuration**, as omitting it defaults to a **relaxed alignment.**
#### Learn more
Why softfail SPF works.
Understand DMARC policies and configuration.
## FAQ
No. It ensures that legitimate emails sent through services like Gorelo aren’t mistakenly blocked, without reducing your protection against spoofing.
1. Go to your **domain’s DNS settings** (where your domain is managed: registrar or DNS host).
2. Find the existing **TXT record** that starts with `v=spf1`.
3. Edit that record and replace `-all` with `~all`. You should have something like the following:
```text theme={null}
v=spf1 include: ~all
```
4. Save the changes.
5. Wait for DNS propagation (can take a few minutes to a few hours).
You can specify the previously suggested configuration, or omit it completely, since these settings default to relaxed when omitted.
Templates are set per custom email address, not per group. To use a different **Ticket Created Email** or **Ticket Status Updated** template for each queue:
1. Create a separate custom email address for each queue, for example `help@` and `billing@`.
2. Assign each email address to the matching **Group** in its Configuration settings.
3. Customize the templates under **Email Template Management** for each address.
Tickets created from inbound emails to an address automatically get that address's groups, and outbound sending from that address is limited to those groups.
1. Go to your **domain’s DNS settings**.
2. Find the **TXT record** for DMARC (usually `_dmarc.yourdomain.com`).
3. Edit the record and change:
* `adkim=s` → `adkim=r`
* `aspf=s` → `aspf=r`
4. Save your changes. You should obtain something like:
```text theme={null}
v=DMARC1; p=quarantine; adkim=r; aspf=r
```
5. Wait for DNS propagation.
# Deploy the Gorelo Agent
Source: https://help.gorelo.io/deploy-gorelo-agent
Deploy the Gorelo Agent on Windows and macOS using the generic or client-specific PowerShell installer or manual executable for asset adoption and monitoring.
You can install the Gorelo Agent via a PowerShell command (recommended) or via a manual executable. A client-specific installer automatically associates the agent with the specified client and location. A generic installer leaves the agent ready for adoption.
Gorelo only supports operating systems that are currently supported by the vendor themselves (Microsoft/Apple).
* [**https://endoflife.date/windows**](https://endoflife.date/windows)
* [**https://endoflife.date/windows-server**](https://endoflife.date/windows-server)
* [**https://endoflife.date/macos**](https://endoflife.date/macos)
## Install the Agent Asset
1. Select the target computer (Windows or Mac).
2. Copy the command.
3. Paste it into PowerShell or the terminal on the target computer and press **Enter.**
Once the asset appears in the asset list (this can take a few minutes based on internet bandwidth), navigate to the Client/Location column and click the **Adopt** button.
Your asset is now connected to the appropriate client and location in Gorelo.
Run the installer in an elevated session.
* For Windows, run PowerShell as administrator.
* For macOS, run `sudo su` (if required).
For troubleshooting, see the [**Gorelo Agent won’t install**](/gorelo-agent-wont-install) page.
# Deploy a policy on all assets
Source: https://help.gorelo.io/deploy-policy-on-all-assets
Create a Gorelo policy targeting assets by tag to distribute checks, plugins, and scripts to every workstation or server in a single deployment step.
Use policies to distribute **checks**, **plugins**, and **scripts** to assets via the use of tags. This guide walks you through creating your first policy to distribute the ScreenConnect plugin to all workstations.
1. Navigate to [**Policies**](https://app.gorelo.io/Asset/policy-management) from the menu.
2. Click **Create a policy** down the bottom-left.
3. Name the policy *Base Workstation.*
4. Under **Must match all these tags,** add the **Workstation** tag.
5. While *Base Workstation* policy is selected in the left column, hover **Add**.
6. Select **Plugin** and then **ScreenConnect.**
7. **Distribute** the policy up the top-left.
The same process can be adapted for any check/plugin/script.
Gorelo applies policies like a router's Access Control List (ACL). Checks/Plugins/Scripts are applied hierarchically from top to bottom. If an identical item exists higher in the hierarchy, it overrides those lower down.
For example, Windows Patch Management in your *Base Workstation* policy right at the bottom. Further up the list, you would then create a client-specific policy with Windows Patch Management and this would override the one in your *Base Workstation* policy.
# Dismiss alerts
Source: https://help.gorelo.io/dismiss-alerts
Dismiss alerts in Gorelo to clear a specific occurrence and stack from the list without stopping future alerts, with tips on critical mobile subscriptions.
Dismissing clears just that particular occurrence (and its stack), but doesn't stop future occurrences from generating.
1. Navigate to the [**Alerts List**](https://app.gorelo.io/Alert/alerts) from the main menu.
2. In the Everything view, you should see the newly generated alert with the following details (but a different asset name):
([**Generate a test alert**](/generate-a-test-alert) if you do not see anything).
3. Click the **Dismiss** button on the far right:
**Tips!**
Critical alerts can be subscribed to so they appear as native iOS/Android notifications on your mobile device. Navigate to your [**Profile Settings**](https://app.gorelo.io/application/setting) on the web and toggle on the Critical Alert subscription.
# Display an icon in the Windows system tray
Source: https://help.gorelo.io/display-an-icon-in-the-windows-system-tray
Deploy the Gorelo Tray App plugin via policy to display a branded icon in the Windows system tray with custom hover text and a clickable redirect URL.
The Tray App plugin can be used to display an icon in the Windows system tray (bottom right corner). It also allows for hover text and a redirection URL.
1. Upload your favicon.
2. Specify your Hover Text (appears when a user hovers your tray icon).
3. Specify your Redirection URL (opens a browser to this URL when a user clicks your tray icon).
4. Click **Save**.
# What are documents
Source: https://help.gorelo.io/documents-overview
Choose between unstructured documents for free-form how-to guides and structured documents based on forms for capturing consistent data entries in Gorelo.
Gorelo provides two types of documents:
* **Unstructured** documents are blank documents, similar to those in apps like Word or Notion. Use them to document a how-to guide. They aren't the best fit when you need to capture specific information.
* **Structured** documents are based on forms. You create them by:
1. Building a form that asks for the specific information you want.
2. Filling out this form for each entry, such as each printer, network rack, or application.
## Document visibility
You can customize document visibility from the sidebar. Go to **Documents**, select the document, then click the **three dots menu**. Each document can be:
* **Private:** Only you and your team can access it. You can share direct access to the document with your team by copying the link from the **Copy Link** option. To access the document from the link, the user has to be signed into Gorelo.
* **Public:** Anyone with the public link can access the document. You generate a public link by toggling the **Public Link** option. To share the public link, click the copy icon next to it.
* **Private and shared with selected clients:** All clients logged into the [Client Portal](/client-portal) can access the document when you toggle the **Share to Portal** option.
# How emails work in Gorelo
Source: https://help.gorelo.io/email-overview
Gorelo uses Mailgun for email delivery with dedicated IPs, tight integration, and full troubleshooting visibility for tickets and outbound messages.
Gorelo uses Mailgun for email delivery to ensure reliability, high deliverability, and seamless troubleshooting. Instead of dealing with multiple BYO mail servers, using Mailgun exclusively allows Gorelo to tightly integrate email with its features—providing better tracking, logging, and efficient email issue handling.
## Why Gorelo uses Mailgun
* **Optimized deliverability** – Mailgun is built to ensure transactional emails reach inboxes, reducing the risk of messages being marked as spam.
* **Simplified troubleshooting** – Gorelo manages the entire email flow, making it easier to track, diagnose, and resolve any issues quickly.
* **Deeper integration** – Full control over email processing lets Gorelo pull error messages, delivery reports, and logs directly into tickets for better visibility.
## Dedicated IP addresses
Gorelo uses dedicated IPs to ensure better email deliverability and maintain a strong sender reputation. The current IPs are:
* **198.244.59.82**
* **159.135.238.33**
Additional dedicated IPs may be added in the future as needed. If you need to whitelist Gorelo’s email servers, ensure this IP (and any future ones) are added to your email security settings.
### What about my custom domain
When using Gorelo, emails are sent from a subdomain like [gorelo.yourdomain.com](http://gorelo.yourdomain.com), where all necessary DNS records are configured. This setup ensures there’s no impact on your root domain ([yourdomain.com](http://yourdomain.com)), meaning your primary email services remain fully functional and unaffected.
Your clients will still see and interact with your root domain for email communication. For example, they’ll receive and reply to emails from [support@yourdomain.com](mailto:support@yourdomain.com), while the subdomain is only used behind the scenes.
## Stripped domains
Gorelo uses the concept of ‘Stripped Domains’. These are domains that you specify should not be associated with any particular Client or Contact — essentially, stripping the client and contact from them when a ticket is generated. In addition, Gorelo will not send an automatic response to the sender.
A great example of this would be for Huntress. If you’ve configured Huntress to email Incident Reports to your help/support address, you likely don’t want everything coming from [**noreply@huntress.io**](mailto:noreply@huntress.io) to be associated with a single client or contact. Instead, you want these fields to be blank so you can easily assign the correct client.
# Example prompt to generate a script with AI
Source: https://help.gorelo.io/example-prompt-to-generate-a-script-with-ai
Copy a ready-made prompt for Claude or another AI assistant to generate PowerShell scripts that use GoreloAction for alerts and custom asset fields.
Copy and paste the following prompt into Claude or a similar AI assistant when you need to create a script that uses GoreloAction. Make sure to replace `[describe your monitoring need]` with your specific requirements.
* Example 1: "monitor disk space usage and alert when drives are below 10% free space."
* Example 2: "rotates the local admin password daily and writes it to a custom field."
```text theme={null}
I need to create a simple PowerShell script that integrates with Gorelo RMM using GoreloAction. The script should [describe your monitoring need].
GoreloAction supports the following functions:
1. Generate Alerts:
GoreloAction -Alert -Severity -Name -Description -Suppress
Severity levels:
- 1: Critical
- 2: Error
- 3: Warning
Example: GoreloAction -Alert -Severity 1 -Name "Critical Error" -Description "Details here" -Suppress 24
2. Write to Custom Fields:
GoreloAction -SetCustomField -Name -Value
Example: GoreloAction -SetCustomField -Name 'asset.lastCheckTime' -Value "2025-03-09 10:30"
3. Read from Custom Fields:
Custom fields can be read using the $gorelo: prefix:
- Client-level: $gorelo:client.fieldName
- Asset-level: $gorelo:asset.fieldName
- File access: $gorelo:file.fileName (Gorelo will automatically download any referenced files before running the script)
Example:
if($gorelo:client.customToken){
# Use the token for actions
$token = $gorelo:client.customToken
}
Example with file:
if($gorelo:file.Installer){
# Run the installer that was uploaded to Gorelo Files
Start-Process -FilePath $gorelo:file.Installer -ArgumentList "/quiet" -Wait
}
Please include proper error handling, clear comments, and appropriate alert severity based on the issue detected. Also, please advise on any custom fields or files that need to be created/uploaded in Gorelo before running this script.
```
Once the script is generated, chat back-and-forth with the AI assistant to make sure it covers your exact needs. Test the script in Gorelo and copy/paste any errors to the AI assistant to troubleshoot (make sure to change any -Suppress to 0 during testing).
# Integrate with existing remote access tools
Source: https://help.gorelo.io/existing-remote-access-tools
Integrate Splashtop, AnyDesk, TeamViewer, RustDesk, and other remote access tools with Gorelo by configuring custom asset fields and URL launch shortcuts.
Follow this guide to integrate other tools in Gorelo, like Splashtop, AnyDesk, TeamViewer, etc.
You can integrate Gorelo with any remote access tool that supports launching via a URL, like Splashtop, AnyDesk, or TeamViewer.
This example uses:
* Splashtop Business
* RustDesk
* Webroot
1. Navigate to **Settings** > **Assets** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#asset#assetcustomfields).**
2. Add custom field with the following details:
* **Name**: `Splashtop SUUID`
* **Variable**: `splashtopSUUID`
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: `Store-SplashtopSUUID`
* **Content**:
```powershell theme={null}
# Define registry path for 64-bit machines
$regPath64 = "HKLM:\SOFTWARE\WOW6432Node\Splashtop Inc.\Splashtop Remote Server"
# Define the value name for the SUUID
$regValue = "SUUID"
# Try to retrieve the SUUID from the 64-bit registry
if (Test-Path $regPath64) {
try {
$suuid = Get-ItemProperty -Path $regPath64 -Name $regValue -ErrorAction Stop
# Check if the SUUID value is present
if ($suuid.$regValue) {
$suuidValue = $suuid.$regValue
Write-Output "Splashtop SUUID: $suuidValue"
# Write the SUUID to the Gorelo custom field
GoreloAction -SetCustomField -Name 'asset.splashtopSUUID' -Value $suuidValue
} else {
Write-Output "SUUID not found in the registry."
}
} catch {
Write-Output "Error retrieving SUUID from the registry: $_"
}
} else {
Write-Output "Splashtop registry not found."
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want to store the Splashtop SUUID for.
3. Add the `Store-SplashtopSUUID` script and set to repeat daily at your preferred time.
4. **Save** and **distribute** the policy.
1. Navigate to **[Asset Shortcuts](https://app.gorelo.io/Admin/admin-settings#asset#assetshortcuts).**
2. Add a new shortcut with the following details:
* **Name**: `Splashtop`
* **URL**: `t-business://com.splashtop.business?account=&uuid={{$gorelo:asset.splashtopSUUID}}&sessiontype=remote`
* **Pinned Name**: `Splashtop`
You should now see the **SPLASHTOP** shortcut up the top-right corner of the Asset Detail page. If the script successfully populated the `$gorelo:asset.splashtopSUUID` variable, then this shortcut will launch the Splashtop Business application.
The shortcut does not install Splashtop -- another script would need to be used for that, for example:
```powershell theme={null}
# Installs Splashtop Streamer using the installer MSI uploaded to $gorelo:file.splashtopInstaller
# Runs a silent install using the 12-digit deployment key at $gorelo:client.splashtopKey
#Check for presence of SplashtopKey
if ([string]::IsNullOrEmpty($gorelo:client.splashtopKey)) {
Write-Output "No SplashTop Key stored for this client. Automatic installation cancelled."
GoreloAction -Alert -Severity 3 -Name "No Splashtop Key stored for this client" -Description "No Splashtop Key is stored in the client custom field so the automatic installation has been cancelled" -Suppress 0
} else {
Write-Output "Splashtop Key Found: " $gorelo:client.splashtopKey
Write-Output "Installer Path: " $gorelo:file.splashtopInstaller
}
#Install Splashtop
msiexec /i $gorelo:file.splashtopInstaller USERINFO="dcode=$gorelo:client.splashtopKey,hidewindow=1,confirm_d=0" /qn /norestart
```
It is strongly recommended to host your own RustDesk server and modify the initial install script to support this.
1. Navigate to **Settings** > **Assets** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#asset#assetcustomfields).**
2. Add custom field with the following details:
* **Name**: RustDesk ID
* **Variable**: rustdeskID
3. Add custom field with the following details:
* **Name**: RustDesk Password
* **Variable**: rustdeskPassword
1. Navigate to **Settings** > Asset > [**Files**](https://app.gorelo.io/Admin/admin-settings#asset#filerepository)
2. Add a file with the following details:
* **File**: Upload the latest RustDesk MSI installer
* **Variable**: rustdesk
1. Navigate to [**Scripts**](https://app.gorelo.io/Asset/script-list)
2. Create a script with the following details:
* **Name**: Install Rustdesk
* **Content**:
```powershell theme={null}
#Install Rusdesk
msiexec /i $gorelo:file.rustdesk /qn /norestart CREATESTARTMENUSHORTCUTS="N" CREATEDESKTOPSHORTCUTS="N" /l*v install.log
```
3. Create a script with the following details:
* Name: Write Rustdesk ID and Password
* Content:
```powershell theme={null}
$RustDeskPath = "$env:ProgramFiles\RustDesk\RustDesk.exe"
# Get Rustdesk ID using the executable
$RustdeskID = cmd /c "`"$RustDeskPath`" --get-id"
if ($RustdeskID) {
# Write ID to Gorelo custom field
GoreloAction -SetCustomField -Name 'asset.rustdeskID' -Value $RustdeskID
Write-Output "Rustdesk ID: $RustdeskID written to Gorelo"
# Generate random 16 character password
$Password = -join ((65..90) + (97..122) + (48..57) | Get-Random -Count 16 | ForEach-Object {[char]$_})
# Set the password in Rustdesk
cmd /c "`"$RustDeskPath`" --password $Password"
# Write password to Gorelo custom field
GoreloAction -SetCustomField -Name 'asset.rustdeskPassword' -Value $Password
Write-Output "Rustdesk password set and saved to Gorelo"
exit 0
} else {
Write-Output "Failed to get Rustdesk ID"
exit 1
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want to install and connect to via RustDesk.
3. Add a continuous Service check for **RustDesk Service**. Add the ‘Install Rustdesk’ script as a remediation step.
4. Add the 'Write Rustdesk ID and Password' script and set to repeat daily at your preferred time.
5. **Save** and **distribute** the policy.
1. Navigate to **[Asset Shortcuts](https://app.gorelo.io/Admin/admin-settings#asset#assetshortcuts).**
2. Add a new Shortcut with the following details:
* **Name**: `RustDesk`
* **URL**:`rustdesk://{{\$gorelo:asset.rustdeskID}}?password={{\$gorelo:asset.rustdeskPassword}}`
* **Pinned Name**: `RustDesk`
You should now see the **RustDesk** shortcut up the top-right corner of the Asset Detail page. If the script successfully populated the custom fields, then this shortcut will launch the RustDesk application.
Bitdefender URL for the install exe should look like this (fake example):
[https://cloudgz.gravityzone.bitdefender.com/Packages/BSTWIN/0/setupdownloader\_\[aHR0cHM6Ly9jbG91ZGdLWDawWVjcy5ncR5em9uZS5iaXRkZWZl3ddwawGfawdmRlci5jb20vUGFja2FnZXMvQlNUV0lOLzAvdkluc3RhbGxlci54bw-bGFuZz1lbi1VUw==\].exe](https://cloudgz.gravityzone.bitdefender.com/Packages/BSTWIN/0/setupdownloader_\[aHR0cHM6Ly9jbG91ZGdLWDawWVjcy5ncR5em9uZS5iaXRkZWZl3ddwawGfawdmRlci5jb20vUGFja2FnZXMvQlNUV0lOLzAvdkluc3RhbGxlci54bw-bGFuZz1lbi1VUw==].exe)
# Filter data with Views and Client Focus
Source: https://help.gorelo.io/filter-data-with-views-and-client-focus
Use Views and Client Focus in Gorelo to filter tickets, assets, and alerts by saved criteria or a specific client, with team-shareable boards across lists.
**Views** are boards that filter your data on each (like Tickets, Assets, Alerts). You can customize your filters in many ways and then save the result as a View. You can also share Views globally with your team.
Use **Client Focus** when you want to filter based on a specific client. The **Client Focus** works in combination with your selected View. For example:
* You have a View that shows ‘Mine & Unassigned’ tickets.
* When applying a Client Focus will filter the data to only show ‘Mine & Unassigned’ for that specific client.
The Client Focus also persists across all lists.
## Create a view from alerts
This example uses the Alerts list.
1. Navigate to the [**Alerts list**](https://app.gorelo.io/Alert/alerts)
2. Click ‘Create a view’ at the bottom of the Views pane
3. Enter the fields to filter the list
* **Name**: this is the name that shows in the Views pane (emojis work), e.g., 🏹 Huntress
* **Keyword**: this will filter by keyword in the Alert **name** (white text)
* **Clients**: leave blank for **all** clients or choose specific clients
* **Severity**: choose one or multiple severity levels
* **Type**: choose one or multiple types
* **Ticketed**: toggle on to show alerts that have been associated with a ticket
* **Ignored**: toggle on to show ignored alerts
4. Click **Save** and navigate back to the Views pane
Tips!
* The 3-dot menu beside each View can be used to:
* **Edit**: make changes to the View
* **Set Default**: this is the view that will load automatically for you
* **Set Global**: this will share the View to everyone in your organization (only Admins can do this)
* **Hide**: this will put the View into the collapsible section called ‘Hidden Views’
* Delete: this will delete the View
* Some lists will have toggles up the top-right to quickly make changes, e.g., show Ticketed/Ignored on the Alerts list
## Filter alerts by client
The Alerts list is used as an example here.
1. Navigate to the [**Alerts list**](https://app.gorelo.io/Alert/alerts)
2. Click the Client Focus button in the top right of the Views pane
3. Enter the client’s name. Your list will now be filtered by the **View** AND the **Client Focus.**
Tips!
* Client Focus persists across all lists in Gorelo. If you set the Client Focus on alerts and then navigate to Tickets, it will still be there.
## Next steps
Manage your clients’ requests and organize your work.
Monitor important events or issues in Gorelo.
# Filter spam
Source: https://help.gorelo.io/filter-spam
Use the Gorelo Spam view to intercept suspicious emails before they reach your ticket queue, review sender, score, and recipient, then unspam or block them.
A dedicated Spam view to manage suspicious emails before they reach your ticket queue.
The **Spam** view can be accessed via the [**Ticket List**](https://app.gorelo.io/Ticket/ticket-list) → Spam (above the ‘Create a View’ button)
The system intercepts potential spam emails and holds them for review, displaying:
* Time Received
* Subject
* Sender
* Spam Score
* Recipient
Each intercepted email offers two actions:
* **Create Ticket**: Converts legitimate emails to tickets
* **Delete**: Removes the unwanted email (cannot be undone)
Currently, Gorelo's filtering thresholds are extremely conservative to minimize false positives. Protection levels will increase with additional email volume and as patterns emerge.
# What are forms
Source: https://help.gorelo.io/forms-overview
Forms in Gorelo capture information from end users for hardware requests, user lifecycle, client onboarding, and more, with name and description settings.
## Form settings
### Name
To change the internal name of the form:
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu
2. Select the form on the left
3. Click the edit icon to the right of the existing form name
4. Change the name and click ‘Update’
### Description
To change the internal description of the form:
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu
2. Select the form on the left
3. Click the edit icon to the right of the description field
4. Add/change the description and click the save icon
### Groups
One or more Groups can be automatically added to a ticket created via a form. You can also choose to notify those groups on ticket creation.
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu
2. Select the form on the left
3. Select the **Settings** tab
4. Select the Group(s) you’d like to automatically apply via the dropdown
5. Toggle on **Notify group** to generate a notification to those group members when a ticket is created via this form
6. Click **Save changes** at the bottom
### Tags
One or more Tags can be automatically added to a ticket created via a form.
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu
2. Select the form on the left
3. Select the **Settings** tab
4. Select the tags(s) you’d like to automatically apply via the dropdown
5. Click **Save changes** at the bottom
### Clients
Forms can be set so only certain Clients have access to them. This is a great way to reduce clutter when generating a form link from an existing ticket.
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu
2. Select the form on the left
3. Select the **Settings** tab
4. Select the tags(s) you’d like to automatically apply via the dropdown
5. Click **Save changes** at the bottom
# Generate a test alert
Source: https://help.gorelo.io/generate-a-test-alert
Generate a test alert in Gorelo using a GoreloAction CLI command on an online agent asset to verify alert delivery and ticket creation workflows.
1. Navigate to the [**Assets List**](https://app.gorelo.io/Asset/asset-list) from the main menu.
2. Click an agent asset that’s currently online.
3. Navigate to the **CLI** tab down the left side.
4. Generate a test alert by pasting the following command into the CLI of an asset:
```text theme={null}
GoreloAction -Alert -Severity 1 -Name "NameHere" -Description "DescriptionHere" -Suppress 0
```
See [**GoreloAction**](/gorelo-action-cli) for more details.
# Generate a form link
Source: https://help.gorelo.io/generate-form-link
Generate a one-time submission link for a Gorelo form to share with clients via email or directly from an existing ticket for self-service data capture.
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu.
2. Select the form on the left.
3. Click the **Submission Link** button up the top right to copy the link.
**Tips!**
* Form links are one-time use and will expire after 7-days
* This form will generate a new ticket based on the [**Form Settings**](/forms-overview#form-settings)
## Generate a form link from an existing ticket
1. Create or navigate to an existing ticket.
2. Click **public comment** in the comment box.
3. Type **Click here** and highlight the word **here**.
4. Click the **Generate form link** button.
5. Click the appropriate form to link.
**Tips!**
* Form links are one-time use and will expire after 7-days.
* This form will generate a submission on the existing ticket.
# Generate and rephrase replies
Source: https://help.gorelo.io/generate-replies-rephrase
Use Gorelo Prompt Management to build custom AI prompts that generate ticket replies or rephrase text, keeping full control of tone and style for your team.
Prompt Management lets you create your own custom prompts to either generate replies or rephrase text. This allows you to make use of AI while keeping full control over the tone and style.
## Add a prompt
1. Navigate to **Settings** → **AI** → **Prompt Management**
2. Click **Add Prompt** and fill out the following fields:
* **Name**: A quick label so you know what it’s for
* **Prompt Type**: Select **Generate reply** or **Rephrase**
* **Prompt Text**: The actual text or instructions you want the AI to follow
3. On the right-side, you can test each prompt type:
* For Generate Reply — select the ticket and then select a comment and click ‘Generate Response’
* For Rephrase — type your text and click ‘Rephrase’
4. Change the status to **Active** (top-right) when you’re ready to make it available for use on tickets
5. Click ‘**Save**’
## How the prompts work
**Generate reply**:
* Uses details from the ticket title, latest comment, and contact info.
* Example: If your prompt says, “Gather More Info,” the AI will use the ticket’s context to create that reply.
* **Rephrase**:
* Takes whatever text you’ve typed in the comment box and reworks it.
* Example: If you write a response but want a more concise version, click **Rephrase**.
## Rephrase or generate a reply
* In the ticket’s **Public Comment** box, you’ll see two buttons:
* **Rephrase your text** (for Rephrase prompts)
* **Generate a reply** (for Generate reply prompts)
* If you’ve got more than one active prompt for a type, a popup appears and lets you pick which one to use.
# Invoicing and billing overview
Source: https://help.gorelo.io/get-paid
Manage invoicing and payments in Gorelo with full or partial invoices created from time, products, or bundles, then review, approve, and send to clients.
Gorelo provides a complete invoicing and billing platform that allows you to manage the invoicing and payment processes efficiently.
## Invoices
An invoice in Gorelo is a document that lists the products and services you provide to your customers, along with the corresponding prices and quantities. You can create invoices from:
* Time or labor entries
* Products
* Bundles
Invoices can be:
* **Full**: billing the entire amount.
* **Partial:** billing a portion of the amount.
Create them from scratch or use templates to save time. Once you have created an invoice, you can:
1. Review it.
2. [Approve it](/approve-and-invoice).
3. Send it to your customers.
Validate the entries to be billed and generate an invoice.
Turn on the Pay Now button in your invoice templates to ease the process for your customers and get paid faster.
## Products and services
Products and services are the items you bill to your customers. They can either be:
* **Time based:** you invoice the time spent on a ticket.
* **Labor based:** you invoice the type of work you perform on a ticket, or the role of the person performing the work.
Check out the following guides to learn how to set up hourly and labor rates:
Combine time entries with roles and work types to set hourly rates.
Set a rate based on the role and the type of work you're invoicing.
## Connect your tools to Gorelo
Connect your Xero account and invoice from Gorelo.
Connect your QuickBooks Online account and invoice from Gorelo.
# GoreloAction CLI (via PowerShell)
Source: https://help.gorelo.io/gorelo-action-cli
Use the GoreloAction PowerShell CLI to generate alerts and write to custom asset fields from your scripts, with parameters for severity, name, and suppress.
GoreloAction is a command-line utility that automatically comes with the [Gorelo Agent](/deploy-gorelo-agent) when you install it on an asset. GoreloAction enables PowerShell scripts to interact with Gorelo. It currently supports:
* Generating alerts.
* Writing to custom asset fields.
## Use GoreloAction
Run the following command in your terminal, and replace `` with the parameter values:
```powershell theme={null}
GoreloAction -Alert -Severity -Name -Description -Suppress
```
### Parameters
| Option | Description |
| -------------- | --------------------------------------------------------------------------------------------------- |
| `-Alert` | Specifies alert creation mode. |
| `-Severity` | Sets the severity level (Integer) - 1: Critical
- 2: Error
- 3: Warning
|
| `-Name` | Title/name of the alert in Gorelo. |
| `-Description` | Detailed description of the alert in Gorelo (optional). |
| `-Suppress` | Alert suppression duration in hours (optional and defaults to 4, use 0 for no suppression). |
| | |
#### Example
```powershell theme={null}
GoreloAction -Alert -Severity 1 -Name "NameHere" -Description "DescriptionHere" -Suppress 0
```
Run the following command in your terminal, and replace `` with the parameter values:
```powershell theme={null}
GoreloAction -SetCustomField -Name -Value
```
#### Parameters
| Option | Description |
| ----------------- | ----------------------------------------------------------------------------------------------------------- |
| `-SetCustomField` | Specifies custom field write mode. |
| `-Name` | Field identifier: - Format: `'asset.fieldname'`
- Remove `$gorelo`: from the variable
|
| `-Value` | Data to be stored in the field. |
#### Example
```powershell theme={null}
GoreloAction -SetCustomField -Name 'asset.rustdeskPassword' -Value "SecurePassword123"
```
# Gorelo Agent won't install
Source: https://help.gorelo.io/gorelo-agent-wont-install
Troubleshoot Gorelo Agent installation failures with the PowerShell prerequisite check, supported OS list, and common fixes for Windows and macOS endpoints.
Occasionally, you may run into issues installing the Gorelo Agent. Here are a few things to consider.
## Supported operating systems
Gorelo only supports operating systems that are currently supported by the vendor themselves (Microsoft/Apple).
* [**https://endoflife.date/windows**](https://endoflife.date/windows)
* [**https://endoflife.date/windows-server**](https://endoflife.date/windows-server)
* [**https://endoflife.date/macos**](https://endoflife.date/macos)
## Prerequisite check via PowerShell
Gorelo provides a simple prerequisite check via PowerShell that you can run.
1. Open an elevated PowerShell window on the computer experiencing agent issues.
2. Paste the following command and press **Enter**:
```text theme={null}
Invoke-Expression (Invoke-WebRequest -Uri "https://gist.githubusercontent.com/mikelgorelo/e5bcac91d2fddd165a2fd56a675ebb3a/raw/dd21bcf13480e366a569ae06fa43b9f3c57fa5d8/gorelo-check.ps1" -UseBasicParsing).Content
```
3. Work through resolving any failures, as per below, and make sure this persists across PowerShell sessions and reboots.
| Check | **❌ Failure Message** | **✅ Troubleshooting** |
| :------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **PowerShell Version Check** | `FAIL: PowerShell version X.X is below the required version 5.1` | - Download and install Windows Management Framework 5.1 from Microsoft
- For Windows 10/11, use Windows Update to update PowerShell
- Verify installation with `$PSVersionTable.PSVersion`
|
| **System Drive Space Check** | - `FAIL: Free space is less than 300 MB (Current: X MB)`
- `FAIL: Unable to get drive info`
- `FAIL: Unable to get System Drive`
| - Run Disk Cleanup to free up space
- Check for and remove large unnecessary files
- Verify system drive is accessible and mounted correctly
- Check disk health with `chkdsk /f`
|
| **Processor Architecture Check** | `FAIL: Non-64-bit processor architecture detected: X` | - Verify system meets 64-bit requirements
- Check if running 32-bit Windows on 64-bit capable hardware
ARM64 is supported, e.g., Snapdragon |
| **Registry Permission Check** | `FAIL: Registry read/write permission check. Error: [specific error]` | - Run script as administrator
- Check permissions on HKLM:\SOFTWARE\Gorelo
- Verify antivirus isn't blocking registry access
- Use RegEdit to check registry key accessibility
|
| **URL Accessibility Checks** | `FAIL: URL check for [Description] ([URL]). Error: [specific error] ` | - Check internet connectivity
- Verify DNS resolution (`nslookup` the domain)
- Check firewall settings
- Verify proxy settings if applicable
|
| **Event Log Permission Check** | `FAIL: Event log read/write permission check. Error: [specific error]` | - Run script as administrator
- Check Event Log service is running (`Get-Service EventLog`)
- Verify permissions on Application event log
- Check Event Viewer functionality manually
|
| **Environment Variable Check** | - `FAIL: The PATH environment variable contains 'system32' but not 'System32\WindowsPowerShell\v1.0'`
- `FAIL: The PATH environment variable contains 'System32\WindowsPowerShell\v1.0' but not 'system32'`
- `FAIL: The PATH environment variable does not contain 'system32' or 'System32\WindowsPowerShell\v1.0'`
| - Check System PATH variable in System Properties
- Verify Windows directory structure
- Repair/restore system PATH if modified
- Compare with working system's PATH variable
|
| **Time Synchronization Check** | `FAIL: Time mismatch detected! [time details]` | - Check Windows Time service is running
- Force time sync: `w32tm /resync`
- Verify time zone settings
- Check network connectivity to [**time.windows.com**](http://time.windows.com)
- Configure automatic time synchronization in Windows settings
|
## Logs
Gorelo logs everything to:
```text theme={null}
%programfiles%\Gorelo\LogFiles\
```
As the install progresses, the installer creates additional folders at each stage with log files inside:
**InstallerHandler** > **Installer** > **Shell > Agent**
Feel free to investigate the following logs -- this is where the most common issues will appear:
```text theme={null}
%programfiles%\Gorelo\LogFiles\Installer\diagnostics**.log
```
```text theme={null}
%programfiles%\Gorelo\LogFiles\Agent\diagnostics**.log
```
If Gorelo support asks for log files, send the entire **LogFiles** folder as a .zip.
## Still having problems?
If you're still experiencing installation issues after resolving all failures in the **Gorelo Agent Check**, contact Gorelo support directly. Use the support chat via the "?" icon in the bottom-left menu.
# Gorelo Connect black screen on Windows
Source: https://help.gorelo.io/gorelo-connect-shows-a-black-screen-on-windows-tech-side
Fix the Gorelo Connect black screen on Windows by adding GoreloConnect.exe to PowerToys FancyZones application exclusions so remote sessions display correctly.
## Problem
Gorelo Connect launches into a black screen on Windows.
## Solution
This can be due to PowerToys FancyZones.
Add `GoreloConnect.exe` to the application exclusions in FancyZones.
# Group assets with tags
Source: https://help.gorelo.io/group-assets-with-tags
Group assets in Gorelo with built-in and custom tags driven by apps, services, registry keys, or Windows features to target policies and run scripts.
## Custom tags
1. Navigate to Settings > [**Tags**](https://app.gorelo.io/Admin/admin-settings#tagmanagementsettings) > Asset Policy Tags.
2. Create an Asset Tag (down the bottom):
* **Tag**: this is the name of the tag (for example, *Veeam B\&R*).
* **Sticky**: the tag can be automatically added but not automatically removed.
* **Property**: select from Apps, Services, Registry Key and Windows Features.
* **Condition**: select the appropriate condition.
* **Value**: enter the expected value.
**Tag expressions** are evaluated every \~6 hours and immediately when the [Gorelo.Rmm.Shell](http://Gorelo.Rmm.Shell) service starts (at first boot or manually).
**Sticky** should be used when you have policies attached with important checks (like backup monitoring). In the event someone accidentally uninstalls Veeam, the tag would remain and the Veeam backup check would continue to alert.\
These tags can be manually removed once the expression no longer matches.
# Gorelo guides overview
Source: https://help.gorelo.io/guides-overview
Browse guides for Gorelo covering service delivery, integrations, remote management, billing, and automation to get more value from your IT operations platform.
Find guides to automate your tasks and integrate tools into Gorelo.
Use AI to automate your workflows and save time on repetitive tasks.
Integrate Gorelo with your favorite tools to automate your workflows and get more done.
Script examples and guides for remote management
Learn how to use Gorelo's billing platform to its full potential.
# How billing works
Source: https://help.gorelo.io/how-billing-works
Gorelo Billing turns time entries, products, bundles, and usage-based quantities into invoices you can review, approve, and send to clients efficiently.
Billing with Gorelo turns work into revenue. You use it to:
* Collect time entries and products.
* Apply rates and contracts.
* Review and send invoices.
## What you can bill
* Time entries from tickets.
* Products added to tickets.
* Bundles and recurring items.
* Usage-based quantities.
Prefer watching a video? Check out this overview of the billing platform in Gorelo:
## Where to find the billing features
Use the Billing area in the left menu to access the following billing features:
Access and manage your invoices list.
Add pricing for your products and services, bundle them together, and add them to an invoice.
Manage your contact list to send invoices to.
Obtain approval and send invoices.
## Track unbilled items with Dynamic Quantities
Gorelo provides Dynamic Quantities to automate your billing by increasing or decreasing quantities of products and bundles and suggesting items that you haven’t billed yet. Currently supported features are:
* Asset Tags
* Contact Tags (M365)
* Pax8 subscriptions
Check [this detailed guide](/track-unbilled-items-with-dynamic-quantities) to learn how to use Dynamic Quantities to avoid unbilled items and automate your billing process.
## More automation features
Set up contracts to manage recurring invoices.
Use prorate items to partially invoice a ticket.
## Next steps
Explore the following guides to learn how to use Gorelo Billing to its full potential:
Use invoice templates to turn on the Pay Now button and get paid faster.
Use Billing Role and Work Type multipliers to set an hourly rate.
Set a rate based on the role or the type of work you're invoicing.
# How hourly rates work
Source: https://help.gorelo.io/how-hourly-rates-work
Gorelo calculates labor rates by multiplying a base hourly rate from your Billing Role by a Work Type multiplier to bill emergency, project, or routine work.
Your labor rate for Time Entries is calculated by combining two factors:
1. A base hourly rate determined by your **Billing Role** (such as Technician, Senior Consultant, etc.)
2. A rate multiplier based on the **Work Type** being performed (for example, emergency work might have a higher multiplier than routine support)
Your final labor rate = Base hourly rate (Billing Role) × Multiplier (Work Type).
For example, if a Technician (Billing Role: \$100/hour) performs emergency work (Work Type multiplier: 1.5×), the final labor rate would be \$150/hour.
# How policies work
Source: https://help.gorelo.io/how-policies-work
Gorelo policies distribute checks, plugins, and scripts to assets using tag-based targeting, so you can apply ScreenConnect or other tools at scale.
Policies are hierarchical configuration containers that you set up to manage assets based on tags. A policy does the following:
* Define a set of tags and associated components.
* Automatically apply checks, plugins and scripts to all matching assets during distribution.
Policies are applied hierarchically from top to bottom. Different policies might contain the same elements targeting the same asset:
* Check
* Plugin
* Script
To avoid conflicts, the highest matching policy in the hierarchy takes priority and overrides the policies below for that specific conflicting element. For example, a client-specific Windows Patch Management policy overrides the base policy.
List, create and edit all policies from the **Policies** option in the lateral bar menu.
# How scripts work
Source: https://help.gorelo.io/how-scripts-work
Learn how Gorelo scripts run on agent assets to automate tasks, with PowerShell, Command Line, or Bash support, timeout settings, and CLI execution.
Scripts in Gorelo handle anything that checks/plugins can't do natively. You write scripts using either:
* PowerShell
* Command Line (CMD)
* Bash
To see a list of all your scripts:
1. Expand the Gorelo left menu.
2. Under **RMM**, click **Scripts**.
You can [test a script](/write-and-test-a-script) against an asset. Input options for timeout and Gorelo built-in variables (custom asset/client fields, files), and trigger an alert depending on the results.
## Check an asset's script history
Each asset dashboard contains a **Script** tab that lets you see:
* Which script was run on the asset.
* The date of the run.
* The success status.
* The results of the run.
Customize which scripts appear on the asset details dashboard by pinning each script from [the script editor](https://app.gorelo.io/asset/script-list).
Roles without access to the script editor can't see or use scripts from the asset details dashboard unless you pin the script.
## Next steps
Run scripts using GoreloAction CLI.
Technical Preview
Gorelo embedded Live Terminal, enhanced with AI assistance.
# How uptime works
Source: https://help.gorelo.io/how-uptime-works
Learn how Gorelo uptime monitoring works using ICMP, HTTP, and TCP checks from multiple regions to alert you when websites or connections go offline.
The **Uptime** feature in Gorelo lets you monitor websites and internet connections using either:
* Internet Control Message Protocol (ICMP) pings.
* HTTP checks
* TCP checks
Gorelo [alerts you](/alerts-overview) when the target becomes unreachable or goes offline.
You configure an uptime check with the following details:
* The check type
* The target IP or URL
* The client/location
* Frequency
* Rechecks
* Monitoring region (Seattle, Sydney, UK, or Frankfurt)
## Automatically assign a location
Gorelo can automatically identify where an unassigned agent belongs based on its public internet IP address.
For example:
1. You create an uptime check for a client site using the WAN IP `203.0.113.10`.
2. A new generic agent installs and reports the same WAN IP.
3. Gorelo matches the IPs and automatically assigns (“adopts”) that agent to the correct Client and Location.
This helps automatically organize newly deployed or unassigned assets without manually moving them to the right customer or site.
# Install Gorelo Connect (remote control)
Source: https://help.gorelo.io/install-gorelo-connect
Install Gorelo Connect on Windows or macOS technician workstations to start remote control sessions from the Asset Detail page using one-click connections.
## Requirements
To successfully install Gorelo Connect on your machine, you need:
1. An active Gorelo subscription.
2. Gorelo Connect installed on the assets you want to monitor.
With these requirements in place, you can install Gorelo Connect on your machine and start monitoring your assets remotely.
## Install Gorelo Connect (technician side)
1. On an asset with the Gorelo Connect plugin, click the ‘Connect’ button.
2. You will see a small banner appear, click ‘Download’
3. Install GoreloLauncher.exe (there will be two UAC prompts — one for Gorelo Launcher and one for Gorelo Connect)
4. Click the ‘Connect’ button again
5. Always allow the protocol handler to open gorelolauncher links
6. You’ll then see the Launcher appear — followed quickly by the Gorelo Connect window
## Reinstall Gorelo Connect on an asset
1. On an asset with the Gorelo Connect plugin, click the Policy section
2. On the Gorelo Connect plugin, click the ‘heart’ icon to check health
3. Then click the reinstall button when it appears.
## Manually add Gorelo Connect to a policy
1. Navigate to [**Policies**](https://app.gorelo.io/Asset/policy-management) from the menu
2. Select an existing Policy
3. Hover over the ‘Add’ button up the top-right and then select ‘Plugin’
4. Select ‘Gorelo Connect’ from the list
5. Click ‘**Save**’
6. **Distribute** the policy
**Dedicated IP addresses**
Seattle: `172.179.240.232` [connect.usw.gorelo.tech](http://connect.usw.gorelo.tech)
Sydney: `20.5.234.185` [connect.aue.gorelo.tech](http://connect.aue.gorelo.tech)
\
Add both of these to your [**Tooling Allowlist**](https://support.huntress.io/hc/en-us/articles/26620768607891-Host-Isolation-IP-Allowlist) in Huntress for remote access during host isolation.
## Choose default remote control tool
Gorelo allows you to choose between the built-in tool or ScreenConnect as your default — all of the primary remote control buttons will then be bound to this selection.
1. Navigate to Settings → Assets → [**Settings**](https://app.gorelo.io/admin/admin-settings#asset#customassettype)
2. Toggle between Gorelo Connect or Screenconnect
3. Click ‘**Update**’
Screenconnect requires a third-party subscription and is not included with Gorelo.
## Automatic install
Gorelo Connect is automatically installed on new assets when the RMM agent is first installed.
## Manual install
For existing macOS assets, Gorelo Connect can be manually enabled/disabled via the 3-dot menu. This can be used to manually install Gorelo Connect or to go through a reinstall process.
## Grant permissions
On the first install (automatic or manual), you will be prompted to grant permission for Gorelo Connect in three areas:
* Full Disk Access
* Accessibility
* Screen & System Audio Recording
Select ‘Open System Settings’ on each popup and toggle on access for GoreloConnect — ‘Quit & Reopen’ if requested.
## Troubleshooting
| **Issue** | **Fix** |
| :---------------------------------------------------------------- | :--------------------------------------------------------------------- |
| Remote keyboard/mouse not working | Confirm **Accessibility** permission is enabled |
| File transfer fails or prompting for individual folder permission | Confirm **Full Disk Access** permission is enabled |
| Black screen or ‘Waiting for image’ | Confirm **Screen Recording** permission is enabled |
| No connection after macOS restart | End user needs to log in first to decrypt the startup disk (FileVault) |
# Install Slide Agent for backups
Source: https://help.gorelo.io/install-slide-agent-for-backups
Deploy the Slide backup agent to Windows assets using a Gorelo PowerShell script that downloads and installs the agent silently across all targeted endpoints.
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Install-Slide
* **Content**:
```powershell theme={null}
# Download the Slide installer
Write-Output "Downloading Slide installer..."
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
$client = New-Object System.Net.WebClient
$client.DownloadFile("https://slide.tech/agent", "C:\Windows\Temp\SlideAgent.exe")
# Install Slide agent silently
Write-Output "Installing Slide agent silently..."
Start-Process -FilePath "C:\Windows\Temp\SlideAgent.exe" -ArgumentList "/S" -Wait -NoNewWindow
# Wait a moment for the installation to complete
Start-Sleep -Seconds 10
# Check if the installation was successful
if (Test-Path "C:\Program Files\Slide\Agent\SlideAgent.exe") {
Write-Output "Slide agent installed successfully"
# Retrieve the pairing code and clean up ANSI color codes
Write-Output "Retrieving pairing information:"
$infoOutput = & "C:\Program Files\Slide\Agent\SlideAgent.exe" info
# Extract just the pairing code line and remove ANSI color codes
$pairingLine = $infoOutput | Where-Object { $_ -match "Pairing Code" }
if ($pairingLine) {
# Remove ANSI color codes and extract just the code
$pairingCode = $pairingLine -replace '\x1B\[[0-9;]*[a-zA-Z]', '' -replace '.*\|\s*', ''
Write-Output "Pairing Code: $pairingCode"
} else {
# If we can't find the specific line, just display all output without color codes
$cleanOutput = $infoOutput -replace '\x1B\[[0-9;]*[a-zA-Z]', ''
Write-Output $cleanOutput
}
exit 0
} else {
Write-Output "Installation may have failed - SlideAgent.exe not found"
exit 1
}
```
3. Run the script against an asset you’d like to back up.
4. Use the Pairing Code via **[https://console.slide.tech/agents](https://console.slide.tech/agents).**
# Install the Gorelo Connect plugin
Source: https://help.gorelo.io/install-the-gorelo-connect-plugin
Distribute the Gorelo Connect plugin via a policy with consent or auto-consent settings to enable remote control and file explorer on managed assets.
The Gorelo Connect plugin distributes the Gorelo remote access and file explorer tool.
Select an existing policy.
Hover over the **Add** button in the top right and then select **Plugin**.
* **Require consent before connecting**: The user must approve the connection before you can connect.
* **Auto-consent after x seconds**: Gorelo grants consent automatically after a set period of time, for example, when the user is away from their desk.
Warn the user you're connecting to their machine by toggling the **Show connection in progress banner** option. When activated, whenever you start a remote connection, a banner appears on the remotely controlled computer with the message "\ from \ is controlling your computer."
# Install software via custom client fields
Source: https://help.gorelo.io/install-via-custom-fields
Install software like Cove, SentinelOne, BitDefender, and Webroot with Gorelo scripts that use client-specific custom fields for keys, tokens, and tenant IDs.
Follow this guide to install SentinelOne, Cove, DNSFilter, etc.
Custom client fields can be used in scripts to install software with client-specific info (keys, tokens, etc.).
This example installs:
* Cove
* SentinelOne
* BitDefender
* Webroot
1. Navigate to **Settings** > **CRM** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#crm#clientcustomfields).**
2. Add custom field with the following details:
* **Name**: Cove Customer UID
* **Variable**: CoveCustomerUID
1. Navigate to a specific client.
2. Click **Custom Fields.**
3. Edit **Cove Customer UID.**
4. Enter the Customer UID retrieved from Cove.
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Install-Cove
* **Content**:
```powershell theme={null}
# ===== Configuration Variables =====
$CUSTOMERUID = $gorelo:client.CoveCustomerUID
$PROFILEID = "All-in" # Default retention policy
$PRODUCT = "0" # Profile ID (use "0" for no profile or a specific profile ID)
$DOWNLOADPATH = "C:\Windows\Temp"
# ===================================
$startTime = Get-Date
$INSTALL = "$DOWNLOADPATH\bm#$CUSTOMERUID#$PROFILEID#.exe"
# Download installer
try {
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
(New-Object System.Net.WebClient).DownloadFile("https://cdn.cloudbackup.management/maxdownloads/mxb-windows-x86_x64.exe", "$INSTALL")
} catch {
Write-Output "ERROR: Failed to download installer - $_"
exit 1
}
# Run installer
try {
Start-Process -FilePath $INSTALL -ArgumentList "-product-name `"$PRODUCT`"" -Wait -NoNewWindow
Start-Sleep -Seconds 5
} catch {
Write-Output "ERROR: Installation failed - $_"
exit 1
}
# Verify installation
$service = Get-Service -Name "Backup Service Controller" -ErrorAction SilentlyContinue
$process = Get-Process -Name "BackupFP" -ErrorAction SilentlyContinue
if ($service.Status -eq 'Running' -and $process) {
Write-Output "SUCCESS: Backup Service Controller is running and BackupFP process is active."
Write-Output "Installed for Customer UID: $CUSTOMERUID"
$exitCode = 0
} else {
Write-Output "WARNING: Backup Service Controller or BackupFP process is not running as expected."
Write-Output "Customer UID: $CUSTOMERUID"
# Check log for errors
$logDirectory = "C:\ProgramData\mxb\Backup Manager\logs\ClientTool"
if (Test-Path $logDirectory) {
$latestLog = Get-ChildItem -Path $logDirectory -Filter "*.log" | Sort-Object LastWriteTime -Descending | Select-Object -First 1
if ($latestLog) {
$errorLines = Get-Content -Path $latestLog.FullName | Where-Object { $_ -match '\[E\]' } | Select-Object -Last 3
if ($errorLines) {
Write-Output "Recent errors from log:"
$errorLines | ForEach-Object { Write-Output $_ }
}
}
}
$exitCode = 1
}
$endTime = Get-Date
Write-Output "Installation completed in $([math]::Round(($endTime - $startTime).TotalSeconds, 2)) seconds."
exit $exitCode
```
1. Navigate to **Settings** > **CRM** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#crm#clientcustomfields):**
2. Add a custom field with the following details:
* **Name**: SentinelOne Site Token
* **Variable**: s1token
1. Navigate to a specific client
2. Click **Custom Fields.**
3. Edit **SentinelOne Site Token**.
4. Enter the Site Token retrieved from SentinelOne.
You can retrieve your SentinelOne Site Token from https\://\.[**sentinelone.net/dashboard**](http://sentinelone.net/dashboard). Navigate to a Site, then to the **Site Info** tab.
1. Navigate to **Settings** > Asset > **[Files](https://app.gorelo.io/Admin/admin-settings#asset#filerepository).**
2. Add a file with the following details:
* **File**: Upload the latest MSI installer
* **Variable**: S1Installer
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Install-SentinelOne.
* **Content**:
```powershell theme={null}
#Silently install SentinelOne
if($gorelo:client.s1token){
$S1Service = get-service -Name 'Sentinel Agent' -ErrorAction SilentlyContinue
if($S1Service -eq $null){
msiexec /i $gorelo:file.S1Installer SITE_TOKEN=$gorelo:client.s1token /quiet /norestart
}
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want SentinelOne installed on.
3. Add the **Install-SentinelOne** script and set to repeat daily at your preferred time.
4. **Distribute** the policy.
1. Navigate to **Settings** > **CRM** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#crm#clientcustomfields).**
2. Add custom field with the following details:
* **Name**: Bitdefender URL
* **Variable**: bitdefenderURL
1. Navigate to a specific client.
2. Click **Custom Fields.**
3. Edit **Bitdefender URL**.
4. Enter the install exe URL retrieved from Bitdefender for each client.
Bitdefender URL for the install exe should look like this (fake example): `htttps://cloudgz.gravityzone.bitdefender.com/Packages/BSTWIN/0/setupdownloader_[aHR0cHM6Ly9jbG91ZGdLWDawWVjcy5ncR5em9uZS5iaXRkZWZl3ddwawGfawdmRlci5jb20vUGFja2FnZXMvQlNUV0lOLzAvdkluc3RhbGxlci54bw-bGFuZz1lbi1VUw==].exe`
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Install-Bitdefender
* **Content**:
```powershell theme={null}
#$gorelo:client.bitdefenderURL
# Check if Bitdefender is already installed
if (Get-Service -Name "EPProtectedService" -ErrorAction SilentlyContinue) {
Write-Host "Bitdefender is already installed. Skipping installation."
exit 0
}
# Proceed with installation
$url = $gorelo:client.bitdefenderURL
$filename = Split-Path $url -Leaf
$installer = Join-Path $env:TEMP $filename
Write-Host "Downloading Bitdefender installer..."
(New-Object System.Net.WebClient).DownloadFile($url, $installer)
Write-Host "Installing Bitdefender..."
Start-Process -FilePath $installer -ArgumentList "/silent" -Wait
Remove-Item -LiteralPath $installer
# Verify installation
Start-Sleep -Seconds 10 # Give the service time to start
$service = Get-Service -Name "EPProtectedService" -ErrorAction SilentlyContinue
if ($service -and $service.Status -eq "Running") {
Write-Host "Installation successful! EPProtectedService is running."
exit 0
} else {
Write-Host "Installation may have failed. EPProtectedService not found or not running."
exit 1
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want Bitdefender installed on.
3. Add the **Install-Bitdefender** script and set to repeat daily at your preferred time.
4. **Distribute** the policy.
1. Navigate to **Settings** > **CRM** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#crm#clientcustomfields).**
2. Add custom field with the following details:
* **Name**: Webroot Key
* **Variable**: webrootKey
1. Navigate to a specific client.
2. Click **Custom Fields.**
3. Edit **Webroot Key**.
4. Enter the Webroot Key **[retrieved from Webroot](https://answers.webroot.com/Webroot/ukp.aspx?pid=17\&app=vw\&vw=1\&solutionid=984).**
1. Navigate to **Settings** > Asset > **[Files](https://app.gorelo.io/Admin/admin-settings#asset#filerepository).**
2. Add a file with the following details:
* **File**: Upload the latest MSI installer
* **Variable**: webrootInstaller
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Install-Webroot
* **Content**:
```powershell theme={null}
# Silently install Webroot
if($gorelo:client.webrootKey){
$WebrootService = Get-Service -Name 'WRSVC' -ErrorAction SilentlyContinue
if($WebrootService -eq $null){
msiexec /i $gorelo:file.webrootInstaller GUILIC=$gorelo:client.webrootKey CMDLINE=SME,quiet /qn /l*v install.log
}
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want Webroot installed on.
3. Add the **Install-Webroot** script and set to repeat daily at your preferred time.
4. **Distribute** the policy.
Alternatively, you can add the script as a remediation step for a Service Check, for example:
# Keyboard shortcuts
Source: https://help.gorelo.io/keyboard-shortcuts
Speed up work in Gorelo with keyboard shortcuts for tickets, navigation, and global actions, including new ticket, public reply, and tab management hotkeys.
## Everywhere
| **Press this** | **To do this** |
| :---------------- | :---------------------------------------------------------------- |
| Ctrl + X | Close all tabs (except the current one) |
| Shift + T | Create a new ticket |
| Ctrl + left click | Open item in a new Gorelo tab, e.g., tickets/assets from the list |
## Tickets
| **Press this** | **To do this** |
| :------------- | :---------------------------------- |
| R | Start a Public Reply |
| Ctrl + Enter | Post expanded comment (Public etc.) |
# Live Terminal
Source: https://help.gorelo.io/live-terminal
Access Windows assets remotely and run scripts through the embedded Live Terminal.
The **Live Terminal** in Gorelo allows you to connect to assets running on Windows and to execute your script collection directly from the Gorelo app. You can access the Live Terminal from your [assets list](https://app.gorelo.io/asset/asset-list):
1. In **Assets**, select an asset
2. From the asset detail page, in the sidebar, click **Live Terminal**.
## Core features
The Live Terminal connects you to the PowerShell terminal on a remote Windows machine, with the following elements in the control bar:
* **Connection status:** A status badge for the asset (**Connected/Disconnected**).
* **Retry:** Restart a session when the asset is disconnected.
* **AI Assistance:** Generate PowerShell scripts that run directly in the Live Terminal after you approve them.
* **PowerShell:** Use the `powershell.exe` command interpreter to run commands.
* **Command Prompt:** Use the `cmd.exe` DOS-lineage shell to run commands.
* **Run As User:** Run commands as the last logged-in user.
Run `whoami` to check the profile you're currently using in the Live Terminal.
## Related resources
Run scripts on Mac or Windows using the GoreloAction CLI.
Connect assets to Gorelo.
# Malwarebytes ThreatDown blocks Gorelo Connect
Source: https://help.gorelo.io/malwarebytes-threat-down-blocks-gorelo-connect
Resolve Malwarebytes ThreatDown blocking the Gorelo Connect installation by adding the Gorelo program folder and shell executable as APT Behavior exclusions.
## Problem
You’re using Malwarebytes ThreatDown and the install of Gorelo Connect is blocked by APT Behavior Protection.
## Solution
Add the following exceptions:
```text theme={null}
C:\Program Files\Gorelo
```
```text theme={null}
C:\Program Files\Gorelo\Agent\Shell\Gorelo.RemoteManagement.Shell\Gorelo.RemoteManagement.Shell.exe
```
```text theme={null}
C:\Program Files\Gorelo\Agent\Plugins\*\*.dll
```
```text theme={null}
C:\Program Files\Gorelo\Agent\RMMAgent\Gorelo.RemoteManagement.Agent\Gorelo.RemoteManagement.Agent.exe
```
# Mystery assets
Source: https://help.gorelo.io/mystery-assets
Understand why unknown assets appear in Gorelo when antivirus sandboxes run the agent installer, how to spot test machines, and how to safely remove them.
If you’re seeing unexpected assets appear — even though you haven’t installed the Gorelo RMM Agent on those endpoints — it can be a bit concerning. But in most cases, there’s no need to worry.
## What’s actually happening?
This usually comes down to how antivirus and other security tools work. Many modern security products automatically upload unfamiliar executables (like the Gorelo RMM Agent installer) to cloud-based sandbox environments for analysis. When that sandbox runs the executable, the agent is installed and shows up in your list of assets.
## How to spot assets created by sandboxing
When unknown assets appear, they’re often the result of anti-malware vendors testing the Gorelo RMM Agent in sandbox environments. Unfortunately, these vendors don’t publish naming conventions for their test machines, so identifying them isn’t always straightforward.
That said, there are a few common signs that an asset was created during automated AV/EDR testing:
### What to look for
| What to look for | Description | Examples/Causes |
| -------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Weird or generic hostnames | Anything that doesn’t follow your site’s usual naming standards. | `John-PC`, `Wilbert`, `Cuckoo`, `CWS`, or `ABC` |
| External IP address doesn’t match your environment | Look up the IP. | It resolves to something like: - Microsoft
- AWS
- A security software provider
|
| Missing or minimal audit data | These test assets usually don’t do much. Some may show a full audit, but most have little or no info. | |
| The asset only checked in once | It was online when created but hasn’t been back since. | Classic behavior of a sandboxed execution. |
| Low hardware specs | The asset may show the bare minimum hardware needed to run Windows or whatever OS is reported. | |
| Generic usernames | Usernames that are typical on test machines. | - `Administrator`
- `User`
- `Johndoe`
|
Even if your antivirus or EDR solution doesn’t use offsite sandbox testing, mystery assets can still appear if someone uploads the Gorelo RMM Agent installer to an online malware scanner.
For example, tools like **VirusTotal** let you upload files to scan across dozens of antivirus engines. If a teammate, security vendor, or anyone with access to your installer does this, it can trigger the agent to run in a sandbox — and that can create a new asset.
# Automatically assign a ticket based on events and time
Source: https://help.gorelo.io/notify-based-on-time-events
Create event and time automation rules in Gorelo to assign tickets, notify users, or trigger actions based on ticket creation, status changes, and unread state.
1. Navigate to Settings —> Automation —> [**Event and Time**](https://app.gorelo.io/Admin/admin-settings#automation#eventandtime)
2. Click ‘**+Automation Rule**’ up the top-right
3. Enter the details:
* **Title**: this is the title of the rule
* **When**: this is the trigger that the rule is based on
* **Condition**: these conditions must be met for the rule to apply (AND operator between each condition)
* **Then**: these are the actions that will then take place
**Tip!**
Automation Rules are forward-looking: they only evaluate triggers that occur after the rule is created. Think of creating a rule as drawing a line in time:
* If your trigger is 'Ticket Created': Only new tickets created after the rule setup will trigger the automation
* If your trigger is 'Ticket Status Updated': Only status changes that happen after the rule setup will trigger the automation
* If your trigger is 'Ticket is Unread': Only changes to the read/unread state that happen after the rule setup will trigger the automation
The rule doesn't retroactively look at past events or states - it only watches for new instances of your chosen trigger from the moment the rule is activated.
## Example: Notify @everyone
Notify @everyone when a ticket is:
* New
* Unread
* Unassigned for over 45mins
# Automate updates with Windows Patch Management
Source: https://help.gorelo.io/perform-automatic-updates-with-windows-patch-management-plugin
Deploy the Gorelo Windows Patch Management plugin to enforce automatic updates, deferrals, deadlines, and reboot behavior across managed Windows assets.
The **Windows Patch Management** plugin enables centralized control over Windows Updates across managed assets. This plugin functions similarly to Windows Update for Business (WUfB) and aligns with Microsoft's recommended practices—focusing on deferral, deadlines, and user experience rather than per-patch approval.
## Add the plugin
1. Navigate to **Policies**.
2. Select the **Windows** tab.
3. Click **+ Add** and select **Plugin**.
4. From the pop-up, select **Windows Patch Management**.
## How it works
This plugin configures **Windows Automatic Updates** via local policy, allowing devices to autonomously receive, install, and reboot for updates based on the settings defined in your Gorelo policy.
Once applied, these settings override local user preferences and are enforced until the policy is removed or modified.
## Update settings
From your **Policy** list, click the pencil icon to edit the Windows Patch Management plugin settings. This opens a pop-up with the following options.
| **Setting** | **Description** |
| :----------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Automatic update behavior** | Sets the update action: `Recommended: Auto install and restart at maintenance time`. **Auto install and restart at maintenance time**
Updates download automatically and then install during Automatic Maintenance when the device isn't in use or running on battery power. When restart is required, the device restarts when not being used. Use the Active hours settings to define a period during which the automatic restarts are blocked. **Auto download and schedule the install**
Automatically download updates and install them on the schedule specified below. When **"Automatic"** is selected as the scheduled install time, Windows will automatically check, download, and install updates. The device will reboot as per Windows default settings unless configured in **"Always automatically restart at scheduled time"** |
| **Active hours start/end** | For ‘Auto install and restart at maintenance time’. Prevents automatic restarts during working hours. |
| **Scheduled install day/time** | For ‘Auto download and schedule the install’. Updates are installed on this day/time. |
## Deadline for OS updates
These settings define how long an asset has to install updates before enforcement kicks in. If enabled, the asset will first attempt to install updates during regular maintenance time. If it fails to do so within the deadline, it enters a grace period where the user is prompted to schedule a restart. Once the grace period expires, the update and restart will be forced.
| **Setting** | **Description** |
| :------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Use Deadline settings** | If enabled, updates will be forced within set timeframes. |
| **Deadline for quality updates** | Number of days (0–30) after the update is offered that the asset has to install it before entering the grace period. `Recommended: 2 days` |
| **Deadline for feature updates** | Number of days (0–30) after the update is offered that the asset has to install it before entering the grace period. `Recommended: 7 days` |
| **Grace period** | Number of days (0–7) after the deadline where the user is prompted to restart or schedule a restart. After this, the device will force the restart. `Recommended: 2 days` |
| **Auto reboot before deadline** | If enabled, allows the system to automatically reboot to complete installation before the deadline expires. `Recommended: Yes` |
\
When aligning these settings with CIS Controls, Essential Eight, NIST etc., the deferral period + deadline + grace period define the total number of days. For example, if you require critical updates to be installed within 7 days of release:
* Quality update deferral period = 3 days
* Deadline for quality updates = 2 days
* Grace period = 2 days
* 3 + 2 + 2 = 7 — you’re now at the maximum of 7 days.
⚠️ It is recommended to start with this as ‘Not configured’ when first onboarding with Gorelo as this is the least impactful option. When you choose to change this to ‘Allow’, start with each of the deadline and grace period values much higher and slowly reduce them to your preferred number.
# How projects work
Source: https://help.gorelo.io/projects
Track multi-step client work in Gorelo Projects with tasks, timelines, checklists, time tracking, and a calendar-driven To Do list.
Technical Preview
The **Projects** module in Gorelo helps you track multi-step engagements and larger initiatives than tickets. You can assign a lead for each project, add tasks, streamline tickets, and collaborate with clients using the **Project** module.
## When to use projects
The **Project** module suits work that requires:
* Time tracking
* Collaboration through the **Client Portal**
* Multi-step processes and milestones
* Visibility for the client while keeping an internal trail
While [tickets](/tickets) are ideal for individual support tasks, the following table identifies scenarios that benefit from being managed as a project:
| Project type | How to use projects in Gorelo | Leveraged by... |
| ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| **Standardized client onboarding** | Create a consistent set of tasks for every new client you sign. Ensure that all necessary steps (setting up organization details, configuring hardware, and onboarding users) are followed precisely for every engagement. | - Project templates
- Checklist templates
- Customizable sections
- Template comments
|
| **Service and hosting migrations** | Define a specific set of tasks tailored to the client's environment (such as a WordPress migration), tracking each stage until the migration is 100% finished. | - Task dependencies
- Timeline
- Timer
|
| **Procurement and logistics management** | Track the acquisition and delivery of physical assets within the context of a larger deployment project. | - Shipment tracking
- Public conversation threads
|
| **Large-scale initiatives** | Manage work that exceeds the scope of a standard support ticket. | - Board (kanban) layout
- Client Portal sharing
- Priorities and due dates
- Private comments
|
The **Project** module simplifies tracking complex work using the following main features:
## Layouts
Navigate between three different layouts:
* **Timeline**: the project's tracking history, which you can manually complete by posting comments. The comments can be public (visible to everyone who has access to the project), private (visible only to your team), and/or fully or partially encrypted.
* **Table**: a list of all the project's tasks.
* **Board**: a Kanban view of all the project's tasks.
### Group tasks
Filter the view using the **Group by** option at the top of each view. You can group tasks by:
* **Sections:** Create and delete sections to categorize your work.
* **Statuses:** Gorelo provides four statuses for tasks, including *Not started*, *Working on It*, *On hold*, and *Done*.
## Tasks
You can manually add tasks and define:
* A title for the task
* An assignee
* A due date
* Assets and/or uptimes
* A priority level (from urgent to low)
Each task contains its own public and private timeline, within which you can add comments specifically to that task. Tasks are also interdependent: you can mark a task as blocked by or blocking another task. Third-party conversations with external providers are also available in tasks.
### Track time for tasks
Each task comes with an embedded timer you can click when you start working on the task. When you stop the timer and click **Add time**, a dialog appears to allow you to optionally upload files and add details. Once completed and submitted, time spent on the task appears in the **Time** tab in each task.
Alternatively, you can also add time manually in the **Time** section of each task.
### Products
Add products and bundles to tasks, and use the predefined sections or edit them as you see fit. Set them as **billable** or **non-billable**. If non-billable, you can select an option to hide the product from the client.
### Checklists
You can set checklists manually for each task or use templates. Gorelo provides predefined templates, but you can create custom ones. When creating a new checklist, click the **disk icon** to save it as a template and reuse it later on similar tasks.
### Shipment tracking
For hardware shipments, you can add a tracking number and carrier to each task and get notified when the shipment is delivered.
### Approval
Some tasks require steps to get approval from your designated [approver](/approve-and-invoice). Add them directly from the task to require approval, with a custom message detailing the action.
### Add tasks to your calendar
You can add each task to your Gorelo calendar and [M365 Outlook calendar](/outlook-calendar). To add a task, open it, scroll to the bottom of the right-hand menu, and click **ADD TO CALENDAR**. Once added, Gorelo lists the task in the **To Do** list alongside your calendar so you can track it from one place. Tasks that you never add to a calendar do not appear in the To Do list. The To Do list is populated from calendar entries, not from every project task.
See these guides to learn how to manage tasks and calendars in Gorelo:
Set up a project and create your first task.
Set up a two-way calendar sync between Gorelo and Outlook.
## FAQs
Yes, you can edit time spent and details. From the task, navigate to the **Time** tab, click the **three dots** of the relevant session, and select **Edit**.
# Publish a form
Source: https://help.gorelo.io/publish-form
Publish a Gorelo form to the Client Portal for client self-service, with options to scope visibility to specific clients or make the form available to all.
Forms can be published on the Client Portal for self-serve. If a client is specified, then it will only be published on their portal. If no client is specified, then it will be published on the portal for all clients.
1. Navigate to [**Forms**](https://app.gorelo.io/form/form-list) from the menu.
2. Select the form on the left.
3. Select the **Settings** tab.
4. Toggle on **Allow in portal** to publish this form on the Client Portal (for the specified clients).
# Quickstart
Source: https://help.gorelo.io/quickstart
Sign up for Gorelo, set up your organization, configure notifications, and deploy your first Gorelo Agent to start managing IT operations end-to-end.
Follow this guide to start using Gorelo. This guide walks you through the initial steps to get your account running, from signing up to deploying your first Gorelo Agent.
## Sign up
To create an account on Gorelo, navigate to [https://signup.gorelo.io/](https://signup.gorelo.io/) and follow the instructions:
Fill in the form with the following information:
* Organization name: the name of your company or organization.
* Your time zone: select the time zone that matches your location to ensure accurate scheduling and reporting.
* Your first and last name
* Your email address
Choose the option that best describes your organization:
* **Managed Service Provider (MSP):** If you provide IT services to multiple clients, select this option to manage all your clients from a single account.
* **Internal IT Team:** If you're managing IT for a single organization, select this option to focus on internal IT management features.
Add the number of technicians that will be using Gorelo. You can always add more users later.
Choose your sign-up option:
* **Azure AD SSO:** Sign up using your Azure Active Directory account for seamless integration and a single sign-on experience.
* **Email and Password:** Create an account using your email address and a secure password.
1. Click the **Azure AD** button.
2. When redirected to the Microsoft login page, enter your Azure AD credentials.
Once authenticated, Gorelo redirects you back and creates your account automatically.
1. Click the **Email and password** button.
2. Fill in your email address.
3. Create a secure password.
4. Check your inbox for a verification email from Gorelo, and click the verification link in the email to activate your account and log in to Gorelo.
Choose one region where you want Gorelo to host your data, and the currency you will be billed in. Available regions are the following:
| Region | Servers | Currency |
| ---------------------------------- | ------------------------------ | ------------------------------- |
| **United States (US)** | Microsoft Azure West US 2 | USD |
| **Australia (AU)** | Microsoft Azure Australia East | AUD |
## Set up your account
Once you're logged in, set up your account from one of these two options:
1. The wizard that pops up when you log in for the first time. You can reopen it at any time by clicking the red flag icon in the left menu.
2. Your account settings, by clicking the **Settings** option in the left menu.
### Set up your organization
If you choose to explore your **Settings** page, follow these steps for basic account setup:
Click **General** > **Organization** and fill in the following information about your organization:
* Email
* Phone number
* Address
From the **Organization** page, scroll down to the **Business Hours** form. Select the days and hours of operation for your organization. This information helps:
* Calculate SLA deadlines.
* Trigger after-hours notifications.
Setting up your location ensures that time-based data is accurate and consistent for:
* You.
* Your team.
* Your clients.
From the **Organization** page:
1. Scroll down to the **Location** form.
2. Click **+ Location**.
You can add as many locations as you need, and mark one of them as the default location by clicking the pin icon. When you mark a location as default, you automatically unmark the previous default location.
Fill in the following information about your location:
* Location name
* Time zone
From the **Settings** menu, invite more users to your organization by clicking **General** > **Users**, then:
1. Click the **+ User** button.
2. Fill in the user's information.
3. Set up the seat type for the user: **Full Access** (full access to all Gorelo resources), **PSA only** (access to the Remote Management module only), or **Co-managed** (access for clients scoped to their organization only).
4. Set up roles and permissions for the user.
* Gorelo provides predefined roles and permissions, but you are free to create new ones with fine-grained control in **Settings** > **Roles** > **+Add role**.
* Each user can have a different time zone and sign-on method.
### Set up domains and clients
These steps help you set up:
* **Custom domains** for custom email notifications and white labeling.
* **Clients** to organize your work and assign tickets and devices to specific clients.
From the **Settings** menu:
1. Click **Emails** > **Settings**.
2. Click the **+ Add Domain** button.
3. Fill in the name of your domain to obtain a `gorelo.` subdomain for your notifications.
After adding a domain, a pop-up automatically opens with instructions to verify your domain ownership and set up your DNS records. If you close the pop-up, you can reopen it by clicking the three dots menu on your domain, from your domains list.
Before you can use your custom domain, you need to verify ownership:
1. From the **Domains** section, click the domain you want to verify.
2. Click **Verify**.
3. Log in to your domain provider and add the provided DNS records to your domain settings.
Click the **copy** icon next to each name and value and paste them into your domain provider settings.
Import your client list from the **Settings** menu:
1. Click **Import**.
2. Select **Clients**.
3. Import using one of the following ways:
Import a file in one of the following formats:
* XLS file
* XLSX file
* CSV file
* Copy and paste table data
Copy and paste table data by clicking the option. Paste the table content and choose a delimiter. Delimiters can be:
* Comma
* Tab
* Semicolon
* Pipe
* Space
## Deploy your first Gorelo Agent
The final step is to install Gorelo Agent on a computer. To do so, follow these steps:
From the left menu, click **Assets**.
Select **Servers**, and from the servers page, click **+ Add Asset** > **Agent Asset**.
1. Add the name of the client for the device.
2. Click the **Request Agent** button.
1. Choose the device's OS:
* Windows
* macOS
2. Copy the installation command.
3. Open the device's terminal, and paste the script.
After running the script, your asset should appear on the Assets list.
### How to install Gorelo Agent remotely
If you don't have physical access to the machine, you need remote management software already installed to deploy the Gorelo Agent remotely.
## Troubleshooting
### Can't verify domain
Make sure the DNS records are correct. The required DNS records are:
| Record | Usage | Expected name field |
| --------- | ------------------------------------------------------------------------ | ------------------- |
| **MX** | Set up email routing for your custom domain | `gorelo` |
| **TXT** | Verify domain ownership and set up SPF and DKIM for email authentication | *idem* |
| **CNAME** | Set up DMARC for email authentication | `email.gorelo` |
## Next steps
Set up notifications to stay on top of important updates and events in your workflows.
Create a catalog of your products and services to easily add them to tickets and assets.
Fine-grained control over what your users can see and do in Gorelo.
Filter and segment your data with Views and Client Focus to find the information you need faster.
# Remote management overview
Source: https://help.gorelo.io/remote-management-overview
Use the Gorelo Agent for asset monitoring and Gorelo Connect for remote control, with comparison tables and deployment guides for both technician and assets.
Gorelo provides a range of remote management features for accessing and controlling remote machines. In this section, you can find guides on essential features like:
* **The Gorelo Agent:** essential software for asset management and monitoring.
* **Gorelo Connect:** a remote control and file explorer tool to remotely access the machines.
## How to start remote management with Gorelo
There are two main steps to get started with remote management in Gorelo, in that order:
1. Deploy the **Gorelo Agent** to your clients' devices to monitor their systems. When you deploy the Gorelo Agent, you automatically install Gorelo Connect on the computer you want to monitor. [Learn how to deploy the Gorelo Agent here](/deploy-gorelo-agent).
2. Install **Gorelo Connect** on your technician’s computer to access the remote machines from it. [Learn how to install Gorelo Connect on the technician’s side here](/install-gorelo-connect).
### Gorelo Agent vs. Gorelo Connect
The following table outlines the key differences between the Gorelo Agent and Gorelo Connect, two essential components of Gorelo's remote management solution:
| Feature | Gorelo Agent | Gorelo Connect |
| --------------------------------------------- | --------------------------------------------- | ------------------------------------------------ |
| Monitoring | ✅ | ❌ |
| Remote access and control for technicians. | ❌ | ✅ |
| Installed on Technician Computer | ❌ | ✅ |
| Installed on Client Computer | ✅ | ✅ (installed alongside the Gorelo Agent) |
| Asset tracking | ✅ | ❌ |
| Client/location association | ✅ | ❌ |
| Screen sharing, remote control, file browsing | ❌ | ✅ |
| Deployment method | PowerShell or manual install (Windows/macOS). | Policies/ **Connect** button from the dashboard. |
| Relationship | Required for broader device management. | Works alongside the Gorelo Agent. |
| [Live Terminal](/live-terminal) | ✅ | ❌ |
Install the Gorelo Agent on your clients' devices to monitor their systems.
Install Gorelo Connect on your technician’s computer to remotely access and control your clients' machines.
## Remote management features
Once you've connected the devices to Gorelo with the Agent and Gorelo Connect, you're ready to explore the remote management features that Gorelo provides.
Monitor the availability and performance of your devices.
Write and test scripts to automate tasks.
Distribute checks, plugins, and scripts to assets based on asset tags.
Group and manage your assets using tags.
Technical Preview
Access remote assets's PowerShell and run scripts with AI assistance.
## Script examples
Useful for things such as BitLocker keys, rotating local admin passwords, and third-party UID’s.
Install SentinelOne, Cove, DNSFilter, etc.
Integrate other tools in Gorelo, like Splashtop, AnyDesk, TeamViewer, etc.
Create a list of assets that are Windows 11 compatible or not.
Set up automatic local admin password rotation in Gorelo.
Create a script with Slide.
Send a WOL packet to a MAC address entered at runtime.
Use an AI assistant to create a script that uses GoreloAction.
# Rotate local admin passwords
Source: https://help.gorelo.io/rotate-local-admin-passwords
Automate local admin password rotation in Gorelo with a PowerShell script that creates the account, sets a secure password, and stores it in a custom field.
This guide helps you set up automatic local admin password rotation in Gorelo. The script creates a local admin account (if it doesn't exist), assigns it to the local administrators group, sets a secure random password, and stores that password in Gorelo for easy retrieval.
1. Navigate to **Settings** > **Assets** > **[Custom Fields](https://app.gorelo.io/admin/admin-settings#asset#assetcustomfields).**
2. Add a custom field with the following details:
* **Name**: Local Admin Password
* **Variable**: localadminpassword
* **Type**: Text
* Toggle on **Show on Asset Detail** and **Blue value**.
3. Click **Save.**
1. Navigate to **[Scripts](https://app.gorelo.io/asset/script-list).**
2. Create a new script with the following details:
* **Name**: 🔐 Set-LocalAdminPassword
* **Platform**: Windows
* **Content**: *\[Copy the PowerShell script provided below]*
3. Click **Save.**
```powershell theme={null}
# =========================================================================
# Simple Local Admin Password Management Script for Gorelo RMM
# =========================================================================
# Configuration variables - change as needed
$localAdminAccount = "localadmin"
$accountFullName = "Local Administrator"
$accountDescription = ""
$hideFromLogonScreen = $true # Set to $false to show the account on logon screen
try {
# Generate a strong random password
$CharSet = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_=+[]{}|;:,.<>?"
$Password = ""
$Random = New-Object System.Random
# Create a 16-character random password
1..16 | ForEach-Object { $Password += $CharSet[$Random.Next(0, $CharSet.Length)] }
# Check if the account exists
$userExists = Get-LocalUser -Name $localAdminAccount -ErrorAction SilentlyContinue
if (-not $userExists) {
# Create the account if it doesn't exist
$securePassword = $Password | ConvertTo-SecureString -AsPlainText -Force
New-LocalUser -Name $localAdminAccount -Password $securePassword -FullName $accountFullName -Description $accountDescription -AccountNeverExpires | Out-Null
Add-LocalGroupMember -Group "Administrators" -Member $localAdminAccount
Write-Output "Created local admin account: $localAdminAccount"
} else {
# Update password if account exists
$securePassword = $Password | ConvertTo-SecureString -AsPlainText -Force
Set-LocalUser -Name $localAdminAccount -Password $securePassword -FullName $accountFullName -Description $accountDescription
Write-Output "Updated password for: $localAdminAccount"
# Check if user is already in Administrators group, add if not
$adminGroup = Get-LocalGroupMember -Group "Administrators" -ErrorAction SilentlyContinue
$isAdmin = $adminGroup | Where-Object { $_.Name -like "*\$localAdminAccount" -or $_.Name -eq $localAdminAccount }
if (-not $isAdmin) {
Add-LocalGroupMember -Group "Administrators" -Member $localAdminAccount
Write-Output "Added $localAdminAccount to Administrators group"
}
}
# Configure account visibility on logon screen
if ($hideFromLogonScreen) {
# Hide the account from logon screen
$registryPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
if (-not (Test-Path $registryPath)) {
New-Item -Path $registryPath -Force | Out-Null
}
Set-ItemProperty -Path $registryPath -Name $localAdminAccount -Value 0 -Type DWORD -Force
Write-Output "Account hidden from logon screen"
} else {
# Show the account on logon screen (by removing the registry entry if it exists)
$registryPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
if (Test-Path $registryPath) {
if (Get-ItemProperty -Path $registryPath -Name $localAdminAccount -ErrorAction SilentlyContinue) {
Remove-ItemProperty -Path $registryPath -Name $localAdminAccount -Force
}
}
Write-Output "Account visible on logon screen"
}
# Store the password in Gorelo RMM
GoreloAction -SetCustomField -Name "asset.localadminpassword" -Value $Password
Write-Output "Password stored in custom field"
} catch {
# Output error to console for on-demand runs
Write-Error "Error managing local admin account: $_"
exit 1
}
```
1. Navigate to **[Assets](https://app.gorelo.io/asset/asset-list).**
2. Select any asset where the script has run.
3. View the **Custom Fields** section to see the stored Local Admin Password.
4. Click the reveal icon to display the password when needed.
## Customize the script
The script includes several variables at the top that you can modify:
* `$localAdminAccount` = "localadmin" # The username for the local admin account
* `$accountFullName` = "Local Administrator" # The full name for the account
* `$accountDescription` = "" # The account description (optional)
* `$hideFromLogonScreen` = `$true` # Set to `$false` to show the account on logon screen
Adjust these variables to suit your organization's needs before deploying the script.
# Service delivery overview
Source: https://help.gorelo.io/sd-overview
Get an overview of Gorelo's service delivery tools for tickets, alerts, knowledge, collaboration, and AI automation to manage IT operations end-to-end.
Gorelo provides a suite of tools to monitor and manage your IT operations, collaborate with your team and clients, and automate your workflows with AI. This overview will give you a brief introduction to each of these tools and how they can benefit your organization.
## Operations
Track and manage your IT operations with tickets and alerts. Capture and organize all your work in one place, and use powerful features to stay on top of everything.
Track and manage your work with tickets and their powerful features.
Set up alerts to monitor your systems and get notified of important events.
Manage and track complex tasks, create templates for recurring workflows and collaborate with your team and clients.
Standardize workflows and ensure consistent service delivery across different clients with checklist templates.
## Knowledge
Share information and documentation with your team and clients. Keep everyone aligned with centralized documents and forms.
Create and organize your internal and client-facing documentation in one place.
Create and manage forms to collect information from your team and clients.
## CRM (Customer Relationship Management)
Organize your clients and contacts, and keep track of important information about them. Use this information to provide better service and deliver a better experience.
Add and manage your clients and their managed devices.
Add and manage your contacts, assign them to tickets, and designate approvers.
Set up custom domains for your senders.
Create and manage your passwords in one place, using 1Password integration.
## Automate with AI
Use AI to automate your workflows and save time on repetitive tasks. From generating replies to summarizing tickets, AI can help you work smarter, not harder.
Leverage AI to get a sentiment analysis from a ticket and prioritize your work.
Use AI to get a summary of a ticket and quickly understand the issue.
Use AI to automatically generate tags for your tickets and keep them organized.
Use AI to automatically assign a ticket type based on its content.
Use time and events to automatically update or close tickets.
Use AI to automatically assign a ticket to the right person or group.
Create your own custom prompts to either generate replies or rephrase text.
# Search in Gorelo
Source: https://help.gorelo.io/search
Use Quick Search and Deep Search in Gorelo to find tickets, assets, clients, contacts, invoices, and documents across the platform, with handy shortcuts.
Search serves as a powerful tool in Gorelo to save time and find almost anything across the platform. To access Search, navigate to the top right corner and click the magnifying glass:
## Quick search
The default search option is **Quick Search**: this will search across many areas of Gorelo: Tickets, Assets, Clients, Contacts, Invoices, and Documents.
The quick search only searches ticket numbers and titles.
## Deep search
To search within ticket comments and time entries, switch to the Tickets tab.
## Shortcuts
Quick shortcuts appear on the right side of each search result and allow you to skip a few clicks:
* **Assets** —> CLI and Remote Connection
* **Clients** —> Tickets, Assets, Contacts, Invoices, Contracts and Docs
* **Contacts** —> Client and Tickets
## Show all tickets
To show all tickets chronologically, click the ‘Show All Tickets’ button up the top right. You can also apply a Client Focus and a date range to narrow things down.
## Next steps
Stay on top of priorities with Gorelo.
Step-by-step guides to get things done with Gorelo.
# Get a sentiment analysis from a ticket
Source: https://help.gorelo.io/sentiment-analysis
Use Gorelo AI Sentiment Analysis to score inbound ticket comments and notify groups when negativity exceeds your threshold so you can act fast on issues.
Sentiment Analysis automatically scores the emotional tone of inbound comments (Public, Third Party, Approval). It then notifies your designated groups when the score is below your configured negativity threshold, allowing you to quickly identify and address potentially dissatisfied clients before issues escalate.
## Enable sentiment analysis
1. Go to **Settings → AI →** [**Sentiment Analysis**](https://app.gorelo.io/admin/admin-settings#ai#customersentiment)
2. Toggle **Sentiment Analysis** on
3. Set your **Score Range** and what you classify as Negative/Positive
4. Toggle whether you’d like to score the first comment.\
NOTE: First comments will typically score lower due to the inherent nature of support requests.
5. Select which **Groups** should receive notifications when a comment is classified as negative
6. Click **Update**
## How it works
* AI analyzes the text of each inbound comment (Public, Third Party, Approval)
* Each comment receives a sentiment score (ranging from 1 to 100)
* Negative scores indicate unhappy clients (1 being extremely negative)
* When a comment's score falls below your negative threshold, notifications are sent to the designated groups
* To see the sentiment score, hover over the profile icon next to each comment in the ticket timeline
## Troubleshooting
**Too many notifications?** Adjust your threshold to a lower value (more negative) to only be alerted for very negative comments.
**Missing negative comments?** Move your threshold to a higher value (less negative) to catch more subtle expressions of dissatisfaction.
**Non-English comments?** Sentiment Analysis supports multiple languages, but may be most accurate with English content.
# Set a labor rate
Source: https://help.gorelo.io/set-a-labor-rate
Configure labor rates in Gorelo by setting a base hourly rate for each Billing Role and a multiplier for each Work Type to bill accurately for every ticket.
Configure labor rates based on the billing role and the type of work you're invoicing.
* **Billing Role**: The name of the billing role, e.g., Technician
* **Hourly Rate**: The ‘per hour’ rate, e.g., 100
* **COA Code**: Select the COA (Chart of Accounts) code that will sync to invoices in Xero/QBO, e.g., 4200 (Labor). If nothing is selected, your default COA from the Xero/QBO integration will be used.
Click ‘**+Work Type**’ up the top-right or edit an existing one.
* **Work Type**: The name of the work type (for example, "Remote Support").
* **Hourly Multiplier**: The multiplier applied to the Billing Role.
* **Billable**: Select the Billable status.
* **COA Code**: Select the COA (Chart of Accounts) code that will sync to invoices in Xero/QBO, e.g., 4800 (Projects). If nothing is selected, the Billing Role COA will be used.
# Set up notifications
Source: https://help.gorelo.io/set-up-notifications
Set up Gorelo notifications to surface ticket updates, alerts, and assignments in the bell pane and mobile push, so you never miss client-impacting events.
Notifications are a critical feature in Gorelo. They allow you to act as soon as an issue on your client's side appears and more. Learn on this page how to make use of them properly.
Here’s what notifications look like in a production setting:
Expand the notification pane by using the bell icon in the top right. Consider keeping it open permanently to make sure you don't miss anything.
If collapsed, the bell icon will show how many new notifications popped up since you last expanded.
Gorelo generates one notification card per ticket — and subsequent notifications on the same ticket will stack the cards (just like iOS or Android).
## What info you find in a notification card
The lines in the previous image contain:
1. The title of the ticket.
2. The client's name.
3. The content of the notification (for example: private comment, status change, time entry).
## Critical notification highlights
Gorelo considers **public comments** and **@mentions** (individuals or groups) as critical. Therefore, it highlights them with icons if they’re buried under a stack of other notifications.
## Dismiss a notification
Dismiss a single notification card by hovering and clicking the X in the top-right OR the entire stack by hovering and clicking ‘Dismiss all’.
From the top right on your notifications pane, you can also:
* Dismiss all notifications.
* Dismiss all notifications from closed tickets.
## Subscribe to notifications
There are two types of ticket notifications you can choose to subscribe to:
* **Newly created tickets**.
* **Tickets assigned to you**.
You can also choose to subscribe to Critical Alerts and receive them as a native iOS/Android notification.
1. Navigate to your Profile icon up the top right and then to [**Settings**](https://app.gorelo.io/application/setting)**.**
2. Scroll down to Notification Subscription
3. Toggle on/off where needed.
Tips!
* Larger MSPs will find they have most users toggling off 'Ticket created’ to reduce noise and leave that to the triage team.
## Next steps
Create boards with filters and save them, then filter by client.
The most powerful and accurate tool in Gorelo.
# Sort tickets with Ticket Types
Source: https://help.gorelo.io/sort-with-tickets-types
Enable Ticket Types in Gorelo to sort tickets with custom categories, optionally require a type per ticket, and assign types automatically using AI.
Ticket Types help sort tickets. You can:
* Create your own custom types.
* Require the selection on each ticket.
* Automatically assign the correct type via AI.
## Enable ticket types
1. Navigate to **Settings** > **Tickets** > **Type**.
2. Toggle **Ticket Type** on.
3. Select between Required or Default.
* **Required**: Ticket Type field will start blank and require selection via AI or manual entry.
* **Default**: The automation will prefill the Ticket Type field with incidents. You can change it via AI or manual entry if needed.
4. Add/Edit Ticket Types if required
Enable [**Auto Ticket Types**](/automated-ticket-types) via AI to get the most value.
## Assign a type to a ticket
1. Open a ticket.
2. In the right pane, check the **Info** tab.
3. Scroll down to Types, and open the dropdown menu.
4. Click the Type
## Sort tickets by type
To sort tickets by type, leverage the **View** feature:
1. From the left general menu, open Tickets. A list of all your tickets appears.
2. At the bottom of the left pane, click the option **+ Create View**.
3. Add a name and scroll down, click **View Additional Fields**.
4. From the **Ticket Type** option, select the Type to filter tickets by.
5. Scroll up to the top and click **Save**.
Once saved, your new View automatically displays all tickets by the selected Type. Gorelo lists this new View in the left pane.
# Dissociate contacts from a domain
Source: https://help.gorelo.io/stip-contacts-from-a-domain
Use Stripped Domains in Gorelo to dissociate contacts from a specific email domain so vendor or alias addresses don't create unwanted contact records.
1. Navigate to Settings —> Email —> [**Stripped Domains**](https://app.gorelo.io/Admin/admin-settings#email#strippeddomains)
2. Click ‘**+ Stripped Domain**’ in the top-right
3. Enter the domain name, e.g., [**huntress.io**](http://huntress.io)
4. Click **Save**
# Summarize a ticket with AI
Source: https://help.gorelo.io/summarize-ticket
Use the Gorelo Ticket Summary AI feature to generate a concise rundown of a ticket's full timeline so you can catch up without scrolling every comment.
Ticket Summary gives you a quick rundown of a ticket’s entire timeline. It’s perfect for catching up on long threads without scrolling through every single comment.
## How to summarize a ticket
1. Go to the **Ticket Detail** page for any ticket
2. Click the Summary button in the top-right corner of the timeline
3. AI will give you a summary of everything that went on.
# How tickets work
Source: https://help.gorelo.io/tickets
Tickets in Gorelo capture client requests with conversations, statuses, assignees, time entries, and products. Learn the anatomy and ticket lifecycle.
A ticket is the record for a client request or issue in Gorelo. It allows you to track the work from start to finish. The Ticket Detail page captures:
* The conversation
* Status
* Assignees
* Time entries
* Products
* Related details
## Ticket details page
A ticket details page contains the following sections:
### Header
The top area of a ticket shows the following details:
* **Ticket number:** automatically attributed, you can't edit it.
* **Ticket Title:** hover it and click the pencil icon to rename a ticket.
* **Client and Location:** click the area to change it.
* **To and Cc** contacts: click the area to add or remove contacts.
* **Status:** click the label and scroll the options to change the status.
* 3-dot menu with:
* **The ticket link** to share it.
* **Merge with** to merge the current ticket's data into another ticket or a [project task](/projects#tasks). The source ticket becomes part of the target ticket, decreasing the number of tickets.
* **Billing** to link the ticket to a [contract](/contracts-overview).
* **QR code label** linked to the contract to print or view.
* **Banner** to set a banner over the ticket (for warnings, etc.).
* The option to mark the ticket as **read/unread.**
### Timeline
The activity feed of a ticket that records all interactions and updates related to the ticket. It includes:
* Timeline tabs
* Plus (+) button to add **Third-party conversations**, **Shipment Tracking**, **Checklists** and [**Approvals**](/create-an-approval-workflow)
* Timeline entries
### Comment box
The editor where you write public or private comments and send updates on a ticket. Allows the following actions:
* Click to type a private comment (anywhere not underlined)
* Click ‘**private comment**’ to expand and type a private comment
* Click ‘**public comment**’ to expand and type a public comment (sent via email)
* Ticket Shortcuts off to the far-right
### Info panel
The side panel for operational details that allows you to:
* Add **time in two ways:**
* Using the **ticket time tracker:** click the start icon to launch a timer and track the time you spend on a ticket.
* **Manually:** hover over the numbers and click **ADD TIME** to add the time spent on this ticket.
* **Products**
* Add/remove **assignees**
* Add/remove **assets** and **uptime**
* Add/remove **tags**
* Change **priority**
* Add/remove **groups**
* Add to **calendar**
## Ticket statuses
Tickets in Gorelo have the following statuses that indicate where the ticket is in its lifecycle:
| Status | Description | Example |
| ------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| New | Automatically applied to newly created tickets. Indicates the ticket is under initial review or triage. | A ticket created via email with a public comment. |
| Open | Work has started and the ticket is assigned to a user. | A teammate begins investigating and replies to the requester. |
| On Hold | Work is paused for an external dependency or response. | Waiting on a vendor update or client reply. |
| Solved | The main issue is resolved, but follow-up tasks may remain. | The fix is applied and you’re waiting for confirmation. |
| Closed | All work is complete and no further action is required. | The requester confirms the issue is resolved. |
You can't manually change the status of a ticket to **New**.
# Use checklists to track your work
Source: https://help.gorelo.io/track-and-assign-work
Add checklists to Gorelo tickets to track your work, assign items to teammates, set due dates, and keep complex projects consistent from start to finish.
## Create and use checklists
1. Navigate to a ticket
2. Click the **+** button in the timeline tab and add a **Checklist**
1. Modify the name (optional) and click Save
2. You can now add checklist items:
* Put your cursor in the **Name** field and type something, e.g., Order hardware
* **Assign** someone and set a **due date** (both optional)
* Click the ✔️ button to add (or press Enter if your cursor is still in the Name field)
Tips!
* Use the tick box to complete items (on the far left)
* Use the grabby icon to rearrange items (on the far left)
* Use Tab to indent items
* Type // in the name field to embed items
* Toggle ‘Incomplete Only’ to view only incomplete items (top-right)
* Toggle ‘Assigned to me’ to view only items assigned to you (top-right)
## Create a checklist template
1. Create a checklist (as per above) that you would like to save as a template
2. Click the 💾 button (top-right) to save as a template
* **Name**: this is the name of the checklist template and it can be changed later, e.g., New Computer Setup
* **Visibility**: this determines who can see and use this template
* Public = everyone
* Private = only you
* Shortcut = only visible via Ticket Shortcuts
* Click **Save**
## Use and edit checklist templates
1. Create or navigate to an existing ticket
2. Click the **+** button in the timeline tab and add a **Checklist**
3. From the Template dropdown, select the appropriate template
4. Use the **Edit** and **Delete** icons on the right
5. Checklist templates can be edited in many ways
* Name can be changed
* Order can be changed
* Items can be added/removed
* Assignees can be added/removed
* Relative due dates can be set, e.g., 7 days would mean the item is due 7 days after the checklist template was added to the ticket
# Troubleshooting tickets
Source: https://help.gorelo.io/troubleshooting-tickets
Resolve common Gorelo ticket issues including grayed-out Add to Calendar, time zone mismatches, and other workflow problems with step-by-step solutions.
| **Problem** | **Description** | Cause | Solution |
| -------------------------------- | ----------------------------------------------- | ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **'Add to calendar' grayed out** | The ‘Add to calendar’ button may be grayed out. | The ticket's status **Closed** | Change the ticket status to anything other than Closed (**Open** or **On Hold**) |
| | | The **time zone** of the user (in Gorelo) is different than their computer/browser | - Navigate to Settings → General → Users
- Edit the user and make sure their time zone is the same as what’s on their computer/browser.
|
# Uninstall the Gorelo Agent
Source: https://help.gorelo.io/uninstall-gorelo-agent
Clean uninstall the Gorelo Agent from Windows or macOS using a PowerShell script that stops services, deletes processes, and removes installation files.
This script will carry out a clean uninstall of the Gorelo Agent:
```powershell theme={null}
# Stop all Gorelo-related processes
$processes = "Gorelo.Rmm.Installer", "Gorelo.Rmm.Installer.Handler", "Gorelo.RemoteManagement.Shell", "Gorelo.RemoteManagement.Agent", "TrayApp"
$processes | ForEach-Object { Stop-Process -Name $_ -Force -ErrorAction Ignore }
# Delete Gorelo services
"gorelo.rmm.installer", "gorelo.rmm.shell" | ForEach-Object {
if (Get-Service -Name $_ -ErrorAction Ignore) { sc.exe delete $_ }
}
# Remove Gorelo program folder
Remove-Item -Path "$Env:ProgramFiles\Gorelo" -Recurse -Force -ErrorAction Ignore -Confirm:$false;
Remove-Item -Path "$Env:ProgramFiles (x86)\Gorelo" -Recurse -Force -ErrorAction Ignore -Confirm:$false;
# Remove Gorelo registry key
# Note: Retaining this key will allow for a repair install
Remove-Item "HKLM:\SOFTWARE\Gorelo" -Recurse -Force -ErrorAction Ignore
```
```shellscript theme={null}
DIR="/Library/Gorelo"
PLISTS=(
"/Library/LaunchDaemons/com.gorelo.agent.plist"
"/Library/LaunchDaemons/com.gorelo.installer.plist"
)
if [ -d "$DIR" ]; then
for plist in "${PLISTS[@]}"; do
if [ -f "$plist" ]; then
sudo launchctl unload "$plist"
sudo rm "$plist"
fi
done
sudo rm -R "$DIR"
sudo defaults delete com.gorelo.app
echo "Gorelo uninstallation complete."
fi
```
# Uninstall Gorelo Connect
Source: https://help.gorelo.io/uninstall-gorelo-connect
Clean uninstall Gorelo Connect and the Gorelo Launcher from Windows using a PowerShell script, with a warning that reinstall is required to restore access.
This script will carry out a clean uninstall of Gorelo Connect and Gorelo Launcher:
This will **break the Gorelo Connect plugin** if installed. Reinstall the Gorelo Connect plugin to restore remote access to this specific asset.
```powershell theme={null}
# Uninstall GoreloConnect
$goreloConnectReg = Get-ChildItem -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall' |
ForEach-Object { Get-ItemProperty $_.PSPath } |
Where-Object { $_.DisplayName -like '*GoreloConnect*' }
if ($goreloConnectReg.UninstallString) {
Start-Process "cmd.exe" -ArgumentList "/c $($goreloConnectReg.UninstallString) /S -Force" -Wait -NoNewWindow
}
# Get all user profiles
$userProfiles = Get-ChildItem "C:\Users" -Directory
# Remove GoreloConnect and GoreloLauncher components for all users
foreach ($profile in $userProfiles) {
# Remove GoreloConnect components
Remove-Item "C:\Users\$($profile.Name)\AppData\Roaming\GoreloConnect" -Recurse -Force -ErrorAction SilentlyContinue
# Remove GoreloLauncher components
Remove-Item "C:\Users\$($profile.Name)\Downloads\GoreloLauncher.exe" -Force -ErrorAction SilentlyContinue
Remove-Item "C:\Users\$($profile.Name)\AppData\Local\GoreloLauncher\config.dat" -Force -ErrorAction SilentlyContinue
Remove-Item "C:\Users\$($profile.Name)\AppData\Local\GoreloLauncher" -Recurse -Force -ErrorAction SilentlyContinue
}
# Remove global GoreloLauncher components
Remove-Item "Registry::HKEY_CLASSES_ROOT\GoreloLauncher" -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item "C:\Program Files\GoreloLauncher" -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item "C:\ProgramData\GoreloLauncher" -Recurse -Force -ErrorAction SilentlyContinue
# NOTE! This will break the Gorelo Connect plugin if installed. Reinstall the Gorelo Connect plugin to restore remote access to this specific asset.
```
```shellscript theme={null}
APP_NAME="GoreloLauncher"
DMG_NAME="$APP_NAME.dmg"
APP_DIR="$APP_NAME.app"
APP_FOLDER="$APP_NAME"
DOWNLOADS_DIR="$HOME/Downloads"
APPLICATIONS_DIR="/Applications"
echo "Starting cleanup for $APP_NAME ..."
if [ -f "$DOWNLOADS_DIR/$DMG_NAME" ]; then
echo "Deleting $DOWNLOADS_DIR/$DMG_NAME"
rm -f "$DOWNLOADS_DIR/$DMG_NAME"
else
echo "No DMG found: $DOWNLOADS_DIR/$DMG_NAME"
fi
if [ -d "$APPLICATIONS_DIR/$APP_DIR" ]; then
echo "Deleting $APPLICATIONS_DIR/$APP_DIR"
rm -rf "$APPLICATIONS_DIR/$APP_DIR"
else
echo "No .app found: $APPLICATIONS_DIR/$APP_DIR"
fi
if [ -d "$APPLICATIONS_DIR/$APP_FOLDER" ]; then
echo "Deleting $APPLICATIONS_DIR/$APP_FOLDER"
rm -rf "$APPLICATIONS_DIR/$APP_FOLDER"
else
echo "No folder found: $APPLICATIONS_DIR/$APP_FOLDER"
fi
echo "GoreloConnect uninstallation complete"
```
This will break the Gorelo Connect plugin if installed. Reinstall the Gorelo Connect plugin to restore remote access to this specific asset.
# Use variables at runtime
Source: https://help.gorelo.io/use-variables-at-runtime
Use Gorelo script variables left blank at design time to prompt for input during on-demand CLI runs, ideal for Wake on LAN and ad-hoc PowerShell tasks.
You can leave a script variable blank and have it prompt the user when run on-demand via the CLI. This example sends a WOL packet to a MAC address entered at runtime.
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Wake on LAN
* **Content**:
```powershell theme={null}
$MacToWake = $gorelo:MacToWake
function Send-WoL {
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$MacAddress,
# Optional: force a specific interface by alias (e.g., "Wi-Fi")
[string]$InterfaceAlias
)
# --- Normalize & validate MAC ---
$norm = $MacAddress -replace '[:\-\. ]',''
if ($norm -notmatch '^[0-9A-Fa-f]{12}$') { throw "Invalid MAC after normalization: '$norm'." }
$macBytes = New-Object byte[] 6
for ($i = 0; $i -lt 12; $i += 2) { $macBytes[$i/2] = [Convert]::ToByte($norm.Substring($i,2),16) }
# --- Build magic packet ---
$packet = New-Object byte[] (6 + 16*6)
for ($i=0; $i -lt 6; $i++) { $packet[$i] = 0xFF }
for ($block=0; $block -lt 16; $block++) { [Array]::Copy($macBytes, 0, $packet, 6 + ($block*6), 6) }
# --- Pick active IPv4 from interface with best default route (0.0.0.0/0) ---
$route = Get-NetRoute -DestinationPrefix '0.0.0.0/0' -ErrorAction SilentlyContinue |
Sort-Object -Property RouteMetric, InterfaceMetric |
Select-Object -First 1
$ipRec = $null
if ($InterfaceAlias) {
$ipRec = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $InterfaceAlias -ErrorAction SilentlyContinue |
Where-Object { $_.IPAddress -notlike '169.254*' -and $_.IPAddress -ne '127.0.0.1' } |
Sort-Object -Property PrefixLength -Descending |
Select-Object -First 1
}
if (-not $ipRec -and $route) {
$ipRec = Get-NetIPAddress -AddressFamily IPv4 -InterfaceIndex $route.InterfaceIndex -ErrorAction SilentlyContinue |
Where-Object { $_.IPAddress -notlike '169.254*' -and $_.IPAddress -ne '127.0.0.1' } |
Select-Object -First 1
}
if (-not $ipRec) {
$ipRec = Get-NetIPAddress -AddressFamily IPv4 -ErrorAction SilentlyContinue |
Where-Object { $_.IPAddress -notlike '169.254*' -and $_.IPAddress -ne '127.0.0.1' } |
Select-Object -First 1
}
if (-not $ipRec) { throw "Couldn't detect a valid IPv4 address." }
$ipBytes = ([System.Net.IPAddress]::Parse($ipRec.IPAddress)).GetAddressBytes()
$prefix = [int]$ipRec.PrefixLength
# --- Build subnet mask bytes from prefix length (no Int32 conversion) ---
$maskBytes = 0,0,0,0
$bits = $prefix
for ($i=0; $i -lt 4; $i++) {
if ($bits -ge 8) { $maskBytes[$i] = 255; $bits -= 8 }
elseif ($bits -gt 0) {
$maskBytes[$i] = (0xFF - ( [math]::Pow(2, (8 - $bits)) - 1 )) -band 0xFF
$bits = 0
} else { $maskBytes[$i] = 0 }
}
# --- Compute broadcast: ip OR (NOT mask) (byte-wise) ---
$broadcastBytes = New-Object byte[] 4
for ($i=0; $i -lt 4; $i++) {
$invMask = (0xFF - $maskBytes[$i]) -band 0xFF
$broadcastBytes[$i] = ($ipBytes[$i] -bor $invMask) -band 0xFF
}
$broadcast = [System.Net.IPAddress]::new($broadcastBytes)
# --- Send to common WoL ports ---
foreach ($port in 9,7) {
$udp = New-Object System.Net.Sockets.UdpClient
$udp.EnableBroadcast = $true
$endpoint = New-Object System.Net.IPEndPoint $broadcast, $port
[void]$udp.Send($packet, $packet.Length, $endpoint)
$udp.Close()
Write-Host "Magic packet sent to $MacAddress via $($broadcast.ToString()):$port"
}
}
# Example:
# Send-WoL -MacAddress "98:FA:9B:55:B4:50"
# Or force a specific adapter:
# Send-WoL -MacAddress "98:FA:9B:55:B4:50" -InterfaceAlias "Wi-Fi"
# Example usage
Send-WoL -MacAddress $MacToWake
```
Write MAC address to a custom field script in **[this guide](/install-via-custom-fields).**
# What are assets
Source: https://help.gorelo.io/what-are-assets
Assets in Gorelo are the devices and endpoints you manage, including Agent assets running the Gorelo Agent and custom assets like printers and routers.
Assets in Gorelo are devices and endpoints that you manage through Gorelo. You add an asset to your float by clicking **Assets**, and the **+Add an asset** button.
There are two kinds of assets in Gorelo:
* **Agent assets:** A managed device running the Gorelo Agent.
* **Custom assets:** Any other hardware. Gorelo provides a predefined custom asset list for access points, desktops or laptops, hypervisors, routers, printers, and phones. Add your own custom assets from **Settings** > **Asset** > **Setting**.
The Assets feature lets you:
* [Group assets with tags.](/group-assets-with-tags)
* [Deploy policies on assets](/deploy-policy-on-all-assets).
* [Use scripts to write custom fields to assets.](/write-to-a-custom-asset)
## Recover a deleted asset
If you delete an asset by accident, you can recover it from the recycle bin. The recycle bin holds deleted clients and assets for a timeframe that you set. Once that timeframe passes, the deleted item can no longer be recovered. See the [CRM overview](/crm#core-features) for the full list of features, including the recycle bin.
## Remote access to assets
You can access remote assets through the embedded terminal in Gorelo. On any asset detail page, select either:
* **CLI:** A classic embedded terminal for assets running on Mac and Windows.
* [Live Terminal ](/live-terminal) : An advanced embedded terminal with AI assistance, for assets running on Windows.
## Learn more
Understand how tags work to automatically group assets.
Known issues and solutions.
# Asset tags in Gorelo
Source: https://help.gorelo.io/what-are-tags
Learn how Gorelo asset tags group endpoints automatically by client, location, OS, services, apps, or custom rules to power policies and scripts at scale.
Asset tags are used to automatically group assets together based on discovered information (services, apps, features etc.) or by manually assigning the tag.
Gorelo has a few built-in tags that will always be present and the rest will come from your own custom tags.
## Built-in tags
* **All**: will be present on ALL assets.
* **Client Name**: such as *Acme Corp*
* **Client Location**: such as *123 Fake Street (Acme Corp)*
* **OS Type**: Windows Workstation, Windows Server or MacOS Workstation
# What's Gorelo
Source: https://help.gorelo.io/what-is-gorelo
Gorelo is an all-in-one IT management platform for MSPs with remote control, asset management, ticketing, billing, AI automation, and powerful integrations.
Gorelo is an all-in-one platform that provides IT management tools, including:
* Remote control
* Asset management
* Ticketing features
* Billing center
* Powerful workflow and automation capabilities
Gorelo integrates common Managed Service Provider (MSP) tools while providing [an API](/api-overview) and [scripting](/how-scripts-work) features to automate repetitive work, from [ticket sentiment analysis](/sentiment-analysis) to [reply generation](/generate-replies-rephrase).
One of the key features is [Gorelo Connect](/what-is-gorelo-connect), a built-in remote control and file explorer that technicians use to remotely access and manage devices seamlessly.
## Get started
To get started with Gorelo, follow one of these two methods:
1. Log in to Gorelo.
2. The onboarding wizard opens automatically on first login.
3. To reopen the wizard, click the red flag on the left menu.
Follow the [Quickstart instructions](/quickstart) from the docs to set up your account from the general settings, from basic settings to setting up your first monitoring agent on a device.
## Next steps
Once you have finished your initial set up, head to the Gorelo key features to track your devices and manage your alerts and tickets:
Track and prioritize work.
Use generated alerts to create a ticket.
Learn how to use Dynamic Quantities.
Use Gorelo AI integration to generate sentiment analysis from tickets to help you prioritize work and alerts.
# What is Gorelo Connect
Source: https://help.gorelo.io/what-is-gorelo-connect
Gorelo Connect is the built-in remote control and file explorer tool, distributed via the Base Workstation and Base Server policies for managed assets.
Gorelo Connect is the built-in remote control and file explorer tool. By default, the Gorelo Connect plugin is distributed via the **Base Workstation** and **Base Server** policy.
If the Gorelo Connect plugin is present and enabled on an asset, it will appear in a few places:
* **Asset Detail**: The ‘Connect’ button will appear in the top-right corner of the Asset Detail page
* **Ticket Detail**: The Remote Control and File Explorer button will appear on the Ticket Detail page when an asset has been added
* **Search**: The Remote Control and File Explorer button will appear in search
* **Alerts**: The Remote Control and File Explorer button will appear on the Alerts list
# Create a Windows 11 compatible assets list
Source: https://help.gorelo.io/windows-11
Use Gorelo custom asset fields and tags to build a live list of Windows 11 compatible and incompatible assets so you can plan and target your upgrade work.
Here’s a way you can create a list of assets that are Windows 11 compatible or not.
1. Navigate to **Settings** > **Assets** > **[Custom Fields](https://app.gorelo.io/Admin/admin-settings#asset#assetcustomfields).**
2. Add custom field with the following details:
* **Name**: Windows 11 Compatibility
* **Variable**: Windows11Compatibility
1. Navigate to **Settings** > **[Tags](https://app.gorelo.io/Admin/admin-settings#tagmanagementsettings).**
2. Select **Asset Policy Tags** from the top.
3. Click **Create an Assets Tag** down the bottom-left:
* **Tag**: Win11Compatible
* **Property**: Registry Key
* **Condition**: Equals
* **Path**: HKEY\_LOCAL\_MACHINE\SOFTWARE\Windows11Compatibility\Status
* **Value**: Compatible
4. Click **Save**.
5. Click **Create an Assets Tag** down the bottom-left:
* **Tag**: Win11NotCompatible
* **Property**: Registry Key
* **Condition**: Equals
* **Path**: HKEY\_LOCAL\_MACHINE\SOFTWARE\Windows11Compatibility\Status
* **Value**: NotCompatible
6. Click **Save**.
7. Click **Create an Assets Tag** down the bottom-left:
* **Tag**: Win11CheckFailed
* **Property**: Registry Key
* **Condition**: Equals
* **Path**: HKEY\_LOCAL\_MACHINE\SOFTWARE\Windows11Compatibility\Status
* **Value**: CheckFailed
8. Click **Save**.
1. Navigate to **[Scripts](https://app.gorelo.io/Asset/script-list).**
2. Create a script with the following details:
* **Name**: Windows 11 Compatibility
* **Content**:
```powershell theme={null}
# Windows 11 Compatibility Check
# Adapted from Microsoft's HardwareReadiness.ps1
# Registry path and name
$RegistryPath = "HKLM:\SOFTWARE\Windows11Compatibility"
$RegistryName = "Status"
# Function to write to registry
function Write-Win11Registry {
param(
[string]$Status
)
try {
# Create registry path if it doesn't exist
if (!(Test-Path $RegistryPath)) {
New-Item -Path $RegistryPath -Force | Out-Null
}
# Write the value
New-ItemProperty -Path $RegistryPath -Name $RegistryName -Value $Status -PropertyType String -Force | Out-Null
}
catch {
Write-Output "Failed to write to registry: $($_.Exception.Message)"
}
}
$Source = @"
using Microsoft.Win32;
using System;
using System.Runtime.InteropServices;
public class CpuFamilyResult
{
public bool IsValid { get; set; }
public string Message { get; set; }
}
public class CpuFamily
{
[StructLayout(LayoutKind.Sequential)]
public struct SYSTEM_INFO
{
public ushort ProcessorArchitecture;
ushort Reserved;
public uint PageSize;
public IntPtr MinimumApplicationAddress;
public IntPtr MaximumApplicationAddress;
public IntPtr ActiveProcessorMask;
public uint NumberOfProcessors;
public uint ProcessorType;
public uint AllocationGranularity;
public ushort ProcessorLevel;
public ushort ProcessorRevision;
}
[DllImport("kernel32.dll")]
internal static extern void GetNativeSystemInfo(ref SYSTEM_INFO lpSystemInfo);
public enum ProcessorFeature : uint
{
ARM_SUPPORTED_INSTRUCTIONS = 34
}
[DllImport("kernel32.dll")]
[return: MarshalAs(UnmanagedType.Bool)]
static extern bool IsProcessorFeaturePresent(ProcessorFeature processorFeature);
private const ushort PROCESSOR_ARCHITECTURE_X86 = 0;
private const ushort PROCESSOR_ARCHITECTURE_ARM64 = 12;
private const ushort PROCESSOR_ARCHITECTURE_X64 = 9;
private const string INTEL_MANUFACTURER = "GenuineIntel";
private const string AMD_MANUFACTURER = "AuthenticAMD";
private const string QUALCOMM_MANUFACTURER = "Qualcomm Technologies Inc";
public static CpuFamilyResult Validate(string manufacturer, ushort processorArchitecture)
{
CpuFamilyResult cpuFamilyResult = new CpuFamilyResult();
if (string.IsNullOrWhiteSpace(manufacturer))
{
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "Manufacturer is null or empty";
return cpuFamilyResult;
}
string registryPath = "HKEY_LOCAL_MACHINE\\Hardware\\Description\\System\\CentralProcessor\\0";
SYSTEM_INFO sysInfo = new SYSTEM_INFO();
GetNativeSystemInfo(ref sysInfo);
switch (processorArchitecture)
{
case PROCESSOR_ARCHITECTURE_ARM64:
if (manufacturer.Equals(QUALCOMM_MANUFACTURER, StringComparison.OrdinalIgnoreCase))
{
bool isArmv81Supported = IsProcessorFeaturePresent(ProcessorFeature.ARM_SUPPORTED_INSTRUCTIONS);
if (!isArmv81Supported)
{
string registryName = "CP 4030";
long registryValue = (long)Registry.GetValue(registryPath, registryName, -1);
long atomicResult = (registryValue >> 20) & 0xF;
if (atomicResult >= 2)
{
isArmv81Supported = true;
}
}
cpuFamilyResult.IsValid = isArmv81Supported;
cpuFamilyResult.Message = isArmv81Supported ? "" : "Processor does not implement ARM v8.1 atomic instruction";
}
else
{
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "The processor isn't currently supported for Windows 11";
}
break;
case PROCESSOR_ARCHITECTURE_X64:
case PROCESSOR_ARCHITECTURE_X86:
int cpuFamily = sysInfo.ProcessorLevel;
int cpuModel = (sysInfo.ProcessorRevision >> 8) & 0xFF;
int cpuStepping = sysInfo.ProcessorRevision & 0xFF;
if (manufacturer.Equals(INTEL_MANUFACTURER, StringComparison.OrdinalIgnoreCase))
{
try
{
cpuFamilyResult.IsValid = true;
cpuFamilyResult.Message = "";
if (cpuFamily >= 6 && cpuModel <= 95 && !(cpuFamily == 6 && cpuModel == 85))
{
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "";
}
else if (cpuFamily == 6 && (cpuModel == 142 || cpuModel == 158) && cpuStepping == 9)
{
string registryName = "Platform Specific Field 1";
int registryValue = (int)Registry.GetValue(registryPath, registryName, -1);
if ((cpuModel == 142 && registryValue != 16) || (cpuModel == 158 && registryValue != 8))
{
cpuFamilyResult.IsValid = false;
}
cpuFamilyResult.Message = "PlatformId " + registryValue;
}
}
catch (Exception ex)
{
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "Exception:" + ex.GetType().Name;
}
}
else if (manufacturer.Equals(AMD_MANUFACTURER, StringComparison.OrdinalIgnoreCase))
{
cpuFamilyResult.IsValid = true;
cpuFamilyResult.Message = "";
if (cpuFamily < 23 || (cpuFamily == 23 && (cpuModel == 1 || cpuModel == 17)))
{
cpuFamilyResult.IsValid = false;
}
}
else
{
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "Unsupported Manufacturer: " + manufacturer + ", Architecture: " + processorArchitecture + ", CPUFamily: " + sysInfo.ProcessorLevel + ", ProcessorRevision: " + sysInfo.ProcessorRevision;
}
break;
default:
cpuFamilyResult.IsValid = false;
cpuFamilyResult.Message = "Unsupported CPU category. Manufacturer: " + manufacturer + ", Architecture: " + processorArchitecture + ", CPUFamily: " + sysInfo.ProcessorLevel + ", ProcessorRevision: " + sysInfo.ProcessorRevision;
break;
}
return cpuFamilyResult;
}
}
"@
try {
$exitCode = 0
[int]$MinOSDiskSizeGB = 64
[int]$MinMemoryGB = 4
[Uint32]$MinClockSpeedMHz = 1000
[Uint32]$MinLogicalCores = 2
[Uint16]$RequiredAddressWidth = 64
# Initialize result object
$outObject = @{
returnCode = -2
returnResult = "FAILED TO RUN"
returnReason = ""
logging = ""
}
# Check Storage
$osDrive = Get-WmiObject -Class Win32_OperatingSystem | Select-Object -Property SystemDrive
$osDriveSize = Get-WmiObject -Class Win32_LogicalDisk -filter "DeviceID='$($osDrive.SystemDrive)'" | Select-Object @{Name = "SizeGB"; Expression = { $_.Size / 1GB -as [int] } }
if ($osDriveSize.SizeGB -lt $MinOSDiskSizeGB) {
$outObject.returnReason += "Storage, "
}
# Check Memory
$memory = Get-WmiObject Win32_PhysicalMemory | Measure-Object -Property Capacity -Sum | Select-Object @{Name = "SizeGB"; Expression = { $_.Sum / 1GB -as [int] } }
if ($memory.SizeGB -lt $MinMemoryGB) {
$outObject.returnReason += "Memory, "
}
# Check TPM
$tpm = Get-Tpm
if (!$tpm.TpmPresent) {
$outObject.returnReason += "TPM, "
}
else {
$tpmVersion = Get-WmiObject -Class Win32_Tpm -Namespace root\CIMV2\Security\MicrosoftTpm | Select-Object -Property SpecVersion
if ($tpmVersion.SpecVersion) {
$majorVersion = $tpmVersion.SpecVersion.Split(",")[0] -as [int]
if ($majorVersion -lt 2) {
$outObject.returnReason += "TPM Version, "
}
}
}
# Check CPU and add CPU Family check
Add-Type -TypeDefinition $Source
$cpuDetails = @(Get-WmiObject -Class Win32_Processor)[0]
if ($null -eq $cpuDetails) {
$outObject.returnReason += "Processor (Not Found), "
}
else {
$processorCheckFailed = $false
# AddressWidth
if ($null -eq $cpuDetails.AddressWidth -or $cpuDetails.AddressWidth -ne $RequiredAddressWidth) {
$processorCheckFailed = $true
}
# ClockSpeed is in MHz
if ($null -eq $cpuDetails.MaxClockSpeed -or $cpuDetails.MaxClockSpeed -le $MinClockSpeedMHz) {
$processorCheckFailed = $true
}
# Number of Logical Cores
if ($null -eq $cpuDetails.NumberOfLogicalProcessors -or $cpuDetails.NumberOfLogicalProcessors -lt $MinLogicalCores) {
$processorCheckFailed = $true
}
# CPU Family
$cpuFamilyResult = [CpuFamily]::Validate([String]$cpuDetails.Manufacturer, [uint16]$cpuDetails.Architecture)
if (!$cpuFamilyResult.IsValid) {
$processorCheckFailed = $true
}
if ($processorCheckFailed) {
$outObject.returnReason += "Processor, "
}
}
# Check SecureBoot
try {
$null = Confirm-SecureBootUEFI
}
catch {
$outObject.returnReason += "SecureBoot, "
}
# Check for i7-7820hq exception
try {
$supportedDevices = @('surface studio 2', 'precision 5520')
$systemInfo = @(Get-WmiObject -Class Win32_ComputerSystem)[0]
if ($cpuDetails.Name -match 'i7-7820hq cpu @ 2.90ghz') {
$modelOrSKUCheckLog = $systemInfo.Model.Trim()
if ($supportedDevices -contains $modelOrSKUCheckLog) {
$outObject.returnReason = "" # Clear any CPU-related failures
}
}
}
catch {
# Ignore i7 exception check failures
}
# Set final result
$WIN11COMPATIBLE = $outObject.returnReason.Length -eq 0
# Output result to object
$outputObject = [pscustomobject]@{
WIN11COMPATIBLE = $WIN11COMPATIBLE
IncompatibleItems = $outObject.returnReason.TrimEnd(", ")
}
# Write to Gorelo custom field
$result = if ($WIN11COMPATIBLE) { "Compatible" } else { "Not Compatible: $($outObject.returnReason.TrimEnd(', '))" }
GoreloAction -SetCustomField -Name 'asset.Windows11Compatibility' -Value $result
# Write to Registry
if ($WIN11COMPATIBLE) {
Write-Win11Registry -Status "Compatible"
}
else {
Write-Win11Registry -Status "NotCompatible"
}
# Return the output object
$outputObject
}
catch {
# Create error output object
$outputObject = [pscustomobject]@{
WIN11COMPATIBLE = $false
IncompatibleItems = "Error running compatibility check: $($_.Exception.Message)"
}
# Write error to Gorelo custom field
GoreloAction -SetCustomField -Name 'asset.Windows11Compatibility' -Value "Error running check: $($_.Exception.Message)"
# Write error to Registry
Write-Win11Registry -Status "CheckFailed"
# Return the error output object
$outputObject
}
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want to check Windows 11 compatibility for.
3. Add the **Windows 11 Compatibility** script and set to repeat daily at your preferred time.
4. **Save** and **Distribute** the policy.
1. Navigate to **[Assets](https://app.gorelo.io/asset/asset-list).**
2. Click **Create view** down the bottom left and use the following details:
* **Title**: Win11 Compatible
* **Tags**: Win11Compatible
3. Click **Save**.
4. Do the same for **Win11 NotCompatible** and **Win11 CheckFailed.**
# Write and test a script
Source: https://help.gorelo.io/write-and-test-a-script
Write and test PowerShell, Command Line, or Bash scripts in Gorelo with type selection, timeout settings, and CLI testing on agent assets before deploying.
For anything that can’t be done natively with checks and plugins, **scripts** can be used.
## Create a script
1. Navigate to [**Scripts**](https://app.gorelo.io/Asset/script-list) from the main menu.
2. Click **Create a script** down the bottom-left.
3. Give the script a title.
4. Type or paste your script in the editor field (for example, `ipconfig`).
5. Click **Save** up the top-right.
## Extra settings
* **Script type**: this will change the script type from default PowerShell to either Command Line or Bash. PowerShell and Command Line is exclusive to Windows and Bash is exclusive to macOS.
* **Timeout**: this allows you to set the timeout period of the script in minutes.
* **Run as user**: this will run the script in the context of the most recently logged on user.
* **Variables**: this is a list of variables available in Gorelo that you can use. Creating [**custom assets fields**](https://app.gorelo.io/Admin/admin-settings#asset#assetcustomfields), [**custom clients fields**](https://app.gorelo.io/Admin/admin-settings#crm#clientcustomfields) and [**custom files**](https://app.gorelo.io/Admin/admin-settings#asset#filerepository) will populate this list.
**Tip!**
See [**GoreloAction**](/gorelo-action-cli) for additional functionality via custom fields and alerting
## Test your script
1. Open or create a new script.
2. Place your cursor in the **Asset** field at the bottom of the page.
3. Type the hostname of the asset you’d like to test against.
4. Click **Run**.
# Write to a custom asset field with scripts
Source: https://help.gorelo.io/write-to-a-custom-asset
Use Gorelo scripts to write values like BitLocker recovery keys, rotated local admin passwords, and third-party UIDs into custom asset fields automatically.
BitLocker keys, rotate local admin password, third-party UID etc.
You can write to a custom asset field via scripts. This is useful for things such as BitLocker keys, rotating local admin passwords, and third-party UID’s.
1. Navigate to **Settings** > **Assets** > **Custom Fields**.
2. Add custom field with the following details:
* **Name**: BitLocker Recovery Key
* **Variable**: bitlockerRecoveryKey
* **Name**: Windows Install Date
* **Variable**: windowsInstallDate
* **Name**: Windows Product Key
* **Variable**: windowsProductKey
* **Name**: MAC Address
* **Variable**: macAddress
* **Name**: RAM Slots Used
* **Variable**: ramSlotsUsed
1. Navigate to **Scripts**.
2. Create a script with the following details:
* **Name**: 🗝️Store-BitlockerRecoveryKey
* **Content**:
```powershell theme={null}
$ErrorActionPreference = 'SilentlyContinue'
# Get drives where BitLocker is "On"
$BitlockerDrives = Get-BitLockerVolume | Where-Object ProtectionStatus -EQ "On" -ErrorAction SilentlyContinue
#Get FileSystem drives
$Drives = Get-PSDrive -PSProvider FileSystem
#Create array of Drive Names with ":" added
$DrivesName = @()
$Drives | foreach {$DrivesName += $_.name + ':' }
#If any Bitlockered drives exist
if($BitlockerDrives){
#Foreach Drive
Foreach ($DriveName in $DrivesName) {
#Confirm is drive is bitlockered
$BitlockerDrive = $BitlockerDrives | where { $DriveName -contains $_ }
#If specific drive is bitlockered
if ($BitlockerDrive){
#Get RecoveryKey
$RecoveryKey = $BitlockerDrive.KeyProtector | Where-Object RecoveryPassword -NE "" | Select-Object -ExpandProperty RecoveryPassword -ErrorAction SilentlyContinue
#Join if multiple with ; delimiter
$RecoveryKey = $RecoveryKey -join ";"
#Add the drive letter to the output
$RecoveryKey = "$($BitlockerDrive.mountpoint)$RecoveryKey"
#Add to other drive keys (If exist)
$RecoveryKeys += " $RecoveryKey "
} else { $RecoveryKeys += $DriveName + "Not Enabled" }
}
GoreloAction -SetCustomField -Name 'asset.bitlockerRecoveryKey' -Value $RecoveryKeys
#If no bitlockered drives found
}else {
Foreach ($DriveName in $DrivesName) {
$RecoveryKeys += $DriveName + "Not Enabled "
}
GoreloAction -SetCustomField -Name 'asset.bitlockerRecoveryKey' -Value $RecoveryKeys
}
```
* **Name**: 🗝️Store-WindowsInstallDate
* **Content**:
```powershell theme={null}
# Initialize array to store all valid dates
$allDates = @()
# Method 1: Win32_OperatingSystem class
$osInfo = Get-WmiObject Win32_OperatingSystem
$installDate = $osInfo.ConvertToDateTime($osInfo.InstallDate)
$allDates += $installDate
Write-Host "OS Installation Date (from Win32_OperatingSystem): $($installDate.ToString('MM/dd/yyyy'))" -ForegroundColor White
# Method 2: Registry installation date
$registryPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"
$registryInstallDate = Get-ItemProperty -Path $registryPath | Select-Object -ExpandProperty InstallDate
$registryInstallDateTime = (Get-Date "1970-01-01 00:00:00.000Z").AddSeconds($registryInstallDate)
$allDates += $registryInstallDateTime
Write-Host "Registry Installation Date: $($registryInstallDateTime.ToString('MM/dd/yyyy'))" -ForegroundColor White
# Method 3: Earliest system restore point (with proper date parsing)
try {
$restorePoints = Get-ComputerRestorePoint | Sort-Object -Property CreationTime
if ($restorePoints) {
$earliestRestorePoint = [datetime]::ParseExact($restorePoints[0].CreationTime.ToString(), "yyyyMMddHHmmss.ffffff-000", $null)
$allDates += $earliestRestorePoint
Write-Host "Earliest System Restore Point: $($earliestRestorePoint.ToString('MM/dd/yyyy'))" -ForegroundColor White
}
}
catch {
Write-Host "Unable to retrieve or parse system restore points." -ForegroundColor Yellow
}
# Method 4: Windows.old folder date (if exists)
$windowsOldPath = "$env:SystemDrive\Windows.old"
if (Test-Path $windowsOldPath) {
$windowsOldDate = (Get-Item $windowsOldPath).CreationTime
$allDates += $windowsOldDate
Write-Host "Windows.old Folder Creation Date: $($windowsOldDate.ToString('MM/dd/yyyy'))" -ForegroundColor White
}
# Filter out any null dates and find the oldest
$validDates = $allDates | Where-Object { $_ -ne $null }
$oldestDate = $validDates | Sort-Object | Select-Object -First 1
Write-Host "`nOldest detected date (likely original deployment): $($oldestDate.ToString('MM/dd/yyyy'))" -ForegroundColor Green
# Format date for Gorelo (date only)
$goreloDateString = Get-Date $oldestDate -Format "yyyy-MM-dd"
# Set Gorelo custom field with the oldest date
try {
GoreloAction -SetCustomField -Name '$gorelo:asset.windowsInstallDate' -Value $goreloDateString
Write-Host "Successfully updated Gorelo custom field" -ForegroundColor Green
} catch {
Write-Host "Error updating Gorelo custom field: $($_.Exception.Message)" -ForegroundColor Red
}
# Display difference between oldest and newest dates for verification
$newestDate = $validDates | Sort-Object | Select-Object -Last 1
$dateDifference = New-TimeSpan -Start $oldestDate -End $newestDate
Write-Host "`nDate range span: $($dateDifference.Days) days" -ForegroundColor Cyan
Write-Host "Newest date found: $($newestDate.ToString('MM/dd/yyyy'))" -ForegroundColor Cyan
```
* **Name**: 🗝️Store-WindowsProductKey
* **Content**:
```powershell theme={null}
# Get Windows Product Key and update Gorelo custom field
try {
# Get Windows Product Key using WMI
$productKey = (Get-WmiObject -query 'select * from SoftwareLicensingService').OA3xOriginalProductKey
if ([string]::IsNullOrEmpty($productKey)) {
# If OA3xOriginalProductKey is empty, try getting it from registry
$regPath = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform'
$regValue = 'BackupProductKeyDefault'
$productKey = (Get-ItemProperty -Path $regPath -Name $regValue -ErrorAction SilentlyContinue).$regValue
}
if ([string]::IsNullOrEmpty($productKey)) {
# If still empty, try another registry method
$regPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DigitalProductId"
$digitalId = (Get-ItemProperty -Path $regPath).DigitalProductId
# Convert Digital Product ID to Product Key
$keyOffset = 52
$isWin8 = ([math]::Floor($digitalId[66] / 6) -band 1)
$productKey = ""
$chars = "BCDFGHJKMPQRSTVWXY2346789"
for ($i = 24; $i -ge 0; $i--) {
$r = 0
for ($j = 14; $j -ge 0; $j--) {
$r = ($r * 256) -bxor $digitalId[$j + $keyOffset]
$digitalId[$j + $keyOffset] = [math]::Floor($r / 24)
$r = $r % 24
}
$productKey = $chars[$r] + $productKey
if (($i % 5) -eq 0 -and $i -ne 0) {
$productKey = "-" + $productKey
}
}
}
if (![string]::IsNullOrEmpty($productKey)) {
# Update Gorelo RMM custom field
GoreloAction -SetCustomField -Name '$gorelo:asset.WindowsProductKey' -Value $productKey
Write-Output "Successfully updated Windows Product Key in Gorelo"
} else {
Write-Error "Could not retrieve Windows Product Key"
exit 1
}
} catch {
Write-Error "Error: $($_.Exception.Message)"
exit 1
}
```
* **Name**: MAC Address for Ethernet
* **Content**:
```powershell theme={null}
# Get Ethernet adapter MAC address only
$MacAddress = (Get-NetAdapter | Where-Object {$_.Name -like "*Ethernet*" -and $_.Status -eq "Up"} | Select-Object -First 1 -ExpandProperty MacAddress)
if ($MacAddress) {
GoreloAction -SetCustomField -Name 'asset.macAddress' -Value $MacAddress
Write-Host "Ethernet MAC Address set to: $MacAddress"
} else {
Write-Host "No active Ethernet adapter found"
}
```
* **Name**: 🗝️Store-ramSlotsUsed
* **Content**:
```powershell theme={null}
$totalSlots = (Get-CimInstance -ClassName Win32_PhysicalMemoryArray).MemoryDevices
$usedSlots = (Get-CimInstance -ClassName Win32_PhysicalMemory).Count
$emptySlots = $totalSlots - $usedSlots
$totalRAM = [math]::Round((Get-CimInstance -ClassName Win32_ComputerSystem).TotalPhysicalMemory/1GB, 2)
$ramInfo = "RAM: $totalRAM GB installed | Slots: $usedSlots/$totalSlots used ($emptySlots empty)"
# Set Gorelo RMM custom field
GoreloAction -SetCustomField -Name 'asset.ramSlotsUsed' -Value $ramInfo
Write-Host "Set Gorelo field 'asset.ramSlotsUsed' to: $ramInfo"
```
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management).**
2. Edit an existing policy that covers the assets you want to store the keys or the addresses for.
3. Add the script and set to repeat daily at your preferred time.
4. **Save** and distribute the policy.
# 1Password integration overview
Source: https://help.gorelo.io/1-password-integration-overview
Set up 1Password vaults, tags, and best practices for MSPs syncing items into Gorelo, with role-based and per-client organization structures.
## 1Password features
### Vaults
Vaults can be used to restrict access to items for certain groups (and users) in 1Password. There are two common approaches here:
* Vaults that are based on roles (like L1, L2, Management, Accounts).
* Vaults that are based on clients (like Acme Corp, Blackrock).
### 1Password tags
1Password uses the concept of tags as opposed to folders for organizational purposes. One of the advantages here is that tags span across all vaults and result in an aggregated list. Folder-like nesting can be achieved with tags by using ‘/’ forward slash. For example, `Clients/Acme Corp` would result in a top-level tag of clients and then a sub-tag of Acme Corp.
### Best practice structure for Gorelo
The recommended approach for Gorelo is to follow these steps:
1. Structure your vaults based on **roles,** as this offers the most flexibility and scalability.
2. Organize your vaults by client with tags.
Password items in Gorelo that you have assigned to a client will be tagged in 1Password with `Clients/{{client.Name}}`. This will allow you to search/navigate using the client name in the native 1Password app, extension, etc.
Structuring your vaults based on clients still works. However, it requires you to recreate the service account every time you add a new client/vault, and to map them to groups like "Everyone".
## Grant access to 1Password vaults
You can grant access to 1Password vaults similarly in both 1Password and Gorelo.
1Password **user**> 1Password **group**> 1Password **vault**
Gorelo **user**> Gorelo **group**> 1Password **vault**
There is no inherent link between Gorelo users/groups and 1Password users/groups — you will need to configure these independently.
# Gorelo API overview
Source: https://help.gorelo.io/api-overview
Use the Gorelo API to integrate external products, with API key authentication via the X-API-Key header, scoped permissions, and HTTP error handling.
Gorelo allows you to integrate with any external product through the Gorelo API.
The Gorelo API uses API keys. Include your key in every request via the X-API-Key header.
The Gorelo base URL depends on the region you opted to host your data on in Gorelo:
Base URL: [**https://api.usw.gorelo.io/**](https://api.usw.gorelo.io/)\
API Reference: [**https://api.usw.gorelo.io/swagger**](https://api.usw.gorelo.io/swagger)
Base URL: [**https://api.aue.gorelo.io/**](https://api.aue.gorelo.io/)\
API Reference: [**https://api.aue.gorelo.io/swagger**](https://api.aue.gorelo.io/swagger)
## Example requests
The following JavaScript `fetch` snippets show how to authenticate with the `X-API-Key` header. Replace `YOUR_API_KEY` with your key and swap the base URL for the region hosting your data.
```js GET theme={null}
const response = await fetch('https://api.usw.gorelo.io/your-endpoint', {
method: 'GET',
headers: {
'X-API-Key': 'YOUR_API_KEY',
},
});
const data = await response.json();
```
```js POST theme={null}
const response = await fetch('https://api.usw.gorelo.io/your-endpoint', {
method: 'POST',
headers: {
'X-API-Key': 'YOUR_API_KEY',
'Content-Type': 'application/json',
},
body: JSON.stringify({ key: 'value' }),
});
const data = await response.json();
```
## Scopes and permissions
You can **scope** API keys. If a key lacks access to an endpoint, the API returns **403 Forbidden**.
## Error handling
| Error | Meaning |
| :------------------------ | :---------------------------- |
| **401 Unauthorized** | Missing/invalid API key |
| **403 Forbidden** | Valid key, insufficient scope |
| **429 Too Many Requests** | Rate limit exceeded |
## Status IDs
### Agent assets
| ID | Status |
| :- | :-------------------- |
| 1 | Installing |
| 2 | Online |
| 3 | Offline |
| 4 | Pending Delete |
| 5 | Deleted |
| 6 | Pending Client Delete |
| 7 | Client Deleted |
# Contracts overview
Source: https://help.gorelo.io/contracts-overview
Contracts in Gorelo invoice labor and products on a recurring schedule. Configure invoicing, labor rates, and products for monthly or yearly billing.
Use contracts to invoice labor and products on a recurring basis. A contract has three sections that you configure: **Invoicing**, **Labor**, and **Products**.
## Contract sections
This is where you define everything invoice related.
| Section | Usage |
| :-------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Start Date** | The contract coverage will start on this date |
| **Repeat Period** | The contract coverage and invoice creation will repeat based on this frequency (Monthly, Quarterly, Half-yearly, Yearly) |
| **End Date** | The contract coverage will end on this date and no longer create invoices (optional) |
| **Invoice Creation** (days before) | The invoice will be created on the Start Date and every month after based on the repeat period (when set to **0**). |
| **Invoice Due** (Days later) | The invoice will be due on the day the invoice is generated when set to **0**. |
| **Invoice Template** | Gorelo creates the invoice PDF based on this selection.
Navigate to Settings > Billing > [**Invoice Template**](https://app.gorelo.io/Admin/admin-settings#billing#invoicetemplate) to create and customize. |
| **Invoice Email Template** | Gorelo sends the invoice email to the selected contacts based on this selection.
Navigate to Settings > Email > [**Settings**](https://app.gorelo.io/Admin/admin-settings#email#settings) and edit your Invoice email address. You can then create and customize via the Email Template Management tab. |
| **Xero Branding Theme** (only for Xero) | Specify the branding theme used in Xero. This allows for automatic payments via third-party providers, for example, Payrix or Pinch. |
| **Reference** | The name of the invoice. You can use template fields here such as `billingmonth`, `contractgroupname`, and `locationname`. |
| **Auto Approve & Send** | The contract creates a draft invoice when this is toggled off (default). Toggle it on and select contacts to have the contract automatically create the invoice, send it to the contact, and sync to Xero/QBO. |
### Invoice creation examples
* **Example 1**: Start Date of **January 1st 2025** with a Repeat Period of **Monthly** and Invoice Creation **0** days before. The second coverage period starts on February 1st 2025 and the invoice generates on **February 1st 2025**.
* **Example 2**: Start Date of **January 1st 2025** with a Repeat Period of **Monthly** and Invoice Creation **7** days before. The second coverage period starts on February 1st 2025 and the invoice generates on **January 25th 2025**.
### Invoice due examples
* **Example 1**: Start Date of **January 1st 2025** with a Repeat Period of **Monthly**, Invoice Creation **0** days before, and Invoice Due **0** days later. The second coverage period starts on February 1st 2025, the invoice generates on **February 1st 2025**, and the invoice is due on **February 1st 2025**.
* **Example 2**: Start Date of **January 1st 2025** with a Repeat Period of **Monthly**, Invoice Creation **0** days before, and Invoice Due **7** days later. The second coverage period starts on February 1st 2025, the invoice generates on **February 1st 2025**, and the invoice is due on **February 8th 2025**.
* **Example 3**: Start Date of **January 1st 2025** with a Repeat Period of **Monthly**, Invoice Creation **7** days before, and Invoice Due **7** days later. The second coverage period starts on February 1st 2025, the invoice generates on **January 25th 2025**, and the invoice is due on **February 1st 2025**.
This is where you choose the type of labor and configure how it functions.
Once you set the labor type, you can't revert it to another labor type, unless you initially set it to **No Labor**. To change the type of labor on an existing contract, contact our Customer Support from the sidebar in Gorelo: click the icon, and select **Contact us**.
### Unlimited hours
Labor is completely uncapped (all-you-can-eat type).
* **Auto Approve** automatically approves all time entries, with the assumption that you use the Contract Profitability report to monitor contract health.
* **Covered items** define which combination of work types and billing roles will automatically be covered by the contract.
* **Example 1**: **Remote Support** performed by a **technician** would be covered ✅.
* **Example 2**: **Onsite (Off Hours)** performed by a **technician** wouldn’t be covered. It instead flows through to default labor rates or an alternate contract ❌.
### Per hour
Gorelo bills labor at the rates you specify.
| Rate | Usage |
| :-------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Use default labor rates** | Allows you to use the default rates but then gives you the option to choose which Work Type and Billing Role combinations are automatically covered by this contract. |
| **Use fixed labor rate** | Allows you to set a fixed rate that overrides all selected Work Type and Billing Role combinations. |
| **Use custom labor rates** | Allows you to override individual Work Type and Billing Roles and choose which Work Type and Billing Role combinations are automatically covered by this contract. |
### Block hours (one-time top up)
Gorelo deducts labor from a block of hours the client purchases upfront. You invoice it once and it doesn't renew.
* Navigate to Settings > Billing > [**Block Hour Templates**](https://app.gorelo.io/Admin/admin-settings#billing#blockhourstemplate) and create your templates (for example, a block of 10 hours).
* The initial **price** and **Block Balance** is what flows through the first invoice.
| Section | Usage |
| :-------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Warning Threshold** | Determines at what percentage of the remaining hours a client banner appears. For example, 10 hours with a 20% threshold shows the client banner when 2 hours remain. |
| **Overrun Threshold** | Determines whether time can still be billed even though 0 hours remain. For example, 10 hours with a 30% overrun allows up to 3 hours to be billed even though 0 hours remain. The next top-up of block hours immediately consumes these overrun hours. |
| **Covered Items** | Define which combination of Work Type and Billing Roles will automatically be covered by the contract. |
### Limited hours (recurring invoice)
Gorelo caps labor at a specific number of hours, then bills any overage on a per-hour basis. The cap renews at the start of each month.
* The **Allocated hours** section is where you’ll set the maximum hours that are covered by the contract.
* You then specify how **excess hours** will be billed (see **Per hour**).
### No labor
The contract does not include any labor component. Use this option when the contract only covers products or recurring fees.
This is where you add products and bundles that will appear on the invoice PDF and sync to Xero/QBO.
* Use the search dropdown to add products/bundles.
* You can modify the description, cost, price, and so on for a product/bundle. The change only impacts this specific contract; the underlying product/bundle is not changed.
**Block hours** and **No labor** both support the additional contract fields:
* Tax Rate
* Tax Code
* Chart of Accounts (COA) when synced with [Xero](/xero) or [QuickBooks Online](/quick-books-online)
## Use case examples
The following table contains billable items that best fit the setup:
| Contract setup | Items |
| :------------------------------------------------------------------------------- | :-------------------------------------------------- |
| You allocate a time balance once and deduct the hours | |
| You bill a fixed amount every month regardless of hours spent | |
| You bill strictly based on hours, without any product | |
| You allocate a fixed time allowance, then bill on a per-hour basis once exceeded | |
# Generate API key
Source: https://help.gorelo.io/generate-api-key
Generate a new Gorelo API key from Settings to authenticate API requests, set a permission scope, name the key, and copy it for use in your integrations.
* Enter a name
* Select the permission scope
* Enter a description (optional)
* Click Generate
* Copy the key
# Huntress integration
Source: https://help.gorelo.io/huntress
Integrate Huntress with Gorelo to deploy and monitor the Huntress agent, with setup steps for the Account Key, API key, and secret key configuration.
Gorelo integrates with Huntress which allows you to deploy and monitor the agent.
1. Navigate to **Settings > [Integrations](https://app.gorelo.io/Admin/admin-settings#integrations).**
2. Click the ⚙️***cog*** icon to configure **Huntress.**
3. Fill in the required fields.
* **Account Key:**
* Navigate to https\://\[yourdomain].huntress.io/account/installer.
* Copy the Account Key into Gorelo.
* **API/Secret Key:**
* Navigate to https\://\[yourdomain].huntress.io/account/api\_credentials.
* Click the green Setup button to begin the process to generate your API Key.
* Copy the API Key and API Secret Key into Gorelo.
4. Click **Connect** and the Client \<-> Organization mapping screen will appear.
5. Map Gorelo clients to the appropriate Huntress organization.
6. Click Map when complete.
Gorelo cannot create Huntress Organizations automatically at this stage so these will need to be created in Huntress first.
1. Navigate to **[Policies](https://app.gorelo.io/Asset/policy-management)** in the main menu.
2. Add the Huntress plugin to an existing policy or create a new one.
3. Click **Distribute.**
**Tips!**
See the [**Policies**](/how-policies-work) guide for additional information.
# Integrate with 1Password
Source: https://help.gorelo.io/integrate-1-password
Integrate 1Password with Gorelo to sync items across vaults for search, embedding, and related items, using the MSP edition and a Service Account Token.
Integrating 1Password with Gorelo allows you to sync 1Password items across your vaults into Gorelo for use in search, embedding, related items and more.
We recommend the **MSP Edition**\
[**https://1password.com/product/enterprise-password-manager-msp-edition**](https://1password.com/product/enterprise-password-manager-msp-edition)
| Field | Value | Example |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| **URL** | In any 1Password application, right-click an item and choose ‘Copy Private Link’ and paste it here to auto-fill your Custom Domain and Account ID | `https://start.1password.com/open/i?a=ABCD1EFGH2IJKL3MNOP4QRST5U&v=abcd1234efgh5678ijkl9012mn&i=zyxw9876vuts5432rqpo1098ml&h=acme.1password.com` |
| **Custom Domain** | Your [1password.com](http://1password.com) subdomain and will be auto-filled by your 1Password | `acme.1password.com` |
| **Account ID** | Your account ID and will be auto-filled by your 1Password URL | `ABCD1EFGH2IJKL3MNOP4QRST5U` |
**Service Account Token:**
* Navigate to your 1Password admin console > Developer > Service accounts.
* Click **New service account** up the top right.
* Enter `Gorelo` as the name.
* Select your vaults and give **write permissions.**
* Create the account and copy the service account token into Gorelo.
Vault mapping screen will appear.
## Troubleshooting
Your integration is probably missing the write permission (step 3). To change the vaults/permissions, 1Password requires you to **delete the service account and recreate it**. Make sure to add the write permission when adding the Service Account Token.
# Gorelo integrations overview
Source: https://help.gorelo.io/integrations-overview
Connect Gorelo to Xero, QuickBooks, Pax8, Huntress, ScreenConnect, 1Password, Microsoft 365, Outlook Calendar, and more to automate your MSP workflows.
Integrate Gorelo with your bookkeeping software.
Integrate Gorelo with your accounting software.
Integrate Gorelo with your software marketplace.
Integrate Gorelo with your cybersecurity software.
Integrate Gorelo with your calendar software.
Integrate Gorelo with your backup tool.
Integrate Gorelo with your remote access software.
Integrate Gorelo with your Microsoft 365 compliance software.
## 1Password integrations
Gorelo integrates with 1Password to securely store and manage your credentials. You can use 1Password to:
Understand how Gorelo integrates with 1Password and how to use it to manage your credentials.
Learn how to set up and use the 1Password integration.
# Outlook Calendar integration
Source: https://help.gorelo.io/outlook-calendar
Set up two-way calendar sync between Gorelo and Outlook with an Azure AD app registration so events flow between user calendars in both directions seamlessly.
Gorelo integrates with Outlook Calendar which allows for 2-way sync between the Gorelo user calendar and the primary calendar in Outlook (SSO with M365 required).
1. Navigate to **[Azure](https://portal.azure.com/) > Microsoft Entra ID.**
2. In the left menu, click **App registrations.**
3. Click **+New registration.**
* **Name**: Gorelo Calendar
* **Supported account types**: Accounts in this organizational directory only
4. Click **Register.**
5. Navigate to **API permissions** from the left menu.
6. Click **Add a permission:**
* Select **Microsoft Graph.**
* Select **Application permission.**
* Select permissions: **[Application.Read](http://Application.Read).All**
* Select permissions: **Calendars.ReadWrite**
7. Click **Add permissions.**
8. Click **Grant admin consent** for the recently added permissions.
9. Navigate to **Certificates & secrets** in the left menu.
10. Click **+ New client secret.**
* Enter a Description and Expiration.
11. Copy the **Secret Value** and save for later.
12. Navigate to **Overview** in the left menu.
13. Copy the **Application (client) ID** and **Directory (tenant) ID** and save for later.
1. Navigate to **Settings >** **[Integrations](https://app.gorelo.io/Admin/admin-settings#integrations).**
2. Click the **⚙️cog** icon to configure **Outlook.**
3. Enter the Client ID, Tenant ID and Secret Key you saved from earlier.
4. Click **Connect.**
5. Each user will then need to toggle on sync via their calendar in Gorelo.
# Partially invoice with Prorate Items
Source: https://help.gorelo.io/partially-invoice-with-prorate-items
Use Prorate Items in Gorelo to partially invoice contract items and bill clients for fractional billing periods, ideal for mid-cycle starts and adjustments.
Prorate items and bill for partial periods.
# Pax8 integration
Source: https://help.gorelo.io/pax8
Integrate Pax8 with Gorelo to dynamically adjust contract quantities from Pax8 subscriptions and expose unbilled items via Dynamic Quantities for billing.
Gorelo integrates with Pax8 which allows you to dynamically adjust contract quantities based on Pax8 subscriptions and expose unbilled subscriptions via [**Dynamic Quantities**](/track-unbilled-items-with-dynamic-quantities).
Do this if you’d like to automatically create a Pax8 client when one is created in Gorelo.
This information will be used on all new orders in Pax8.
The Client Mapping screen will appear.
**Tips!**
* Only subscriptions billed in advance and associated with each Pax8 client are available via this integration, like Microsoft 365, Exclaimer, or Dropsuite.
* See [**Dynamic Quantities**](/track-unbilled-items-with-dynamic-quantities) to automate billing and expose unbilled subscriptions
## FAQ
Yes. Gorelo currently supports subscription-based services from Pax8.
# QuickBooks Online integration
Source: https://help.gorelo.io/quick-books-online
Integrate Gorelo with QuickBooks Online to sync clients, invoices, tax rates, payments, and more, with step-by-step setup and account authentication.
Gorelo integrates with QuickBooks Online which allows you to sync clients, invoices, tax rates, payments and more!
You will then be redirected back to Gorelo with a success message.
This will be used for any item synced from Gorelo to QuickBooks that does **not** have a COA code applied automatically to the product/bundle/category.
Gorelo recommends creating a new COA code such as '**4444 Uncoded from Gorelo**' to make it obvious when something synced without a legitimate COA code. If this code has just been created, then F5 refreshes while on the '*Integration with QuickBooks is successful*' screen so it appears, or start the integration again.
**Tips!**
* *Clients in Gorelo with identical names to Contacts in QBO will be mapped automatically*
* Chart of Account (COA) codes can be set individually on the following levels:
* Products
* Bundles
* Chart of Account (COA) codes can be set via [**Product Categories**](https://app.gorelo.io/Admin/admin-settings#billing#productcategories) and Subcategories — products/bundles will then inherit these COA codes.
## Optional settings
Clicking the **Mark as default** button on the far right of your chosen tax rate.
**Tips!**
* Tax rates can be set individually on the following levels:
* Products
* Bundles
* Contract line items
* Invoice line items
* Tax rates can be set via [**Product Categories**](https://app.gorelo.io/Admin/admin-settings#billing#productcategories) and Subcategories — products/bundles will then inherit these tax rates
## How Gorelo syncs with QuickBooks Online
The following table explains how to use invoices in Gorelo to ensure they sync in QuickBooks Online, and vice versa.
| Action | Do it from |
| :-------------------------- | :-------------------------- |
| Creating an invoice | Gorelo |
| Approving a drafted invoice | Gorelo or QuickBooks Online |
| Sending an invoice | Gorelo |
| Posting a payment | QuickBooks Online |
# Revoke API key
Source: https://help.gorelo.io/revoke-api-key
Revoke a Gorelo API key from Settings to immediately invalidate the key, block any further API requests using it, and protect your integrations and data.
# ScreenConnect integration
Source: https://help.gorelo.io/screen-connect
Integrate ScreenConnect with Gorelo for one-click remote desktop sessions and agent installation, with Instance ID, API path, and credential configuration.
Gorelo integrates with ScreenConnect for one-click Remote Desktop connections and agent installation.
1. Navigate to **Settings** > **[Integrations](https://app.gorelo.io/Admin/admin-settings#integrations).**
2. Click the ⚙️**cog** icon to configure **ScreenConnect.**
3. Fill in the required fields:
* **Instance ID**
1. Access one of your endpoints that already has your ScreenConnect Client installed.
2. Navigate to **Services**.
3. Copy the value of the ScreenConnect Client Service in parentheses:
* **MSI URL**
1. Log in to your ScreenConnect tenant.
2. Click **Access.**
3. Click **Build.**
4. Change type to **Windows (MSI).**
5. Click **copy URL.**
4. Click **Connect.**
Gorelo automatically inserts the client name into the ScreenConnect company field on install. See Step 3 for additional configuration.
1. Navigate to [Policies](https://app.gorelo.io/Asset/policy-management) in the main menu.
2. Add the ScreenConnect plugin to an existing policy or create a new one.
3. Click **Distribute.**
**Tips!**
See the [Policies](/how-policies-work) guide for additional information.
1. Log in to your ScreenConnect tenant.
2. Navigate to **Access**.
3. Click the **3-dot menu** on the **All Machines** session group and click **Edit.**
4. Enter `CustomProperty1` in the **Subgroup Expressions** field.
5. Click **Save.**
## Troubleshooting
### ScreenConnect is not connecting on a specific asset
If ScreenConnect doesn't show a connection on a specific asset, reinstall it by following these steps:
1. Navigate to the details page of the specific asset.
2. Click the **Policy** tab down the bottom-left:
3. Click the heart icon on the ScreenConnect plugin.
4. Click the ScreenConnect icon to reinstall.
# Slide backup integration
Source: https://help.gorelo.io/slide
Integrate Slide with Gorelo to view snapshot status and initiate new backups directly from the Asset Detail page for protected Windows endpoints.
Gorelo integrates with Slide which allows you to view the status of existing snapshots and initiate a new snapshot from the Asset Detail page.
* API Key:
1. Navigate to [https://console.slide.tech/settings](https://console.slide.tech/settings)
2. ‘Create API Token’
3. Copy and paste the token into Gorelo
To view the integration in action, navigate to a mapped asset in Gorelo and you will see Slide backup info in the top-right corner:
* **Yellow:** The status of the last 10 snapshots (oldest to newest). Hover to see more detail.
* **Red:** The status of cloud replication (solid blue is replicated to the cloud, outline-only is not replicated to the cloud).
* **Orange:** Click to initiate a snapshot.
* Click anywhere else to navigate to the Slide portal.
# Use Swagger UI
Source: https://help.gorelo.io/swagger-ui
Authenticate Swagger UI for the Gorelo API by pasting your API key into the apiKey dialog so every Try it out call includes the key automatically.
Use the API depending on the region you opted to host your data on in Gorelo:
All “Try it out” calls will include your key automatically.
All “Try it out” calls will include your key automatically.
# Track unbilled items with Dynamic Quantities
Source: https://help.gorelo.io/track-unbilled-items-with-dynamic-quantities
Use Dynamic Quantities in Gorelo to automate contract billing from asset tags, contact tags, and Pax8 subscriptions, surfacing unbilled items for review.
Dynamic Quantities are used to automate your billing by increasing/decreasing quantities of products/bundles and suggesting things that haven’t been billed yet. **Asset Tags**, **Contact Tags** (M365) and **Pax8** subscriptions are currently supported.
## Set up rules
Then click **Dynamic Quantities** up the top right.
You will see **Dynamic Elements** that Gorelo has detected from each **Source**.
Example: Source of **Asset Tag** and a Dynamic Element of **Windows Workstation**.
Select what you’d like to occur when this dynamic element is detected (and not currently mapped to a contract).
* **Unmapped**: This element will appear in the **Pending** tab and directly on each contract ready for you to map a product/bundle.
* **Suggest**: Choose a product/bundle to suggest. This element will appear in the **Pending** tab and directly on each contract ready for you to click ‘Add’ as the product/bundle has been suggested.
* **Ignore**: This element will not appear in the Pending tab or directly on each contract.
## See what's pending
You should check this Pending tab regularly to make sure you’re billing for everything. Anything that appears here should be either added to a contract, individually ignored or ignored via the Rules tab.
You will see all dynamic elements that are pending contract addition:
* **Add** will navigate you to the client’s contract (or list of contracts) so you can add from there.
* **Ignore** will hide just this specific dynamic element for this specific client (and appear in the Ignored tab)
# Xero integration
Source: https://help.gorelo.io/xero
Integrate Gorelo with Xero to sync clients, invoices, tax rates, and payments, with step-by-step OAuth setup and account-level mapping configuration.
Gorelo integrates with Xero, which allows you to sync clients, invoices, tax rates, payments and more!
Select the appropriate organization (if there are multiple) and click **Allow Access**. You will then be redirected back to Gorelo with a success message.
* This will be used for any item synced from Gorelo to Xero that does **not** have a COA code applied automatically to the product/bundle/category.
* It is recommended to create a new COA code such as '**4444 Uncoded from Gorelo**' to make it obvious when something synced without a legitimate COA code. If this code has just been created then F5 refresh while on the '*Integration with Xero is successful*' screen so it appears, or start the integration again.
**Tips!**
* ***Clients*** in Gorelo with identical names to ***Contacts*** in Xero will be mapped automatically.
* Chart of Account (COA) codes can be set individually on the following levels:
* Products
* Bundles
* Chart of Account (COA) codes can be set via [**Product Categories**](https://app.gorelo.io/Admin/admin-settings#billing#productcategories) and Subcategories — products/bundles will then inherit these COA codes.
## Set the default tax rate
Click the **Mark as default** button on the far right of your chosen tax rate.
**Tips!**
* Tax rates can be set individually on the following levels:
* Products
* Bundles
* Contract line items
* Invoice line items
* Tax rates can be set via [**Product Categories**](https://app.gorelo.io/Admin/admin-settings#billing#productcategories) and Subcategories — products/bundles will then inherit these tax rates
## How Gorelo syncs with Xero
The following table explains how to use invoices in Gorelo to ensure they sync in Xero, and vice versa.
| Action | Do it from |
| --------------------------- | -------------- |
| Creating an invoice | Gorelo |
| Approving a drafted invoice | Gorelo or Xero |
| Sending an invoice | Gorelo |
| Posting a payment | Xero |