Appearance
Production operations
These guides are for people who run the fleet after it ships: evidence, monitors, incidents, customer-facing status, and support access. Start with Production rollout for the release gate, or From signal to verified recovery when something is already broken.
What you need
| You need to | Open |
|---|---|
| Qualify an image before a customer network | Device preparation |
| Collect and search device logs | Configure logs and Search logs |
| Inspect host facts or recent device events | Device Diagnostics and Device timeline |
| Choose the right health check | Create monitors and alerts |
| Separate ISP outages from product faults | ISP tags and connection quality |
| Own an incident through recovery | Incidents and on-call |
| Investigate security activity or detections | Security activity and detections |
| Turn on SAML and SCIM | SSO and SCIM |
| Give L1 support a safe role | Support team access |
| Show customers selected truth | Customer status visibility |
| Build a wallboard or dashboard | Dashboards |
Prepare and deploy
| Guide | Description |
|---|---|
| Device preparation | Golden images, agent install, NTP, hardening. |
| Firewall operations | Outbound-only model in restricted networks. |
| Production rollout | Production-image qualification, identity, pilot handoffs, and release gates. |
| Choose a remote-access method | Decide between Remote Shell, Wormhole, SSH, desktop, and file retrieval. |
Logs, monitors, and tasks
| Guide | Description |
|---|---|
| Logs and diagnostics setup | Agent-side log setup before devices ship. |
| Configure logs | Add sources, search, and filter. |
| Search logs | Find events across the fleet and attach log alert rules. |
| Device Diagnostics | Host and system evidence on the device workspace. |
| Device timeline | Lifecycle, connectivity, and operational events for one unit. |
| Monitors and alerts | Overview of monitor types and alert triggers. |
| Create monitors and alerts | Choose service, device, or user-impact checks. |
| Service monitors | HTTP, CORS, DNS, and heartbeats. |
| Device monitors | One-device or fleet connectivity. |
| User-impact monitors | Journey and metric health from the application. |
| ISP tags and connection quality | ASN-derived ISP cohorts and short-window link quality. |
| Scheduled tasks | Overview of cron HTTP automation. |
| Task scheduling | HTTP jobs on a cron schedule. |
Incidents and customer surfaces
| Guide | Description |
|---|---|
| Incidents and on-call | Queue, acknowledgement, and escalation. |
| From signal to verified recovery | Canonical incident method. |
| Dashboards | Internal walls and paired displays. |
| Customer surfaces | What customers may see inside their boundary. |
| Customer status visibility | External status pages. |
| Integrations | Chat, on-call, webhooks, cellular, and security integrations. |
Security operations
| Guide | Description |
|---|---|
| Security activity and detections | Investigate activity, assign detection roles, and export to SIEM tooling. |
| SSO and SCIM | Directory sign-in, provisioning, and Organisation Admin break-glass. |
| Set up roles | Security Admin, Analyst, Viewer, and the wider OEM role set. |
| Permission areas | security.read / security.write and related grants. |
| API keys | Organisation keys for Gateway and integrations. |
| Trust on someone else's network | Platform, network, and device privilege boundaries. |
Support and governance
| Guide | Description |
|---|---|
| Support team access | Support Engineer, scope tags, and when to stack log search. |
| Audit trails for support | Access history for incidents. |
| Mapping devices to customers | Tags and naming conventions. |
| Set up roles | The role set those support groups sit in. |
Adjacent fleet guides
Use Fleet operations when the job is inventory, classes, or guarded multi-device actions:
Factory install
Review the security model before shipping devices with the agent pre-installed.