Surfil
Surfil/Products/Fleet Control
// surfil fleet-control · enterprisepartly built

Device registry, shadow-agent discovery, instant revoke.

At scale, you don't know how many devices are running agents, whether any are running unsanctioned ones, or how to shut one off the moment it matters.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Fleet Control is partly built. Some of what follows ships on a linked device today and the rest does not. Your dashboard marks each capability, and nothing shows a number it has not measured.
What it does

Every device. One registry.

Fleet Control maintains a live registry of every enrolled device, surfaces agents running outside policy (shadow agents), and can revoke a device's access instantly.

Device registry - One list of every device with Surfil installed, and its current status.
Shadow-agent discovery - Surfaces agents operating outside declared policy so they can be reviewed, not just guessed at.
Instant revoke - Cut a device's access immediately - no waiting on the next check-in.
Fits the entitlement model - Revocation is enforced at the edge, the same layer that already gates entitlement.

Proof, not promises

Fleet Control produces one metric type on the shared spine: enrolled devices (and shadow agents found). Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.

$ surfil verify rcpt_8f2a
✓ VALID (offline · epoch 7)
In your dashboard

Fleet Control, as you'd actually see it

hub.surfil.com/fleet
ada-mbp-14enrolled · policy v3 · last seen 2m ago
ci-runner-06enrolled · policy v3 · last seen 41s ago
dev-nas-02shadow agent detected · unreviewed MCP server
lee-mbp-16revoked · access cut at edge
Illustrative fleet registry - enrollment, shadow discovery and revocation state.
How it works

How Fleet Control does it

1Devices enroll with Ed25519 device tokens via the standard device flow.
2The registry tracks each device's status, policy pack and last check-in.
3Shadow discovery flags agents and MCP servers running outside declared policy.
4Revocation is enforced at the edge - effective immediately, fail-closed.
5Everything the registry shows is metadata; device contents never leave devices.
Use cases

Where Fleet Control earns its place

Unknown agent sprawl

Find how many machines actually run agents, including the ones nobody declared.

Offboarding

Revoke a departing contractor's device access in one action, enforced at the edge.

Policy coverage

See which devices are running which policy pack, mapped before an audit asks.

FAQ

Questions developers ask first

What is a shadow agent?

An agent or MCP server running outside declared policy. Fleet Control surfaces it for review.

How fast is revoke?

Immediate - enforced at the edge layer that gates entitlement, not on the next check-in.

Does the registry see device contents?

No - enrollment status, policy version and check-in metadata only, never device contents.

Works well with

One spine - products compound

Add Fleet Control to your agents.

Core installs with Starter; Fleet Control plugs into the same interception point - no second layer, no new setup.