Devices Console
Single-pane fleet view of every PC running CtrlOne - search, filter, group, and drill into per-device restriction status, last-seen, and live actions.
The web app your operators live in - dashboards, onboarding wizard, policy versioning + rollback, compliance evidence pack, employee portal, bulk actions, saved views, scheduled reports, outbound integrations, SSO, API tokens, BitLocker posture, endpoint isolation and more.
35 features
Single-pane fleet view of every PC running CtrlOne - search, filter, group, and drill into per-device restriction status, last-seen, and live actions.
Reusable bundles of restriction toggles you can apply to one PC, a group, or your whole fleet. Versioned, named, and easy to roll out or roll back.
Organise PCs into logical groups (offices, roles, kiosks) so policies and bulk commands target exactly the right machines without one-by-one work.
Curated bundles of restrictions for common scenarios (kiosk, finance team, contractor laptop) so operators don't have to remember which toggles belong together.
Invite teammates as admins or auditors, manage permissions, reset passwords, and audit sign-in history. Email-based invites and password-reset flows included.
Real-time stream of every blocked action on every PC - what was blocked, by which restriction, and when. Filter by device, user, or restriction.
Full hardware and software inventory for every managed PC - CPU, RAM, storage, OS build, installed applications, licence keys and device identifiers - collected at check-in and updated on every sync. Query, filter and export the fleet's asset register from the admin console without touching a single machine.
Curated, opinionated security defaults across screen, recording, USB, clipboard, print, network and apps - flip an entire hardening baseline in one click.
Push browser homepages, allowlists, blocklists, kiosk mode, SafeSearch, DNS filtering, and live URL blocking from one screen across the fleet.
Track licence keys, seat counts, subscription tier per device and per tenant. Activate, deactivate, transfer, and audit licence usage in one place.
Configure email delivery, branding, retention, audit-log cleanup, password policy, and other tenant-wide preferences without opening a config file.
QA-friendly screen that lets operators trigger and verify each restriction without touching production policies - invaluable during onboarding.
Remotely uninstall, reset, or rotate keys on devices that are leaving the fleet - including a forced-clean mode that takes the agent off the PC entirely.
Background engine that watches for offline devices, suspicious block-event spikes, licence expiry, and email-delivery failures - and emails the right operator.
Tamper-evident record of every admin action: policy edits, command queues, user invites, password resets, restores. Filter, export, and retain per policy.
Guided 4-step flow at /onboarding: claim key -> installer download -> first device check-in -> apply policy template. Polls every 5s while waiting for the first device so the operator sees the moment it arrives.
Every policy edit snapshots the prior state into policy_versions. Newest-first list with diff-vs-current and a one-click Restore. Rollback itself snapshots first so it stays undoable.
Streams a ZIP with audit log, policies, policy versions and device posture in CSV + JSON, plus a framework-specific README mapping evidence to controls. Ships templates for ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 20000-1:2018 and ISO 22301:2019. Manifest carries SHA-256 of every file.
Single-fetch /dashboard summary: devices online/offline/unclaimed, open alerts, operators, 7-day audit volume, agent-version mix and recently enrolled PCs. Auto-refreshes every 30s. Master-admin gets the cross-tenant rollup.
Cookie-gated /portal for end-users. The local agent mints a short-lived signed link the user clicks; they see their device, the restrictions currently on, and can submit unblock-app / temp-unrestrict / other requests for an admin to decide.
Selection bar above the device list for bulk reassign, bulk uninstall and bulk re-policy. Audited per-action; admin / owner only for destructive ones.
Save the current filter, search, sort and column set as a named view. Private-by-default with a per-tenant share toggle so the whole console can land on the same starting page.
Hard ceilings on devices and operators, enforced server-side as a safety floor independent of plan + seat overrides. Stops a runaway script from enrolling 10,000 PCs into a 50-seat plan.
Per-tenant logos, colours and installer product names. Branding applies to the admin console, the employee portal, and the NSIS installer's UI strings.
Cron-style report schedules that email a PDF or CSV to a distribution list. Built-in templates for fleet posture, audit summary and policy drift.
Per-tenant outbound dispatcher pushes alerts to Slack, Teams, PagerDuty, generic webhooks, Splunk HEC and Microsoft Sentinel. Secret rotation and per-channel filters are first-class.
Each tenant brings its own IdP. State between login start and IdP callback is carried in HMAC-signed envelopes so there's no shared session store to scale or leak.
Mint, scope and revoke long-lived tokens for service accounts. Tokens are role-aware so a CI runner can read inventory without being able to issue commands.
One-click 'cut this PC off the network' that drops a deny-by-default Windows Filtering Platform rule keeping only the agent's cloud channel reachable. Reversible from the same button.
Operator-initiated remote sessions via the device's installed remote-control tool (AnyDesk-class). Agent reports installed/running status and can wipe the tool's saved ID for a clean session.
Force-install missing security patches, surface the per-device patch backlog and roll up across the fleet. Pairs with the offline fail-closed window so unpatched offline PCs degrade automatically.
Per-device BitLocker enable/disable/pause/resume plus a fleet posture rollup: which volumes are protected, which are suspended for the next reboot and which are unprotected.
Heartbeat surface for Defender real-time, signature freshness, Tamper Protection, and any 3rd-party AV / EDR registered with Security Center. A drift in any of these becomes an alert.
Per-device adapter, IP, gateway, DNS, public IP and last-seen-on-which-Wi-Fi data. Used by the geofence and the 'this PC moved off the corporate network' alert.
Per-device USB write events: which file, which volume, which user, when. Pairs with USB Storage Lockdown so the operator can flip from monitor to enforce on a single PC or the whole fleet.