Proxaradocs
Guides/Endpoint Protection

Endpoint quickstart

The device path: a short route from a signed agent to live coverage across a managed fleet.

Updated July 2026

The shortest real path from a signed installer to live device coverage. This is Endpoint Protection's quickstart, the device product; for the hosted connector with nothing to install, start at the Connect quickstart. A fleet rollout is three steps: push the agent, push the trust profile, watch devices appear in the console. Nothing on this page requires an employee to do anything.

Before you start

Onboarding provisions two things for the firm: a dedicated single-tenant stack in its own AWS account, and the signed agent installers with a per-tenant enrollment key. The on-premise and private deployment guide covers what is inside that stack. For an individual evaluation on one machine, the trial demo is the faster route; this page is the fleet path. An Endpoint pilot follows the same path at a smaller scale: after the review meeting, one approved test laptop first, then a small pilot group for twenty-one days measured from activation, and a decision in writing at the end.

Step 1: push the agent

Deploy the signed package for each platform, a notarized .pkg on macOS and a signed .msi on Windows, through the MDM the firm already runs (Jamf, Intune, Kandji, Mosyle, Workspace ONE, JumpCloud). The package carries the agent and the companion app in one bundle. The MDM rollout guide has the per-MDM specifics.

ProxaraAgent.pkg
Signed and notarized
Certificate trust profile
com.apple.security.root
The fleet
MacBook Pro · 14F2INSPECTING
MacBook Air · 09C7INSPECTING
Mac mini · 22A1INSPECTING
The two pushes, then the fleet activates itself

Step 2: push the trust profile

Alongside the package, push the per-tenant certificate profile (com.apple.security.root on macOS, a Trusted Certificate profile in Intune on Windows). This is what lets the agent inspect AI traffic. It is the same mechanism enterprise TLS-inspection products use, and it is the one step that cannot be skipped: without the trusted certificate the agent stays in passthrough and inspects nothing. It never breaks a site either way.

Step 3: nothing

The agent activates itself at first boot. It registers the device against the firm's stack with the enrollment key, mints its own signing keys, configures the system proxy, and begins inspecting AI traffic. There is no first-run wizard and no employee prompt in the MDM path.

Confirm coverage

Open the console. The Overview page has two views: Flow shows employees and the AI providers they reached, and Servers shows which AI surfaces are covered. A newly enrolled device appears as soon as it sees its first AI traffic. The chain pill in the corner confirms the signed record is intact and growing.

Overview
Intelligence
Threat Coverage
Compliance
MCP Tools
Activity
OverviewFlowServers
EMPLOYEESAI PROVIDERSACAvery ChenChatGPTClaudeGemini
Inspected
24
Redacted
9
Flagged
2
Chain intact
The Overview a finished rollout lands on

Where to go next

To understandRead
What the agent inspects and what it never touchesThe device proxy
What happens to a sensitive promptRedaction and tokenization
How AI agents and their tools are governedAgent governance
Where alerts actually arrive day to daySlack and Teams
How to prove it out on one machine firstSingle-device validation
The exact hosts the agent talks toNetwork endpoints
How to take it all back outRollback and uninstall