The one-laptop checklist: a silent install through the firm's own management tool, the firm's VPN, endpoint security, filtering, and browsers, a reboot, and a clean removal at the end.
This page is Endpoint Protection's checklist. The one-laptop step of the Endpoint pilot is one Windows machine that IT controls, never an employee's. The agent goes on through the firm's own management tool, the checklist below runs against the firm's own VPN, endpoint security, filtering, and browsers, and the agent comes off. Nothing reaches an employee device before every line passes.
The window is three to five business days. The hands-on checks take under an hour; the rest is soak time, letting the device run under normal use so a slow conflict surfaces here rather than on the fleet.
Setup
Install exactly the way the rollout will: a device group containing the one test machine, the certificate profile, and the signed installer as a Required app, per MDM rollout. Deploying through the firm's real management tool matters; a hand-run installer would validate a different motion than the one employee machines will get.
The checklist
Work through it in order. Each line names what to confirm.
- The install ran silently. No prompt, no window, and no restart request reached the desktop, and the management tool shows the install succeeded.
- The service is up and the device reports in. The agent service is running, and the device appears in the firm's console reporting its capture mode.
- Certificate trust is in place. Capture is active. If the certificate has not landed, the agent stays in full passthrough and alerts the operator; that state is visible, never silent.
- The VPN connects and carries traffic as before. Connect, work, disconnect, reconnect.
- Endpoint security reports the device healthy. The agent's binaries are code signed, so protection that gates by publisher can pin trust to the signer. No alert, no quarantine, no performance complaint.
- Web filtering still decides. Test a category the firm blocks and confirm the filter still blocks it.
- Ordinary sites are untouched. Banking, sign-in pages, health portals, and general browsing behave exactly as before; destinations without AI evidence are never decrypted.
- An approved AI tool works. Open the firm's sanctioned AI tool, ask something real, and confirm the reply arrives normally and speed is acceptable on the firm's network.
- Redaction shows up on the record. Send a test prompt seeded with made-up identifiers and confirm the event appears in the console with the redacted version alongside. Redaction and tokenization describes what to expect. Never use real client data for this test.
- Known limits behave as documented. Certificate-pinned desktop apps pass through untouched by design. Check observed behavior against the stated limits, so a documented bypass is not recorded as a failure.
- A restart comes back clean. Reboot the machine and confirm the service returns, capture resumes, and nothing prompts.
- Removal restores the device. At the end of the window, remove the agent through the management tool per Rollback and uninstall and confirm proxy settings, certificate stores, and services return to their prior state, with nothing left behind.
What pass means
Every line confirmed on the firm's own stack, by the person who runs that stack. A line that fails is a finding: it is either resolved and re-run, or it is a documented reason to stop before any employee is touched. The fleet push does not start until this stage passes.