Pilot to production rollout
Expand Trustity from a verified pilot into production with staged rings, change control, and measurable exit criteria.
Pilot to production rollout
A successful Trustity deployment starts with a controlled pilot, not an organization-wide policy flip. Use this guide after at least one healthy enrolled endpoint and after the relevant modules have been validated in a low-risk environment.
Scope
This article covers change management for TAO, GenGuard, VisionX, Vault/PAM, HostGuard IPS, and portal administration. It does not replace module-specific runbooks.
Trustity supports MDM rings for initial install and portal prod/eval branches for ongoing TAO updates after enroll. Download the first installer from Cloud Portal → Deployment, then use Deployment control for version targeting (Latest / Previous on prod; eval for canary). See TAO deployment branches and auto-update.
Prerequisites
- Organization onboarding and entitlements confirmed
- Deployment downloads available from Cloud Portal → Deployment
- At least one verified healthy endpoint per major OS in scope
- Named owners for policy, deployment, helpdesk, and security response
- Documented exception process before aggressive enforcement
- Related module guides reviewed for entitled capabilities
Recommended rings (organizational)
| Ring | Audience | Goal |
|---|---|---|
| 0 - Lab | Dedicated test devices | Validate install, enrollment, policy refresh, and low-impact tests |
| 1 - IT / Security | Endpoint engineers and security operators | Confirm admin workflows, event triage, unlock/reveal hygiene, and support readiness |
| 2 - Pilot business unit | Representative users and jump hosts | Measure false positives, helpdesk volume, and operational friction |
| 3 - Broad production | Remaining entitled devices and browsers | Expand only after exit criteria are met |
Do not skip Ring 1 for modules that can lock screens, block browser actions, rotate passwords, or create firewall blocks.
Portal Deployment control maps eval/prod branches onto this model for TAO version rollout after agents are enrolled. MDM rings remain the right place for first-time install and GenGuard policy waves.
Rollout procedure
- Freeze a written pilot plan: modules, rings, start date, success metrics, rollback owner, and support hours.
- Confirm packaging and license handling remain tenant-specific. Use placeholders in documentation and scripts; never publish live organization license keys.
- Apply AV/EDR exclusions for TAO to the next ring before install when another endpoint security product is present.
- Deploy TAO and, where entitled, GenGuard force-install to the next ring only.
- Start with observe-friendly settings where available:
- VisionX: pilot activation and tuning before org-wide Strict or Always-on enforcement; confirm Strict no-camera locks appear in portal Events/Incidents on a current agent
- HostGuard: Report only before firewall enforcement
- GenGuard: limited templates or allow-listed tools before aggressive blocks
- Vault/PAM: targeted local accounts and force-rotate validation before broad schedules
- Save policy, wait for entitled online agents to refresh, and verify health in Managed devices.
- Run the module validation checklist from the relevant KB article.
- Review Audit Logs, module Live Events, and Activity Log for unexpected volume or failures.
- Hold a go/no-go review before promoting the next ring (including a newer TAO Setup version).
Exit criteria for each ring
Promote only when all of the following are true for that ring:
- Enrollment success rate meets the agreed threshold
- Agent online rate and version currency are acceptable
- Policy changes appear on sample endpoints after a normal refresh window
- Helpdesk can execute unlock, reveal, or unblock procedures without sharing secrets in tickets
- False-positive or exception volume is understood and owned
- Audit and event views show the actions operators expect
- Inventory scans return expected item counts on sample hosts
- Rollback or ring-pause steps are documented and tested enough to use under pressure
Change control
- Change one major control family at a time when possible.
- Record who approved the change, when it was saved, and which ring it affects.
- Keep a short before/after note for threshold, template, activation-mode, and rotation-interval changes.
- Prefer temporary exceptions with owners and expiry dates over permanent weakenings.
Rollback and pause options
Depending on the module, pause impact by:
- Reverting the policy to the previous saved configuration
- Moving VisionX to Standby or a narrower on-demand scope
- Returning HostGuard to Report only
- Softening GenGuard templates or domain/keyword rules
- Pausing scheduled PAM rotation while leaving vault access least-privileged
- Stopping further package assignment while leaving already-enrolled healthy agents in place
Do not uninstall the agent fleet as the first response to a policy issue unless the incident requires it.
Security considerations
- Limit who can change production policy and who can reveal vaulted credentials.
- Treat license keys, unlock codes, uninstall codes, and vaulted passwords as secrets.
- Ensure employee-monitoring notices and local legal requirements are addressed before enabling camera, browser, or endpoint enforcement.
- Keep evidence, vault reveals, and unlock assistance inside approved channels only.
