Skip to main content
A deployment connects one or more policy versions to a target set of enrolled machines.

Apply a deployment

  1. Go to Admin → enforcement, find the machine, and expand its row.
  2. Select edit, add the reviewed policy version, and choose observe or its enforcing effect.
  3. Apply the change, then wait for the machine’s next check-in and confirm its deployment and coverage state.
  4. Go to Observe → policy to inspect live decisions. The machine deployment editor with policy versions, enforce and observe effects, and the apply deployment action.
1

Choose the version and targets

Deploy a reviewed version, not a mutable draft, starting with a non-production machine or small cohort whose sessions you can inspect.
2

Observe decisions

Review matches, reasons, affected tools, and false positives without blocking work.
3

Enforce and verify coverage

Promote after observed matches separate unsafe actions from valid ones, then confirm every intended machine has pulled the deployment and is reporting decisions.
Machines need the policies:pull capability. Event reporting is separately controlled by events:add; verify both when you expect Cloud analysis and enforcement.
Enforcement management is an administrative Cloud workflow. Do not treat root-only enforcement routes as ordinary customer /v1 API endpoints.