Device registry, shadow-agent discovery, instant revoke.
At scale, you don't know how many devices are running agents, whether any are running unsanctioned ones, or how to shut one off the moment it matters.
Every device. One registry.
Fleet Control maintains a live registry of every enrolled device, surfaces agents running outside policy (shadow agents), and can revoke a device's access instantly.
Proof, not promises
Fleet Control produces one metric type on the shared spine: enrolled devices (and shadow agents found). Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.
✓ VALID (offline · epoch 7)
Fleet Control, as you'd actually see it
How Fleet Control does it
Where Fleet Control earns its place
Unknown agent sprawl
Find how many machines actually run agents, including the ones nobody declared.
Offboarding
Revoke a departing contractor's device access in one action, enforced at the edge.
Policy coverage
See which devices are running which policy pack, mapped before an audit asks.
Questions developers ask first
What is a shadow agent?
An agent or MCP server running outside declared policy. Fleet Control surfaces it for review.
How fast is revoke?
Immediate - enforced at the edge layer that gates entitlement, not on the next check-in.
Does the registry see device contents?
No - enrollment status, policy version and check-in metadata only, never device contents.
One spine - products compound
Add Fleet Control to your agents.
Core installs with Starter; Fleet Control plugs into the same interception point - no second layer, no new setup.