Overview

The devices module provides a centralized inventory of all employee devices with real-time compliance monitoring powered by the LowerPlane Desktop Agent. The agent automatically reports encryption status, antivirus coverage, firewall settings, screen lock configuration, OS updates, and MDM enrollment — eliminating manual device audits.

Device Coverage

The dashboard shows a Device Coverage metric comparing the number of active employees who have the agent installed versus total active employees. Aim for 100% coverage to ensure full endpoint compliance visibility.
Device coverage is calculated as: (unique employees with agent-reported devices / total active employees) × 100%

How Devices Are Registered

Devices are registered automatically when an employee installs and signs into the LowerPlane Desktop Agent. No manual device entry is needed.
1

Employee Installs Agent

The employee downloads the Desktop Agent from the Employee Portal (Devices > Download Agent) and installs it on their work device.
2

Employee Signs In

The employee signs in with their company email. The agent links the device to their LowerPlane account.
3

Agent Reports Automatically

The agent runs security checks and reports results to the dashboard. The device appears in the admin’s device inventory automatically.
4

Continuous Monitoring

The agent syncs periodically, keeping compliance status up to date without any manual action.
For detailed installation instructions for each platform (macOS, Windows, Linux), see the Desktop Agent page.

Compliance Monitoring

The agent performs the following security checks on each device:

Required Security Controls

CheckWhat It VerifiesSeverity
Disk EncryptionFull-disk encryption is enabled (FileVault, BitLocker, LUKS)High
OS Up to DateOperating system has the latest updates installedHigh
AntivirusEndpoint protection software is installed and runningHigh
FirewallSystem firewall is enabled and activeHigh
Screen LockAuto-lock is configured with password/PIN required on unlockHigh
CheckWhat It VerifiesSeverity
MDM EnrolledDevice is enrolled in Mobile Device ManagementLow
Password ManagerA password manager application is installedLow
Recommended controls don’t affect overall compliance status but are tracked for security posture visibility.

Compliance Status

Based on the required checks, each device receives an overall status:
StatusMeaning
CompliantAll required security checks pass
Mostly CompliantAll but one required check passes
Non-CompliantTwo or more required checks fail

Security Controls Coverage

The admin dashboard shows aggregate coverage for each security control across all devices:
  • Encryption — X of Y devices encrypted
  • Antivirus — X of Y devices with antivirus
  • Firewall — X of Y devices with firewall enabled
  • Screen Lock — X of Y devices with screen lock configured
  • MDM Enrolled — X of Y devices enrolled in MDM
These metrics feed into your compliance scoring and evidence collection for frameworks like ISO 27001, SOC 2, HIPAA, and PCI-DSS.

Device Properties

Each agent-reported device includes:
FieldDescriptionSource
Device NameComputer hostnameAgent
Device TypeLaptop or DesktopAgent
ManufacturerDevice manufacturer (Apple, Dell, Lenovo, etc.)Agent
ModelSpecific model name or numberAgent
Serial NumberUnique hardware serial numberAgent
Machine IDSystem-assigned unique identifierAgent
OS NamemacOS, Windows, or LinuxAgent
OS VersionOperating system version numberAgent
Assigned ToThe employee who signed in on the agentAgent
Last Check-InMost recent agent sync timestampAgent
Compliance StatusOverall compliance based on security checksCalculated

Device Statuses

StatusDescription
AssignedDevice is actively assigned to an employee (agent installed and signed in)
UnassignedDevice is in inventory but not linked to an employee
LostDevice has been reported lost
StolenDevice has been reported stolen
RetiredDevice has been decommissioned
Lost or stolen devices containing company data must be reported immediately. If the device is encrypted and MDM-enrolled, a remote wipe can be initiated through your MDM provider.

Admin Actions

Sync Devices

  • Sync All — Refresh all device data from connected MDM integrations (Jamf, Intune, Kandji, etc.)
  • Agent-reported devices sync automatically — no manual sync needed

Edit Device

Admins can update device metadata and security check values manually if needed (e.g., to correct a check that the agent couldn’t detect).

Export

Export the full device inventory to CSV for reporting, asset management, or audit evidence.

Retire / Delete

Mark devices as retired when decommissioned, or delete device records that are no longer needed.

MDM Integration

If your organization uses an MDM solution connected through LowerPlane integrations, device data from both the Desktop Agent and MDM are merged:
Data SourceWhat It Provides
Desktop AgentReal-time security checks (encryption, firewall, screen lock, antivirus, OS updates)
MDM IntegrationDevice inventory, configuration profiles, app management, remote wipe capability
Both sources contribute to the device’s compliance status. The agent provides the security check results; MDM provides management and enforcement.

Compliance Mapping

Device management supports endpoint security controls across frameworks:
FrameworkControlRequirement
ISO 27001A.8.1Asset inventory and ownership
ISO 27001A.11.2Equipment security
SOC 2CC6.7Restrict transmission and movement of information
SOC 2CC6.8Prevention of unauthorized software
HIPAA164.310(b)Workstation use
HIPAA164.310(d)(1)Device and media controls
PCI-DSS5.1Anti-virus software on all systems

Best Practices

  • Deploy the Desktop Agent to all employees — aim for 100% device coverage
  • Require full-disk encryption on all devices — this is a baseline control for every compliance framework
  • Set auto-lock timers with password required — the agent checks both timeout and authentication
  • Monitor check-in freshness — devices that haven’t checked in recently may need attention
  • Enroll devices in MDM for remote management and enforcement capabilities
  • Review non-compliant devices weekly and follow up within 7 days
  • Wipe devices before reassignment to prevent data leakage between employees