Overview
Getting started
Five steps take this console from empty to managing a real device. Leave at any point and pick up where you stopped — progress is read from the console, not from this browser.
Needs your approval
Open the queueRecent check-ins
Newest firstNo device has checked in yet. A device appears here the moment it first contacts this console.
Set up your console
Name your workspace
Step 1 of 5Your technicians see this name in the header, and it stands beside every action in the audit feed. A console still called default tells a customer that nobody has set it up yet.
Secure your account
Step 2 of 5A time-based one-time code on top of your password. Any RFC 6238 authenticator app works. The secret is shown once, while you enrol, and never again.
- 1 · Scan this code
-
2 · Or add the account by hand
-
3 · Confirm with a code
Confirming spends that code — RFC 6238 §5.2 lets a code be accepted only once, and this console enforces it. Your next sign-in needs the next code, not this one.
Mint your first deploy token
Step 3 of 5A deploy token binds a device to this workspace at install time. The device presents it once; every check-in after that resolves this workspace on its own.
Copy this token now
This will not be shown again. The console keeps only a hash of it, so nobody — including this console — can retrieve it later. If you lose it, mint another and revoke this one.
Install the TZX Desk client on the machine you want to manage, then run it once with the token below. This console does not host the installer — it is the client build you already ship to your technicians.
A device that enrols this way lands in Devices as waiting for approval until you approve it — unless you ticked auto-approve below.
Install on a device
Step 4 of 5Run the client with your deploy token on one machine. It appears here within a few seconds of its first check-in. This list refreshes on its own while you are on this step.
Optional finishing touches
Step 5 of 5Neither of these is needed to run the console. Both are what a second week of using it usually asks for.
Devices
Enrol a device| State | Device | Platform | Group | Tags | Last seen | First seen | Strategy | Actions |
|---|
jk move enter open x select a approve r revoke g group / search esc close
Groups
A group is the customer a device belongs to. The desktop client lists one shared address book per group, so a device moved here shows up under that customer on every technician's home.
| Name | Devices | Actions |
|---|
A group can be deleted only when it holds no devices and no usable deploy token still targets it. Move the devices from the Devices screen; revoke the token from Deploy tokens.
Create a group
Waiting for approval
Nothing connects until you approve it: the signalling server asks this console on every pairing. Approve a device to let it in; deny it to keep it out until you decide otherwise.
jk move a approve r deny enter open in Devices
Deploy tokens
Copy this token now
This will not be shown again. The console keeps only a hash of it, so nobody — including this console — can retrieve it later. If you lose it, mint another and revoke this one.
| Name | Uses | State | Actions |
|---|
A deploy token binds a device to this workspace at install time. Only its hash is stored; the listing shows a non-secret prefix so support can tell tokens apart.
Mint a token
Strategies
| Name | Settings | Actions |
|---|
A device uses its own assigned strategy, else this workspace's default, else none. Settings reach a device on its next heartbeat.
New strategy
Assign to devices
Users
| Username | Role | MFA |
|---|
No users to show.
Owner and admin may administer this console; technician and viewer may not. Only an owner can create another owner.
Add a user
Tenants
Each tenant is a separate customer: its own devices, users, tokens and audit feed. Your session is scoped to one of them; sign in as a tenant's owner to work inside it.
| Name | Anonymous inbound | Actions |
|---|
Create a tenant
Settings
Two-factor authentication
A time-based one-time code on top of your password. Any RFC 6238 authenticator app works. The secret is shown once, while you enrol, and never again.
- 1 · Scan this code
-
2 · Or add the account by hand
-
3 · Confirm with a code
Confirming spends that code — RFC 6238 §5.2 lets a code be accepted only once, and this console enforces it. Your next sign-in needs the next code, not this one.
This session
- Signed in as
- Role
- Workspace
- Console
The session token lives in this browser tab only and ends when the tab closes. Signing out ends it on the server too.
Appearance
Dark is the default. Light is a designed palette, not an inversion. Your choice is kept in this browser.
Keyboard
- /
- Focus search from anywhere
- j k
- Move down and up a list
- enter
- Open the highlighted device
- x
- Select the highlighted device
- a
- Approve the highlighted device
- r
- Revoke it, after a confirmation
- esc
- Close the pane, the menu, or clear a selection
Audit
Nothing recorded yet. Approvals, connection sessions and file transfers appear here as they happen.
The feed shows the newest 500 events across console actions, sessions and file transfers. Filters apply to what is loaded.