Concepts
Tenants
A tenant is one customer. Everything a customer owns (devices, sites, packages, scripts, deployments, alerts, audit entries) belongs to exactly one tenant, and users of a tenant only ever see that tenant.
A tenant is an organization of Entrosity Hub that has Axis enabled: it is created, renamed and suspended there. A tenant is either active or suspended. Suspending it signs its users out of Axis within about a minute and disconnects its agents and connectors.
Users and roles
Users are Entrosity accounts: they sign in on Entrosity Hub, where they are invited and given their role in each organization. A user can have a role in several tenants. There are four roles:
| Role | Scope | In short |
|---|---|---|
| Global admin | The whole installation | Entrosity staff (the Hub's platform admins). Manages the global library and agent releases, and can open any tenant. |
| Tenant admin | One tenant | Sets up the customer: sites, enrollment, AD, packages, scripts, alert rules, settings. |
| Technician | One tenant | Day-to-day work: device actions, deployments, scripts, alerts. |
| Viewer | One tenant | Read-only. |
The full permission matrix is on Roles and permissions.
Sites
A site is a physical or logical location inside a tenant, such as "HQ" or "Branch office". Each device belongs to one site. A site has a time zone, which is used for deployment maintenance windows. Site connectors are installed per site.
Devices
A device is one Windows computer. A device can be known from two sources:
- agent: the Entrosity Axis agent is installed and reports in;
- ad: the computer was found in Active Directory by the site connector;
- both: the two records were matched and merged.
A device's status is online, offline (three missed heartbeats,
about three minutes), never_connected (known from AD only) or
decommissioned.
Agent
The agent (rmm-agent, Windows service RMMAgent) runs as SYSTEM on
every managed PC. It enrolls once with an enrollment token, then keeps
a WebSocket open to the server, sends a heartbeat every 60 seconds and
inventory reports, and executes jobs one at a time.
Site connector
The site connector (rmm-connector, Windows service RMMConnector)
runs on one domain-joined server per site. It syncs AD computers over
LDAP(S), pushes the agent to computers over SMB (or WinRM), and sends
wake-on-LAN packets. It enrolls with a connector enrollment token.
Enrollment tokens
An enrollment token lets new agents (kind agent) or connectors (kind
connector) join a tenant and a site. Tokens can have an expiry and a
maximum number of uses, and are shown only once. Revoking a token does not
affect installations that already enrolled.
Jobs
A job is one unit of work for one agent or connector: install a package, run a script, reboot, collect inventory, sync AD, push the agent, update itself. Jobs are pushed over the WebSocket, acknowledged, run, and report a result. Offline devices get their jobs when they reconnect, until the job expires.
Packages and deployments
A package describes software: an uploaded MSI or EXE, a PowerShell script, or a winget package ID, plus optional detection rules that tell whether it is installed. A deployment installs or uninstalls a package on a set of devices (targets), with a schedule, maintenance window, concurrency limit, retries and a reboot policy.
Global library
Global admins can create global packages, scripts and alert rules. They are visible (read-only) and usable in every tenant. Tenants can switch individual global alert rules off.
Alerts
An alert rule describes a condition (for example "disk free below 10 %"). The server evaluates every rule once a minute and opens, updates and resolves alerts by itself. Users acknowledge or resolve alerts and choose which ones they get by e-mail.
Audit log
Every change made through the portal and every job created is written to the audit log with who, what, when, where from, and before and after values (secrets redacted).