Overview
The devices module provides a centralized inventory of all employee devices with real-time compliance monitoring powered by the LowerPlane Desktop Agent. The agent automatically reports encryption status, antivirus coverage, firewall settings, screen lock configuration, OS updates, and MDM enrollment — eliminating manual device audits.Device Coverage
The dashboard shows a Device Coverage metric comparing the number of active employees who have the agent installed versus total active employees. Aim for 100% coverage to ensure full endpoint compliance visibility.Device coverage is calculated as: (unique employees with agent-reported devices / total active employees) × 100%
How Devices Are Registered
Devices are registered automatically when an employee installs and signs into the LowerPlane Desktop Agent. No manual device entry is needed.Employee Installs Agent
The employee downloads the Desktop Agent from the Employee Portal (Devices > Download Agent) and installs it on their work device.
Employee Signs In
The employee signs in with their company email. The agent links the device to their LowerPlane account.
Agent Reports Automatically
The agent runs security checks and reports results to the dashboard. The device appears in the admin’s device inventory automatically.
Compliance Monitoring
The agent performs the following security checks on each device:Required Security Controls
| Check | What It Verifies | Severity |
|---|---|---|
| Disk Encryption | Full-disk encryption is enabled (FileVault, BitLocker, LUKS) | High |
| OS Up to Date | Operating system has the latest updates installed | High |
| Antivirus | Endpoint protection software is installed and running | High |
| Firewall | System firewall is enabled and active | High |
| Screen Lock | Auto-lock is configured with password/PIN required on unlock | High |
Recommended Controls
| Check | What It Verifies | Severity |
|---|---|---|
| MDM Enrolled | Device is enrolled in Mobile Device Management | Low |
| Password Manager | A password manager application is installed | Low |
Recommended controls don’t affect overall compliance status but are tracked for security posture visibility.
Compliance Status
Based on the required checks, each device receives an overall status:| Status | Meaning |
|---|---|
| Compliant | All required security checks pass |
| Mostly Compliant | All but one required check passes |
| Non-Compliant | Two or more required checks fail |
Security Controls Coverage
The admin dashboard shows aggregate coverage for each security control across all devices:- Encryption — X of Y devices encrypted
- Antivirus — X of Y devices with antivirus
- Firewall — X of Y devices with firewall enabled
- Screen Lock — X of Y devices with screen lock configured
- MDM Enrolled — X of Y devices enrolled in MDM
Device Properties
Each agent-reported device includes:| Field | Description | Source |
|---|---|---|
| Device Name | Computer hostname | Agent |
| Device Type | Laptop or Desktop | Agent |
| Manufacturer | Device manufacturer (Apple, Dell, Lenovo, etc.) | Agent |
| Model | Specific model name or number | Agent |
| Serial Number | Unique hardware serial number | Agent |
| Machine ID | System-assigned unique identifier | Agent |
| OS Name | macOS, Windows, or Linux | Agent |
| OS Version | Operating system version number | Agent |
| Assigned To | The employee who signed in on the agent | Agent |
| Last Check-In | Most recent agent sync timestamp | Agent |
| Compliance Status | Overall compliance based on security checks | Calculated |
Device Statuses
| Status | Description |
|---|---|
| Assigned | Device is actively assigned to an employee (agent installed and signed in) |
| Unassigned | Device is in inventory but not linked to an employee |
| Lost | Device has been reported lost |
| Stolen | Device has been reported stolen |
| Retired | Device has been decommissioned |
Admin Actions
Sync Devices
- Sync All — Refresh all device data from connected MDM integrations (Jamf, Intune, Kandji, etc.)
- Agent-reported devices sync automatically — no manual sync needed
Edit Device
Admins can update device metadata and security check values manually if needed (e.g., to correct a check that the agent couldn’t detect).Export
Export the full device inventory to CSV for reporting, asset management, or audit evidence.Retire / Delete
Mark devices as retired when decommissioned, or delete device records that are no longer needed.MDM Integration
If your organization uses an MDM solution connected through LowerPlane integrations, device data from both the Desktop Agent and MDM are merged:| Data Source | What It Provides |
|---|---|
| Desktop Agent | Real-time security checks (encryption, firewall, screen lock, antivirus, OS updates) |
| MDM Integration | Device inventory, configuration profiles, app management, remote wipe capability |
Compliance Mapping
Device management supports endpoint security controls across frameworks:| Framework | Control | Requirement |
|---|---|---|
| ISO 27001 | A.8.1 | Asset inventory and ownership |
| ISO 27001 | A.11.2 | Equipment security |
| SOC 2 | CC6.7 | Restrict transmission and movement of information |
| SOC 2 | CC6.8 | Prevention of unauthorized software |
| HIPAA | 164.310(b) | Workstation use |
| HIPAA | 164.310(d)(1) | Device and media controls |
| PCI-DSS | 5.1 | Anti-virus software on all systems |
Best Practices
- Deploy the Desktop Agent to all employees — aim for 100% device coverage
- Require full-disk encryption on all devices — this is a baseline control for every compliance framework
- Set auto-lock timers with password required — the agent checks both timeout and authentication
- Monitor check-in freshness — devices that haven’t checked in recently may need attention
- Enroll devices in MDM for remote management and enforcement capabilities
- Review non-compliant devices weekly and follow up within 7 days
- Wipe devices before reassignment to prevent data leakage between employees