Console & fleet

Steer sensitivity and ask timers

From the console you can tune how a fleet behaves without touching a single machine. Two families of controls are available on Cloud Enterprise devices: the sensitivity bands and the user confirmation-prompt hold timers. This page explains what each does and how it reaches the fleet.

~5 min read · Console & fleet

This is a Cloud Enterprise capability. Private daemons are not steered from the console; they take their settings through their own local channel.

Two families of knobs

The console exposes two kinds of control, delivered together to a device:

  • Sensitivity: the bands that decide whether a change is allowed, asked about, or reverted.
  • User confirmation-prompt timers: how long a held change waits for your answer.

Sensitivity

The sensitivity controls set where the boundaries sit between the three outcomes. There is a band above which a change is reverted, a band below which it is allowed, and an evidence control for changes that carry strong proof. Tighten them to hold more and ask more; loosen them to ask less. The exact numbers are yours to set and are deliberately not printed here.

User confirmation-prompt hold timers

When a change lands in the uncertain middle band, it is held and you are asked. Three timers govern that hold:

  • A longer answer window for a milder middle-band change.
  • A shorter answer window for a hotter one.
  • An absolute cap that bounds every hold from the moment it is created.
A timer is a fail-safe, not a release. While a change is held it stays in its safe state; if a window elapses with no answer, the change is rolled back, never waved through. Timeout is treated as a reject.

How a change reaches the fleet

A setting is edited in the console, stored on the device configuration, and delivered to the device on its next config poll. It applies to holds created after that point; a hold already waiting keeps the window it was armed with. Nothing about protected content travels this path, only the settings.

What the hold looks like on the device: user confirmation prompts. Where the outcomes are recorded: incidents and audit. Bundle these with model and mode: profiles.

Was this helpful?

Tune the whole fleet from one place.

Sensitivity and ask timers, delivered on the next poll, with no content ever leaving the machine. Enterprise, in the console.

Sign me up