Skip to content

Provision and claim

Provisioning establishes device identity and its initial organisation and class context. After first connection, assign customer or site context so the device is supportable as shipped inventory.

Provision securely

An organisation provisioning key authorises agent provisioning. The organisation can define a default device class, and supported install flows can select an explicit class.

  1. Create or select an organisation provisioning key.
  2. Set the intended default class or include the explicit supported class selection.
  3. Run preflight against the target operating system and network.
  4. Provision one staging device and verify its organisation, class, architecture, and first connection.
  5. Add the key to a controlled manufacturing or image-build process.

Treat provisioning keys as secrets. Do not commit them to source control, bake a reusable plaintext key into a customer-readable image, print them in support logs, or reuse them across untrusted manufacturers. Rotate after exposure or supplier change and validate the replacement before revoking the old path.

Use organisation keys with explicit or default class assignment. Migrate any class-scoped keys into this model.

Complete the ownership handoff

After first connection:

  1. Confirm the device identity, organisation, class, architecture, and connectivity state.
  2. Apply the approved customer, site, and operational tags.
  3. Where customer and site modules are enabled, associate the device with the supported records.
  4. Verify that the support team can find the device and reach the intended logs, monitors, and remote tools.
  5. Treat the unit as shipped inventory only after that context is complete.