DEVICE TRUST
Devices
See what needs attention, then take the next step.
Agent-reported checks. A passing result is a recent observation, not a security guarantee. How Trust works
DEVICE DETAILS
Loading device…
Checks
Device information
SHARED VISIBILITY
Checks
The checks your company uses, and exactly what each one reads.
Recent investigations What admins asked devices to read
Query text is visible to everyone signed in. Device answers remain admin-only.
ADMIN TOOLS
Investigate
Ask a specific question. Review the query, choose the devices, then read their answers.
A draft is never run automatically. Device answers are not sent to AI; your question is.
SETUP
Add devices
Download an installer and deploy it with your device-management tool. Trust starts collecting checks when the agent connects.
Prepare enrolment
Use an existing enrolment secret
Prepare the MDM rollout
For macOS, install the background-item profile first. It keeps the Trust service managed; macOS can still show a background-item notice. The quiet profile is optional and suppresses this notification category for every app on the Mac.
Assign the profile, wait until Iru reports it installed, then deploy the installer below. Use the quiet profile only if that is your company policy.
Deploy the agent
Hash-verified osquery · no self-updater
Run once as root through Iru. Set the Custom Script to “install once”; a failed run retries automatically.
The installer contains the enrolment secret. Iru owns future updates and removal. Trust will never delete a generic osquery installation.
Inspect installer
Agent endpoint:
Operator checks for Iru
Run these as separate one-time Custom Scripts when you need evidence in an Iru job. They never contain the enrolment secret.
Run the pilot check
Deploy to one device per operating system first. In Trust, wait for a fresh result, confirm the assigned person and run the local deployment audit before expanding the blueprint.
Open devices →CONFIGURATION
Settings
Connect the inventory, manage agent updates and keep access in the Hub.
Device assignments
Assets supplies the assigned person by serial number. Trust refreshes this connection every 15 minutes.
In Assets → Settings → Device trust, allow this Trust ID:
Deployment settings
Changing the gateway requires new installers. Existing agents keep their configured endpoint.
Agent updates
Iru is the update authority. Download a new reviewed installer from Add devices, test it on the pilot blueprint and then deploy it as an update. Trust does not run a hidden updater on employee devices.
Managed by the deployment tool · bundle 0.7.2
Agent performance Advanced
Changes apply after Save, when agents next retrieve their configuration.
Removed devices
Removing a device revokes Trust enrolment immediately. Use Iru to uninstall the agent, then save the job reference as proof. Trust never infers removal from an offline device.
Activity
| When | Who | What changed |
|---|
THE SHORT GUIDE
How Trust works
Know which device needs attention, what was checked and what to do next.
Connect your devices
IT deploys the read-only osquery agent from Add devices. Assets supplies the assigned person; IT can set a fallback assignment for unknown serials.
Work through what needs attention
Use the device filters, open an item and review its checks. Trust shows failures, missing answers and old evidence separately.
Verify the result
Apply the fix through your normal IT process. Keep the device online so its agent can report again, then refresh its page.
Reading a device's status
- Needs attention
- A recent check failed. Open the device to see the check and suggested next step.
- Not verified
- Answers are missing, a query could not run, or there are no active checks for this operating system.
- Out of date
- A check or the device's last contact is older than 24 hours. This is not proof of a failure or a recent pass.
- Checks passing
- All active, applicable checks have recent successful answers. This is not certification or a guarantee that the device is secure.
After upgrading from older Trust versions, old results wait for fresh agent answers because their per-check age was not recorded.
What employees can see
Employees see their assigned devices, results and the checks catalogue. Fleet viewers have read access to all devices. Admins manage checks, enrolment, assignments and investigations. These roles are set only in Hub → Permissions.
What Trust reads and sends
The Checks page exposes the configured SQL and pass rules. Admin investigations are listed there too; answers are admin-only. Queries can read system and application metadata. Trust restricts SQL and disables event streams and file carving, but the agent reports with the permissions granted to it.
AI drafting sends your question to the Hub-configured provider. Device answers are not automatically sent with it; avoid putting confidential data in the question.
Checks, fixes and notifications
The built-in catalogue is a starting point, not a certified CIS assessment. IT chooses checks appropriate to each operating system. Newly failing checks can notify the assigned active employee through the Hub. Delivery is best effort. Trust does not apply fixes or block company sign-in based on posture.
Agent updates and removal
Iru owns installer updates and removal. Trust revokes enrolment immediately, then waits for an IT audit reference instead of guessing whether an offline device was cleaned up. Unknown or shared osquery installations are never deleted automatically. Windows remains a pilot path.
For the company
Trust helps IT identify work and avoids manually collecting each device's settings. IT still deploys agents, chooses checks, investigates failures and performs remediation. Results are self-reported and can be falsified by a compromised device; there is no verified savings or compliance guarantee.