Fleet coverage answers whether a policy exists where the risk exists. Track machines by stable ID and a human-readable label, then compare their assigned and reported deployment state.
Check coverage
-
Go to Admin → enforcement and review the enforcing and observing totals.
-
Search for a machine by ID or label, or filter for machines missing a policy.
-
Expand a row to compare assigned policies, reported deployment, last check-in, and history.
-
Refresh after the machine’s polling interval when an applied deployment remains pending.
Use fp events --agent-id <agent-id> --since 24h to confirm the machine’s agent activity reaches Cloud.
Use coverage views to find:
- Machines that never pulled the latest deployment
- Enrolled machines that stopped reporting activity
- A policy assigned to the wrong environment or cohort
- Version drift after an interrupted update
Rename a machine without reconnecting it:
Check local state:
Use labels that identify workload and environment. Hostnames alone are often insufficient after autoscaling or machine replacement.