Your company workspace

Welcome to Trust.

Your company account. One sign-in for all your tools.

Checking your session…

Your Hub checks your access and brings you straight back here.

Access is managed by your company in the Hub.

DEVICE TRUST

Devices

See what needs attention, then take the next step.

Loading devices…

Agent-reported checks. A passing result is a recent observation, not a security guarantee. How Trust works

← Devices

DEVICE DETAILS

Loading device…

Checks

Device information

SHARED VISIBILITY

Checks

The checks your company uses, and exactly what each one reads.

Recent investigations What admins asked devices to read

Query text is visible to everyone signed in. Device answers remain admin-only.

ADMIN TOOLS

Investigate

Ask a specific question. Review the query, choose the devices, then read their answers.

A draft is never run automatically. Device answers are not sent to AI; your question is.

← Devices

SETUP

Add devices

Download an installer and deploy it with your device-management tool. Trust starts collecting checks when the agent connects.

1

Prepare enrolment

Use an existing enrolment secret
2

Prepare the MDM rollout

For macOS, install the background-item profile first. It keeps the Trust service managed; macOS can still show a background-item notice. The quiet profile is optional and suppresses this notification category for every app on the Mac.

Assign the profile, wait until Iru reports it installed, then deploy the installer below. Use the quiet profile only if that is your company policy.

3

Deploy the agent

trust-macos-install.sh

Hash-verified osquery · no self-updater

Run once as root through Iru. Set the Custom Script to “install once”; a failed run retries automatically.

The installer contains the enrolment secret. Iru owns future updates and removal. Trust will never delete a generic osquery installation.

Inspect installer

Agent endpoint:

Operator checks for Iru

Run these as separate one-time Custom Scripts when you need evidence in an Iru job. They never contain the enrolment secret.

4

Run the pilot check

Deploy to one device per operating system first. In Trust, wait for a fresh result, confirm the assigned person and run the local deployment audit before expanding the blueprint.

Open devices →

CONFIGURATION

Settings

Connect the inventory, manage agent updates and keep access in the Hub.

Device assignments

Assets supplies the assigned person by serial number. Trust refreshes this connection every 15 minutes.

In Assets → Settings → Device trust, allow this Trust ID:

Deployment settings

Changing the gateway requires new installers. Existing agents keep their configured endpoint.

Agent updates

Iru is the update authority. Download a new reviewed installer from Add devices, test it on the pilot blueprint and then deploy it as an update. Trust does not run a hidden updater on employee devices.

Managed by the deployment tool · bundle 0.7.2

Agent performance Advanced

Changes apply after Save, when agents next retrieve their configuration.

Removed devices

Removing a device revokes Trust enrolment immediately. Use Iru to uninstall the agent, then save the job reference as proof. Trust never infers removal from an offline device.

Activity
WhenWhoWhat changed

THE SHORT GUIDE

How Trust works

Know which device needs attention, what was checked and what to do next.

1

Connect your devices

IT deploys the read-only osquery agent from Add devices. Assets supplies the assigned person; IT can set a fallback assignment for unknown serials.

2

Work through what needs attention

Use the device filters, open an item and review its checks. Trust shows failures, missing answers and old evidence separately.

3

Verify the result

Apply the fix through your normal IT process. Keep the device online so its agent can report again, then refresh its page.

Reading a device's status

Needs attention
A recent check failed. Open the device to see the check and suggested next step.
Not verified
Answers are missing, a query could not run, or there are no active checks for this operating system.
Out of date
A check or the device's last contact is older than 24 hours. This is not proof of a failure or a recent pass.
Checks passing
All active, applicable checks have recent successful answers. This is not certification or a guarantee that the device is secure.

After upgrading from older Trust versions, old results wait for fresh agent answers because their per-check age was not recorded.

What employees can see

Employees see their assigned devices, results and the checks catalogue. Fleet viewers have read access to all devices. Admins manage checks, enrolment, assignments and investigations. These roles are set only in Hub → Permissions.

What Trust reads and sends

The Checks page exposes the configured SQL and pass rules. Admin investigations are listed there too; answers are admin-only. Queries can read system and application metadata. Trust restricts SQL and disables event streams and file carving, but the agent reports with the permissions granted to it.

AI drafting sends your question to the Hub-configured provider. Device answers are not automatically sent with it; avoid putting confidential data in the question.

Checks, fixes and notifications

The built-in catalogue is a starting point, not a certified CIS assessment. IT chooses checks appropriate to each operating system. Newly failing checks can notify the assigned active employee through the Hub. Delivery is best effort. Trust does not apply fixes or block company sign-in based on posture.

Agent updates and removal

Iru owns installer updates and removal. Trust revokes enrolment immediately, then waits for an IT audit reference instead of guessing whether an offline device was cleaned up. Unknown or shared osquery installations are never deleted automatically. Windows remains a pilot path.

For the company

Trust helps IT identify work and avoids manually collecting each device's settings. IT still deploys agents, chooses checks, investigates failures and performs remediation. Results are self-reported and can be falsified by a compromised device; there is no verified savings or compliance guarantee.