Skip to content

Production operations

These guides are for people who run the fleet after it ships: evidence, monitors, incidents, customer-facing status, and support access. Start with Production rollout for the release gate, or From signal to verified recovery when something is already broken.

What you need

You need toOpen
Qualify an image before a customer networkDevice preparation
Collect and search device logsConfigure logs and Search logs
Inspect host facts or recent device eventsDevice Diagnostics and Device timeline
Choose the right health checkCreate monitors and alerts
Separate ISP outages from product faultsISP tags and connection quality
Own an incident through recoveryIncidents and on-call
Investigate security activity or detectionsSecurity activity and detections
Turn on SAML and SCIMSSO and SCIM
Give L1 support a safe roleSupport team access
Show customers selected truthCustomer status visibility
Build a wallboard or dashboardDashboards

Prepare and deploy

GuideDescription
Device preparationGolden images, agent install, NTP, hardening.
Firewall operationsOutbound-only model in restricted networks.
Production rolloutProduction-image qualification, identity, pilot handoffs, and release gates.
Choose a remote-access methodDecide between Remote Shell, Wormhole, SSH, desktop, and file retrieval.

Logs, monitors, and tasks

GuideDescription
Logs and diagnostics setupAgent-side log setup before devices ship.
Configure logsAdd sources, search, and filter.
Search logsFind events across the fleet and attach log alert rules.
Device DiagnosticsHost and system evidence on the device workspace.
Device timelineLifecycle, connectivity, and operational events for one unit.
Monitors and alertsOverview of monitor types and alert triggers.
Create monitors and alertsChoose service, device, or user-impact checks.
Service monitorsHTTP, CORS, DNS, and heartbeats.
Device monitorsOne-device or fleet connectivity.
User-impact monitorsJourney and metric health from the application.
ISP tags and connection qualityASN-derived ISP cohorts and short-window link quality.
Scheduled tasksOverview of cron HTTP automation.
Task schedulingHTTP jobs on a cron schedule.

Incidents and customer surfaces

GuideDescription
Incidents and on-callQueue, acknowledgement, and escalation.
From signal to verified recoveryCanonical incident method.
DashboardsInternal walls and paired displays.
Customer surfacesWhat customers may see inside their boundary.
Customer status visibilityExternal status pages.
IntegrationsChat, on-call, webhooks, cellular, and security integrations.

Security operations

GuideDescription
Security activity and detectionsInvestigate activity, assign detection roles, and export to SIEM tooling.
SSO and SCIMDirectory sign-in, provisioning, and Organisation Admin break-glass.
Set up rolesSecurity Admin, Analyst, Viewer, and the wider OEM role set.
Permission areassecurity.read / security.write and related grants.
API keysOrganisation keys for Gateway and integrations.
Trust on someone else's networkPlatform, network, and device privilege boundaries.

Support and governance

GuideDescription
Support team accessSupport Engineer, scope tags, and when to stack log search.
Audit trails for supportAccess history for incidents.
Mapping devices to customersTags and naming conventions.
Set up rolesThe role set those support groups sit in.

Adjacent fleet guides

Use Fleet operations when the job is inventory, classes, or guarded multi-device actions:

Factory install

Review the security model before shipping devices with the agent pre-installed.