Optional managed Guardian module

Protect every managed endpoint and keep it patched.

Guardian Endpoint Protection combines centrally managed endpoint security with Damocles-managed operating-system and supported application patching across the agreed device scope.

Endpoint security managementManaged patch deploymentRestart and exception follow-upParticipant, business and provider visibility
What the service includes

Endpoint protection is delivered as an ongoing managed service—not just a software licence.

For every endpoint covered by the module, Damocles manages the protection configuration, device onboarding, security posture and patching workflow within the agreed supported scope.

Managed patching is included with the Guardian Endpoint Protection module. It is not presented as a separate surprise service for the same protected devices.

01

Protect

Deploy and manage the endpoint security agent, protection policy and device onboarding state.

02

Patch

Plan and deploy operating-system and supported third-party application patches across the agreed endpoint estate.

03

Verify

Track patch outcome, restart requirements, failures, exceptions and unresolved exposure through Guardian.

Operational inclusions

What Damocles manages for covered endpoints.

The service joins endpoint security, vulnerability context, patch execution and accountable follow-up instead of leaving the customer with disconnected consoles and patch lists.

ON

Onboarding and deployment

Controlled installer and entitlement workflow, device onboarding, ownership mapping and protection-state confirmation.

PP

Protection policy

Centrally managed endpoint protection policy, health status and security-event visibility for the agreed device scope.

VM

Vulnerability visibility

Device-level vulnerability and remediation context, including active, resolved and restart-required states where supported.

OS

Operating-system patching

Managed operating-system patch deployment through agreed maintenance windows and operating rules.

AP

Supported application patching

Managed patching for supported third-party applications where the selected protection and patching platform provides coverage.

RW

Restart coordination

Visibility and follow-up for patches that require a restart, including outstanding restart and completion state.

EX

Exceptions and failures

Failed patches, exclusions, unsupported software and devices needing intervention are identified and tracked rather than silently ignored.

AC

Actions and remediation

Material endpoint issues can be linked to Guardian risks, owners, due dates and All Actions follow-up.

RP

Reporting

Protection coverage, vulnerability posture, patch status and remediation progress are presented through customer-safe Guardian records.

Managed endpoint lifecycle

From device onboarding to verified patch outcome.

The exact cadence and maintenance windows are agreed for the customer or provider estate.

01

Authorise

Confirm the tenant, device entitlement, ownership and approved scope.

02

Onboard

Deploy the endpoint agent and confirm the device is reporting and protected.

03

Assess

Review device health, vulnerabilities, available patches and security findings.

04

Schedule

Apply agreed maintenance windows, exclusions and change requirements.

05

Deploy

Roll out approved operating-system and supported application patches.

06

Verify

Confirm success, track restarts or failures, and retain evidence and follow-up actions.

Participant, business and provider delivery

The same managed service supports individual participants and multi-customer providers.

Participants can see their linked devices, endpoint protection state, priority vulnerabilities and remediation guidance without gaining visibility of unrelated devices.

Business customers receive an estate view of covered devices, protection status, vulnerability and patch posture, unresolved issues and remediation progress.

Providers can operate across their own devices and authorised child customers using provider-scoped entitlements, installer controls, device mappings, posture views and customer-safe reporting.

Commercial quantity is normally based on the number of protected endpoints. Exact included devices, operating systems, supported applications, patch windows and service responsibilities are recorded in the package schedule.

Service boundary

Managed patching applies to the agreed supported scope.

The service covers authorised devices and software supported by the selected endpoint and patching platform. Unsupported, end-of-life, isolated or specialist systems are identified and handled through an agreed exception or separately scoped remediation plan.

Emergency out-of-band change, major application upgrades, bespoke line-of-business software and remediation requiring engineering work may require separate approval. The website does not promise universal compatibility, zero vulnerabilities or patch success on every device.

Guardian records and reports the operational state; Damocles performs the managed service. The platform does not imply unsupervised patching outside the agreed policy and maintenance windows.

Managed device security

Confirm the endpoint count, supported scope and maintenance model.

We will define the covered estate, protection policy, patching scope, maintenance windows, exception handling and reporting before activation.

Guardian Endpoint Protection and Managed Patching | Damocles Security