Admin Console

The web app your operators live in - dashboards, onboarding wizard, policy versioning + rollback, compliance evidence pack, employee portal, bulk actions, saved views, scheduled reports, outbound integrations, SSO, API tokens, BitLocker posture, endpoint isolation and more.

35 features

Devices Console

Single-pane fleet view of every PC running CtrlOne - search, filter, group, and drill into per-device restriction status, last-seen, and live actions.

Policies

Reusable bundles of restriction toggles you can apply to one PC, a group, or your whole fleet. Versioned, named, and easy to roll out or roll back.

Device Groups

Organise PCs into logical groups (offices, roles, kiosks) so policies and bulk commands target exactly the right machines without one-by-one work.

Feature Groups

Curated bundles of restrictions for common scenarios (kiosk, finance team, contractor laptop) so operators don't have to remember which toggles belong together.

User Management

Invite teammates as admins or auditors, manage permissions, reset passwords, and audit sign-in history. Email-based invites and password-reset flows included.

Block Events

Real-time stream of every blocked action on every PC - what was blocked, by which restriction, and when. Filter by device, user, or restriction.

Asset Management

Full hardware and software inventory for every managed PC - CPU, RAM, storage, OS build, installed applications, licence keys and device identifiers - collected at check-in and updated on every sync. Query, filter and export the fleet's asset register from the admin console without touching a single machine.

Enterprise Security Baseline

Curated, opinionated security defaults across screen, recording, USB, clipboard, print, network and apps - flip an entire hardening baseline in one click.

Browser Control Center

Push browser homepages, allowlists, blocklists, kiosk mode, SafeSearch, DNS filtering, and live URL blocking from one screen across the fleet.

Premium / Licence Management

Track licence keys, seat counts, subscription tier per device and per tenant. Activate, deactivate, transfer, and audit licence usage in one place.

Org Settings

Configure email delivery, branding, retention, audit-log cleanup, password policy, and other tenant-wide preferences without opening a config file.

Restriction Test Bench

QA-friendly screen that lets operators trigger and verify each restriction without touching production policies - invaluable during onboarding.

Uninstall Master

Remotely uninstall, reset, or rotate keys on devices that are leaving the fleet - including a forced-clean mode that takes the agent off the PC entirely.

Alerts Engine

Background engine that watches for offline devices, suspicious block-event spikes, licence expiry, and email-delivery failures - and emails the right operator.

Admin Audit Log

Tamper-evident record of every admin action: policy edits, command queues, user invites, password resets, restores. Filter, export, and retain per policy.

Tenant Onboarding Wizard

Guided 4-step flow at /onboarding: claim key -> installer download -> first device check-in -> apply policy template. Polls every 5s while waiting for the first device so the operator sees the moment it arrives.

Policy Versioning + Rollback

Every policy edit snapshots the prior state into policy_versions. Newest-first list with diff-vs-current and a one-click Restore. Rollback itself snapshots first so it stays undoable.

Compliance Evidence Pack

Streams a ZIP with audit log, policies, policy versions and device posture in CSV + JSON, plus a framework-specific README mapping evidence to controls. Ships templates for ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 20000-1:2018 and ISO 22301:2019. Manifest carries SHA-256 of every file.

Per-Tenant Dashboard

Single-fetch /dashboard summary: devices online/offline/unclaimed, open alerts, operators, 7-day audit volume, agent-version mix and recently enrolled PCs. Auto-refreshes every 30s. Master-admin gets the cross-tenant rollup.

Employee Self-Service Portal

Cookie-gated /portal for end-users. The local agent mints a short-lived signed link the user clicks; they see their device, the restrictions currently on, and can submit unblock-app / temp-unrestrict / other requests for an admin to decide.

Bulk Device Actions

Selection bar above the device list for bulk reassign, bulk uninstall and bulk re-policy. Audited per-action; admin / owner only for destructive ones.

Saved Device Views

Save the current filter, search, sort and column set as a named view. Private-by-default with a per-tenant share toggle so the whole console can land on the same starting page.

Per-Tenant Device + Operator Caps

Hard ceilings on devices and operators, enforced server-side as a safety floor independent of plan + seat overrides. Stops a runaway script from enrolling 10,000 PCs into a 50-seat plan.

Per-Tenant Custom Branding

Per-tenant logos, colours and installer product names. Branding applies to the admin console, the employee portal, and the NSIS installer's UI strings.

Scheduled Reports (PDF / CSV)

Cron-style report schedules that email a PDF or CSV to a distribution list. Built-in templates for fleet posture, audit summary and policy drift.

Outbound Integrations

Per-tenant outbound dispatcher pushes alerts to Slack, Teams, PagerDuty, generic webhooks, Splunk HEC and Microsoft Sentinel. Secret rotation and per-channel filters are first-class.

Per-Tenant SSO (SAML + OIDC)

Each tenant brings its own IdP. State between login start and IdP callback is carried in HMAC-signed envelopes so there's no shared session store to scale or leak.

Service-Account API Tokens

Mint, scope and revoke long-lived tokens for service accounts. Tokens are role-aware so a CI runner can read inventory without being able to issue commands.

Endpoint Isolation

One-click 'cut this PC off the network' that drops a deny-by-default Windows Filtering Platform rule keeping only the agent's cloud channel reachable. Reversible from the same button.

Remote Control Tooling

Operator-initiated remote sessions via the device's installed remote-control tool (AnyDesk-class). Agent reports installed/running status and can wipe the tool's saved ID for a clean session.

Patch Enforcement

Force-install missing security patches, surface the per-device patch backlog and roll up across the fleet. Pairs with the offline fail-closed window so unpatched offline PCs degrade automatically.

BitLocker Posture

Per-device BitLocker enable/disable/pause/resume plus a fleet posture rollup: which volumes are protected, which are suspended for the next reboot and which are unprotected.

AV / EDR / Defender Health

Heartbeat surface for Defender real-time, signature freshness, Tamper Protection, and any 3rd-party AV / EDR registered with Security Center. A drift in any of these becomes an alert.

Network Telemetry

Per-device adapter, IP, gateway, DNS, public IP and last-seen-on-which-Wi-Fi data. Used by the geofence and the 'this PC moved off the corporate network' alert.

USB DLP

Per-device USB write events: which file, which volume, which user, when. Pairs with USB Storage Lockdown so the operator can flip from monitor to enforce on a single PC or the whole fleet.