ConnectWise RMM: devices, patch posture, and your business reviews
ConnectWise RMM — the cloud RMM on the Asio platform — is where your managed endpoints live. This connector reads three things out of it: each customer's sites, their device inventory, and their patch posture — and hangs them off the matching Current company so they can feed your executive and CIO business reviews. It is read-only in the strictest sense: Current reads ConnectWise RMM and can never change anything in it.
Generate API access in Asio (one time)
- 11 · Open API AccessSign in at home.connectwise.com, launch the Asio platform, and go to Integrations → API Access in the side menu. Press + Generate API Access.
- 22 · Name it and tick the scopesName it something recognisable like Current, tick only the read scopes listed below, accept the consent checkbox, and Generate.
- 33 · Copy both values nowYou get a Client ID and a Client Secret. The secret is never shown again — copy it before closing. And know the sharp edge: Regenerate invalidates every previously issued credential on the spot, not just the one you're replacing.
Scopes to tick (all read-only): Platform – Companies – Read Platform – Sites – Read Platform – Devices – Read Platform – Assets – Read Platform – Agent – Read Platform – Os Patching Endpoint Patches – Read Platform – DeviceGroups – Read Platform – Performance – Read Platform – Policy – Read Security – Threats – Read
That scope set is deliberately read-only — there is no write scope on the list, so even the credential itself can't change anything in your RMM.
Connect it in Current
- 1Open the ConnectWise RMM cardIn Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find the ConnectWise RMM card in the Reporting integrations section.
- 2Paste the Client ID and Client SecretCurrent works out your region — North America, Europe, or Asia-Pacific — from the Client ID itself, and you can override it explicitly if yours is unusual.
- 3Press Test connectionCurrent exchanges the credentials for a token live to prove they work before storing anything, and surfaces ConnectWise's real error if they don't. On success the secret is stored server-side only — the browser never sees it again.
What Current syncs, and how often
The sync runs every 6 hours on its own, and Sync now covers the impatient path. Each run walks your sites and devices and writes value-signals — never a raw event firehose.
| Data set | What Current stores | Where it lands |
|---|---|---|
| Customer sites | Each site (your customer) by id and name, with its device count | The mapped Current company + SBR packs |
| Device inventory | Per device: hostname, device type, operating system, online/last-seen. No end-user personal data beyond the hostname | The mapped Current company + SBR packs |
| Patch posture | Per device, whether it's patch-compliant — where ConnectWise reports it. A device with no patch data reads as unknown, never as compliant | The company's posture panel + the SBR fleet chapter |
The read-only guarantee
Every request Current makes to ConnectWise RMM passes through a read-only guard that only permits the specific read endpoints above (plus the token exchange itself). Automations, scripts, policy changes, and credential management are not on the list and are unreachable, even by a code bug. Current cannot write to ConnectWise RMM.
Mapping RMM customers to your companies
Current matches each RMM site to one of your Current companies automatically by normalized name — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and links it only when exactly one company matches. Anything it can't match confidently is left for you.
- 1Let the auto-matcher run firstEvery sync, Current links each RMM site to the one Current company whose normalized name matches exactly (see above). Most sites map themselves — only the ambiguous ones need a hand.
- 2Open the mapping panelIntegrations → ConnectWise RMM → Manage → Customer mapping. It opens on the Unmapped tab, which lists every site the matcher couldn't place confidently.
- 3Map a site to its companyOn an unmapped row press Map, type a few letters of the Current company, and pick it. The site's devices and patch posture attach to that company right away — no wait for the next 6-hour sync.
- 4Ignore internal or test sitesFor a site that should never map to a customer — your own internal RMM, a lab, a test tenant — press Ignore. It moves to the Ignored tab and stops counting as unmapped, so the card's unmapped badge reflects only real work left to do.
- 5Fix a wrong match laterThe Mapped tab lists every linked site; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed site back. A manual map or unlink is never overwritten by a later auto-match.
- +Unmatched sites appear on the ConnectWise RMM card's mapping panel — press Map to pick the right Current company by hand.
- +A manual mapping is never overwritten by the auto-matcher on a later sync, and neither is a manual unlink.
- +Unmapped sites still sync — their devices are stored — but the data only appears on a company once the site is mapped to it.
When something looks wrong
| What you see | What it means |
|---|---|
| Test connection fails immediately | Usually the secret was mistyped or has since been regenerated (regenerating invalidates every old credential), or the region override is wrong. The message carries ConnectWise's real reason. |
| Card shows Error mentioning 401 after it was working | The credentials were regenerated or revoked in Asio. Generate a fresh pair (re-ticking the scopes) and reconnect. |
| A company shows no RMM data | Its site isn't mapped yet, or the site genuinely has no devices. Check the mapping panel's Unmatched list. |
| Patch posture is blank for some devices | ConnectWise hasn't reported patch data for them. Current shows unknown rather than guessing — the figure fills in when the data exists. |
