1. The endpoint agent
A code-signed service installed on each managed device. It collects performance and inventory data, evaluates the policies assigned to that device, executes approved scripts and patch jobs, and brokers remote sessions. It is visible in the installed-programs list and can be removed with a documented command.
2. The cloud platform
Hosted in United States data center regions for US accounts. It stores telemetry, inventory, policies, scripts and audit records; runs the alerting and automation engines; and serves the console API. Multi-tenant isolation is enforced at the data layer, not only in the interface.
3. The browser console
Works in current versions of Chrome, Edge, Firefox and Safari. No plug-in, no desktop client required. Technicians authenticate with MFA, see only the tenants their role allows, and can launch a remote session directly from an alert or asset record.