Managed devices and software inventory
Organize the fleet with device groups, monitor enrolled endpoints, request inventory scans, and manage baselines.
Managed devices and software inventory
Open Secure Vault → Trustity Vault → Devices to reach Managed devices. The page combines fleet groups, heartbeat, TAO health, module status, PAM state, and software inventory, and automatically refreshes every 15 seconds.
Access depends on the Vault entitlement. A Vault-scoped membership is intentionally limited to the Secure Vault sidebar. Some actions can affect endpoints or privileged local accounts; use an authorized operational role and approved change record.
Organize devices into groups
Use the Groups panel on the left to organize the fleet without changing how TAO enrolls.
- Select New to create a top-level group, or add a subgroup under an existing folder.
- Select devices with the checkbox (TAO-managed endpoints only), then choose Move to group… or Ungrouped.
- Select a group in the tree to filter the list (includes devices in that folder and its subgroups). Use All devices or Ungrouped as needed.
- Rename or delete groups from the row actions. Deleting a group ungroups its devices and moves child folders up one level.
Each device has at most one primary group. Groups are for organization and for per-group security policies (see Security Policies hub). They are separate from Deployment rings, which only control TAO update channels.
The list is built from enrolled TAO agents. If an agent is online but vault/PAM is not linked yet, the card may show Pending vault and PAM actions stay disabled until the vault row exists.
Review fleet health
- Review the totals for online, devices, TAO managed, and software items.
- Use All, Online, Offline, Pending, or VisionX.
- Search with Search hostname, user, IP… (hostname, user, IP, group name, or module).
- Confirm Auto-refresh every 15s or select Refresh.
- For each device, review Communication, TAO, Inventory, and PAM.
- Treat Rotation pending, Scan pending, or Rotation & scan pending as queued work awaiting agent communication.
An Online label reflects recent communication, not proof that every module is healthy. Review TAO health, version, policy version, module badges, and any VisionX detail.
Inspect one device
- Select the hostname for device detail, or review the summary card.
- Confirm hostname, IP, operating system, and Last heartbeat.
- Under TAO, confirm health, agent version, policy version, and expected modules.
- For VisionX devices, select Details and review Session helper, Model ready, Unlock code set, Camera ready, activation mode, and any Lock readiness message.
- Under Inventory, review app count, last scan time, and No scan yet, Scan is stale, Scan requested, or Inventory is fresh.
Request and review software inventory
Asset Inventory runs on the endpoint: TAO enumerates installed software (Windows Uninstall registry keys; Linux package managers) and reports a snapshot to the portal. The portal replaces the previous snapshot for that device on each successful report.
- On the device, select Scan.
- Confirm Inventory scan requested. Results appear after the next TAO heartbeat.
- Wait for the device to communicate; the card shows Scan requested while pending.
- Select Inventory to open Software Inventory.
- Review Name, Version, Publisher, and Install Date.
- Confirm the last-scan time and total item count.
A scan request is asynchronous. Repeated clicks do not make an offline device return faster.
On the agent UI, Asset Inventory should show LIVE after a successful report. A message such as Report failed: portal error … inventory insert failed means the endpoint collected data but the portal rejected the write - capture hostname, time, and exact text for Support. After a portal fix or retry, request Scan again and reopen the inventory modal.
Search software across the fleet
- Select Software.
- In Fleet Software Search, enter at least two characters of a software name or publisher.
- Optionally use Filter by device hostname... and All publishers.
- Review result totals, affected devices, publishers, and baseline status.
- Select Export CSV to export the currently filtered results.
The search may show showing first 100 matches. Narrow the query or filters before drawing fleet-wide conclusions.
Manage a software baseline
- In Fleet Software Search, locate a row with a valid version.
- Confirm the software name, publisher, device, and installed version.
- Select Use current as baseline only after the version is approved.
- Wait for Baseline saved for software.
- Search again and review Match, Drift, or No baseline.
A baseline is a comparison reference, not an automatic remediation action. Investigate drift before upgrading, removing, or approving software.
PAM and destructive-action caveats
The page may also expose local-account rotation and password controls. PAM manages local accounts only; domain or Active Directory users are not managed here. Restrict Reveal password, Copy password, Rotate, local-account selection, and Delete to specifically authorized operators.
Removing a device from the portal does not uninstall the agent. If TAO remains installed, the station can register again on a later heartbeat.
Troubleshooting
No devices enrolled yet
Select Open Deployment Center, install and enroll TAO with the correct organization key, and wait for the first heartbeat.
Device shows Pending vault
TAO enrolled successfully, but the vault/PAM host record is not linked yet. Health and modules still appear; wait for the next vault link path or complete PAM enrollment before using password controls.
Group filter shows no devices
Confirm devices are assigned to that group (or a subgroup). Use All devices to verify enrollment, then move selected agents into the group.
