Evidence enters through a bounded service.
The current pilot shape connects a platform-specific agent, an authenticated FastAPI service and an operator review surface. Each layer has an explicit limit.
Where evidence enters, and where it stops.
The flow mirrors the current product boundary. It does not imply an unimplemented platform layer.
- 01
Agent
A platform-specific agent reports enrollment, heartbeat and available inventory fields. It does not send credentials or document contents as routine telemetry.
- 02
Authenticated service
The FastAPI service authenticates the device, stores customer-scoped records and evaluates explainable availability and health evidence.
- 03
Operator view
Authenticated operators use server-side permission checks to review fleet, device, job, report and audit routes.
- 04
Guarded support
Remote support is device-bound, permission-gated and short-lived; it remains a private preview capability until physical QA is complete.
Capability truth stays close to the evidence.
States below are intentionally conservative. Partial source coverage remains Preview until the full product boundary is accepted.
| Capability | Status | Evidence boundary | Public proof |
|---|---|---|---|
| Enrollment and device identity Device identity is stored server-side and scoped to the authenticated service. | Available | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Sanitized device identity view |
| Hardware inventory Only fields reported by the agent are shown; missing telemetry stays unknown. | Preview | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Interface preview |
| Software inventory Publisher, install date and other fields remain dependent on agent support. | Preview | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Software list preview |
| Online, offline and stale state Silence is reported as unavailable or stale evidence, not as proof of shutdown. | Available | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Availability report preview |
| Lifecycle, site and hierarchy Retire and restore preserve history and require fresh enrollment for a new credential. | Available | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Fleet filter preview |
| Jobs and bounded diagnostics Operator, target, state and result evidence are retained in the authenticated service. | Available | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Job timeline preview |
| RBAC and audit Administrative actions require server-side permissions; unknown admin routes deny by default. | Available | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Audit timeline preview |
| Remote support The workflow is implemented but remains gated by physical QA and deployment configuration. | Preview | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Sanitized support-session preview |
| Patch and broader device management Patch execution, mobile management, EDR and endpoint privilege management are not claimed here. | Planned | Source-backed capability and test evidence. Private operator boundary; no public credentials or production records. | Not shown as available |
Answers without the larger claim.
What platforms are supported now?
The accepted pilot baseline covers Windows amd64, Linux amd64/arm64 and macOS amd64/arm64. The exact pilot matrix is confirmed before access.
Is Endpoint an MDM?
No. Endpoint is presented as a focused device-operations preview. Broader MDM, mobile management and EDR claims are not made.
Can it patch devices or deploy software?
Some guarded control-plane foundations exist, but patch deployment and broader execution remain agent- and physical-QA-dependent. They are not represented as general availability.
What data does the agent collect?
The baseline covers device identity, reported inventory, availability and operational evidence. It should not routinely collect passwords, tokens, keystrokes, clipboard history or document contents.
How is access controlled?
Authenticated control-plane sessions, server-side role permissions, device bearer credentials and audit records form the access boundary.
This public page shows source-backed product shape and sanitized demonstration evidence for Endpoint. It is not a customer report, production dashboard or general-availability promise.
