Deployment and status
Roll the Endpoint Agent out to your fleet, then use the console to track coverage and switch individual workstations on or off.
What you receive
Your QuilrAI representative supplies the agent packages (MSI, PKG, macOS configuration profiles and certificates) with your tenant ID. Step-by-step installation guides are at installdocs.quilrai.dev.
The Endpoint Agent package is separate from the Browser Extension's native Browser Agent. Do not reuse the Browser Agent install commands from the Browser Extension deployment pages.
Before you start, check OS versions, network destinations and platform approvals in Requirements.
Bind the agent to your tenant
The installer needs your tenant ID. It uses it to look up your tenant's backend and DLP hosts. Supply it in one of these ways:
Windows recipe
-
Deploy the MSI as a line-of-business or Win32 app (Intune), or with your software distribution tool, in system context:
msiexec /i quilrai-endpoint-agent.msi /qn /l*v C:\Windows\Temp\quilrai-install.log TENANTID=<your-tenant-id> -
The install fails with exit code
1603if the tenant's backend cannot be resolved, for example because the tenant ID is wrong or the QuilrAI discovery host is blocked (see Requirements). Details are in the log file. -
Detection rule: the file
%ProgramFiles%\QuilrAI\quilrai.exeexists, or the MSI product code. -
Uninstall:
msiexec /x <ProductCode> /qn, or assign the app for uninstall in your management tool.
macOS recipe
-
Deploy the configuration profiles first: the system extension profile, the Full Disk Access profile, and a certificate payload with the QuilrAI root and intermediate CA certificates.
-
Wait until devices report the profiles as installed.
-
If you use the universal package, deploy a pre-install script that writes your tenant ID to
/Library/Application Support/QuilrAI/tenant_id. -
Deploy the
.pkg. It installs as root and needs no user interaction when the profiles are in place. -
Detection rule:
/Applications/QuilrAIProxy.appand/Library/LaunchDaemons/com.quilrai.agent.plistexist, or the package receiptai.quilr.agent.endpoint.installer. -
Uninstall:
sudo "/Library/Application Support/QuilrAI/quilrai-endpoint-uninstaller" --force
After the first install, the agent keeps itself up to date. See Requirements.
Pilot first
Deploy to a small group first, confirm the checks in Confirm a healthy rollout, then widen the assignment.
Watch coverage
The table lists each Workstation, User, Operating system, Agent version, Status, and Last registered time (the last time the agent checked in). Use Search and the status and version filters to find a device.
Reconcile assigned and reporting devices
The Workstations count shows devices whose agent has checked in, not devices you assigned the package to. To find gaps:
- Export the device names in your MDM assignment group, with each device's install status and last check-in time.
- Search for those names in Users › Endpoint deployment.
- Sort the gaps:
A running agent checks in with QuilrAI about every 2 minutes.
Enable or disable workstations
Select one or more workstations and use the bulk Enable or Disable action. The action applies to every session on the workstation; a workstation whose sessions differ shows as Mixed sessions.
To turn the agent off for the whole tenant instead, use Enable or Disable in Agent settings. For incident handling, timing and recovery, see Agent kill switch.
Confirm a healthy rollout
For one person's devices and sensor status, open their profile in Users and go to Deployment & devices.