The full platform

Everything MAJIC can do — on your own hardware

One agent, one install. Below is the full capability set: how MAJIC reaches your machines, runs its own AI, sets itself up across your domain, and keeps every byte inside your network.

Reach any machine

Multiple remote-execution methods — always a path in

MAJIC never depends on a single channel. It picks the fastest available method and falls back automatically, so a machine is reachable even if its IP changes or it moves networks.

API dispatch Primary

The control plane sends a command to the central API; the target's agent picks it up over a live SignalR hub and runs it in seconds. Fastest path, fully audited server-side.

Scheduled-task exec

For privileged or network-credentialed work, the agent registers a one-time elevated scheduled task — the same trick used for SQL and cross-machine hops.

WinRM / PowerShell remoting

Domain-wide remote PowerShell for fleet sweeps, installs, and orchestration across every Windows host at once.

SSH over encrypted tunnel

Every host gets an outbound-only Cloudflare tunnel — key-based SSH from anywhere, no open ports, works behind any NAT or WAN.

Direct agent commands

Read checks, status, inventory, and service control run locally on the agent with zero round-trips.

SQL & double-hop

Reach database servers and network resources through a credentialed worker, so data-tier tasks run without exposing credentials.

Your own AI brain

One-file local LLM install — your models, your GPUs

MAJIC installs and serves large language models on your own hardware. No tokens billed to a third party, no prompts leaving your network.

One-file model install

The installer stands up the local inference stack (Ollama + a routing layer) and pulls the models — a single file does the whole setup, no ML expertise required.

Multi-LLM orchestrator

Fast lane for quick answers, deep-thinking lane for hard problems, and a vision lane — MAJIC routes each request to the right local model automatically.

Runs on your GPUs

From a single workstation card to a multi-GPU server — MAJIC manages quantization and load so big models run on the hardware you already own.

Bring-your-own keys (optional)

Want to burst to a cloud model for a specific task? Add your own API key, gated by org-admin — MAJIC stays local by default.

Sets itself up

Auto domain-joined chat & onboarding

Drop MAJIC on a domain and it configures itself — devices auto-enroll, users sign in with what they already have, and the AI is seeded with your business on day one.

Auto domain chat setup

On a Windows domain, domain-joined machines auto-enroll and trusted users get instant, zero-config access to the company chat — no per-machine keys to hand out.

Sign in with what you have

Google Workspace / Microsoft 365 single sign-on, or local accounts — plus domain-verification (DNS TXT) and email 2FA for org onboarding.

/import — learns your business

One command pulls in your existing knowledge, chat history, device inventory, and your public website, then trains your private model so the AI knows your operation from the start.

Per-org isolated knowledge

Every organization's AI memory lives in its own isolated store on its own servers — physically separated from everyone else, invisible even to MAJIC operators.

Manage & automate

Full fleet management + process automation

Live monitoring — CPU, memory, disk, who's logged on, what's running, across every PC and server.
Remote management — reboot, restart services, push fixes, run scripts from one dashboard or by asking in plain English.
Self-healing agents — auto-update and recover without a tech touching the box.
Live alerts & activity feed — know the moment something needs attention.
Bottleneck detection — MAJIC watches how work flows and surfaces the repetitive processes costing your team hours.
Email-pattern automation — connected to your mail, it learns recurring request/response patterns and offers to handle them for you.
AI / MCP connectors — let the AI act on your systems with scoped, revocable tokens; read-only by default, write with API Access.
Role-based team access & MFA — full audit log of who did what, when, on every device.
Zero-trust by design

Security built for companies that mean it

No open ports

Every agent dials OUT through an encrypted tunnel. Nothing to forward, nothing to attack on your router.

Data never leaves

Inference, knowledge, and conversations stay on your hardware and inside your network. No third-party cloud.

Step-up MFA on sensitive actions

Reboots, config changes, and remote exec require step-up auth and are fully logged.

Per-org isolation

Each organization's data lives in its own physically separate store — multi-tenant safe.

Scoped, revocable tokens

Every integration and connector uses least-privilege tokens you can revoke instantly.

Full audit trail

Every action, by every user and the AI, is recorded with who/what/when across the fleet.

How it ships

One install. Scales from a home lab to a multi-site enterprise.

One-file install

The single installer hardens the host too — enables remote access, sets power & uptime, and wires the tunnel so the box stays reachable.

Domain & non-domain

Personal machines, standalone servers, and full Active Directory domains all supported.

API Access (token credits)

Let the AI connector act on your fleet — fix things, not just report. Billed in simple token-based credits.

See it built for your business

Have a demo code? View the preview we personalized for you.

Enter your demo code →    Visit appmajic.ai