Skip to main content

Backend connectivity

The Endpoint Agent talks to the QuilrAI backend over outbound HTTPS only. It pushes what it discovers, pulls governance decisions, and reports enforcement activity.

Configure
Tenant ID at install
Backend found by lookup
Push discovery
Startup + every 30 min
Batches of 50, gzip
Pull governance
Delta sync every 60 s
No restart needed
Report activity
Audit log per decision
Block / quarantine alerts
QuilrAI

Connection settings​

You do not edit a configuration file. At install time the agent is bound to your tenant ID (see Deployment and status) and looks up its tenant's backend and DLP hosts. Every request carries your tenant identity, which the backend uses to keep tenants isolated.

What is exchanged​

DirectionEndpointDataWhen
Agent to backendPOST /ea/v1/sync/discovered-appsDiscovered apps and AI entities, including device ID, user, OS, and identity. Returns 202 Accepted.At startup and every 30 minutes; batches of up to 50, gzip-compressed, retried on failure
Agent to backendPOST /ea/v1/sync/unknown-processesProcesses the agent could not map, for the backend to identifyAs found
Backend to agentGET /ea/v1/sync/deltaGovernance overrides: approval status, execution policy, criticalityDelta sync every 60 seconds
Backend to agentGET /ea/v1/sync/process-mapProcess-name to application mappingsUsed by the correlator
Agent to backendPOST /ea/v1/sync/activityEnforcement audit record per decisionImmediately
Agent to backendPOST /ea/v1/sync/alertsBlock and quarantine alertsImmediately

Policy changes you make in the console reach the agent on the next delta sync and apply without a restart.

Verify the connection​

  1. Discovered apps appear in Inventory within the first discovery cycle.
  2. The device appears in Users › Endpoint deployment with a recent Last registered time (the last time the agent checked in). See Deployment and status.
  3. After you change an app policy, the agent applies it within about a minute.

Offline behavior​

FeatureBehavior
Alert bufferingCritical alerts are queued in a local database while the backend is unreachable and sent when connectivity returns. Non-critical activity logs are not buffered.
Idempotent uploadsDiscovery batches can be retried safely.
Sync cursorThe last delta position is saved to disk before overrides are applied, so a restart resumes safely.
Inventory snapshotDiscovered entities are snapshotted to disk and reloaded at startup.

Network requirements are listed in Requirements.