Skip to main content

Concepts

Tenants​

A tenant is one customer. Everything a customer owns (devices, sites, packages, scripts, deployments, alerts, audit entries) belongs to exactly one tenant, and users of a tenant only ever see that tenant.

A tenant is an organization of Entrosity Hub that has Axis enabled: it is created, renamed and suspended there. A tenant is either active or suspended. Suspending it signs its users out of Axis within about a minute and disconnects its agents and connectors.

Users and roles​

Users are Entrosity accounts: they sign in on Entrosity Hub, where they are invited and given their role in each organization. A user can have a role in several tenants. There are four roles:

RoleScopeIn short
Global adminThe whole installationEntrosity staff (the Hub's platform admins). Manages the global library and agent releases, and can open any tenant.
Tenant adminOne tenantSets up the customer: sites, enrollment, AD, packages, scripts, alert rules, settings.
TechnicianOne tenantDay-to-day work: device actions, deployments, scripts, alerts.
ViewerOne tenantRead-only.

The full permission matrix is on Roles and permissions.

Sites​

A site is a physical or logical location inside a tenant, such as "HQ" or "Branch office". Each device belongs to one site. A site has a time zone, which is used for deployment maintenance windows. Site connectors are installed per site.

Devices​

A device is one Windows computer. A device can be known from two sources:

  • agent: the Entrosity Axis agent is installed and reports in;
  • ad: the computer was found in Active Directory by the site connector;
  • both: the two records were matched and merged.

A device's status is online, offline (three missed heartbeats, about three minutes), never_connected (known from AD only) or decommissioned.

Agent​

The agent (rmm-agent, Windows service RMMAgent) runs as SYSTEM on every managed PC. It enrolls once with an enrollment token, then keeps a WebSocket open to the server, sends a heartbeat every 60 seconds and inventory reports, and executes jobs one at a time.

Site connector​

The site connector (rmm-connector, Windows service RMMConnector) runs on one domain-joined server per site. It syncs AD computers over LDAP(S), pushes the agent to computers over SMB (or WinRM), and sends wake-on-LAN packets. It enrolls with a connector enrollment token.

Enrollment tokens​

An enrollment token lets new agents (kind agent) or connectors (kind connector) join a tenant and a site. Tokens can have an expiry and a maximum number of uses, and are shown only once. Revoking a token does not affect installations that already enrolled.

Jobs​

A job is one unit of work for one agent or connector: install a package, run a script, reboot, collect inventory, sync AD, push the agent, update itself. Jobs are pushed over the WebSocket, acknowledged, run, and report a result. Offline devices get their jobs when they reconnect, until the job expires.

Packages and deployments​

A package describes software: an uploaded MSI or EXE, a PowerShell script, or a winget package ID, plus optional detection rules that tell whether it is installed. A deployment installs or uninstalls a package on a set of devices (targets), with a schedule, maintenance window, concurrency limit, retries and a reboot policy.

Global library​

Global admins can create global packages, scripts and alert rules. They are visible (read-only) and usable in every tenant. Tenants can switch individual global alert rules off.

Alerts​

An alert rule describes a condition (for example "disk free below 10 %"). The server evaluates every rule once a minute and opens, updates and resolves alerts by itself. Users acknowledge or resolve alerts and choose which ones they get by e-mail.

Audit log​

Every change made through the portal and every job created is written to the audit log with who, what, when, where from, and before and after values (secrets redacted).