Optional managed protection product

Protect endpoints, keep supported software patched and make exceptions visible.

Guardian Endpoint Protection and Managed Patching combines compatible endpoint-security technology with Damocles policy, health, patch, restart, exception and remediation operations.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Vendor-neutral endpoint modelManaged protection policyOS and supported application patchingHealth, restart and exception follow-up
Buyer decision summary

Know what Guardian Endpoint Protection and Managed Patching does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains supported device identifiers, customer mapping, health state, patch state, restart condition, action history, exception records and approved evidence. Installer secrets, platform credentials and raw upstream payloads remain restricted.

The proposal identifies protected endpoint quantity, supported operating systems, application list, policy, maintenance windows, restart handling, support, exclusions, reporting and the selected connector or licence.

The product does not imply support for every operating system, application, device type, network condition or patch, and it does not guarantee that every attack will be prevented or every update will install without impact.

01

What the product does

Supported operating systems, applications and platform fields are confirmed in the package schedule.

02

What the customer sees

Participant, business and provider views remain role and relationship scoped.

03

What Damocles manages

Managed patching is included for covered devices and supported software within the contracted scope.

The operational problem

Endpoint security fails when protection agents, patch state and operational exceptions are managed as separate problems.

A device can appear protected while its agent is unhealthy, its operating system is missing critical updates, a supported application remains exposed, a patch is waiting for restart or an exception has no owner and review date.

Guardian combines supported protection and patch information into one customer and provider workflow. Damocles operates the agreed policy, deployment, patch windows, failure follow-up and evidence. The selected endpoint technology remains an implementation detail named in the commercial schedule.

01

Know which devices are not healthy

Identify missing, stale, degraded, unprotected and unsupported endpoint states across the agreed estate.

02

Move patches through completion

Track available, approved, deployed, failed, restart-required, deferred and exception states.

03

Make operational exceptions accountable

Record ownership, reason, compensating controls, expiry and evidence for devices or software outside normal policy.

Product capability

Protection and patch operations for the agreed endpoint scope.

Supported operating systems, applications and platform fields are confirmed in the package schedule.

AG

Agent onboarding

Deploy or map the compatible endpoint agent and confirm customer, device and policy ownership.

PH

Protection health

Track agent status, policy, last-seen state, protection condition and supported remediation context.

OS

Operating-system patching

Approve and deploy supported operating-system updates through agreed rings and maintenance windows.

AP

Application patching

Deploy supported third-party application updates included in the agreed software scope.

RS

Restart coordination

Identify pending restart state, communicate the requirement and track completion where supported.

EX

Failure and exception handling

Review installation failure, unsupported software, device-offline, deferral and approved exception conditions.

What the customer sees

Customers see device posture and required action without working inside the endpoint platform.

Participant, business and provider views remain role and relationship scoped.

DV

Device inventory

Approved devices, operating system, last-seen state, protection health and customer ownership.

PP

Protection posture

Protected, degraded, stale, missing and unsupported conditions with practical next steps.

PS

Patch state

Available, scheduled, installed, failed, deferred and restart-required states where supported.

RA

Remediation actions

Owner-ready work for offline devices, failed patches, restarts, unsupported software and policy exceptions.

EV

Evidence and history

Deployment, status, exception, action and review records supporting the customer outcome.

RP

Customer reporting

Estate-level protection, patch, exception and remediation summaries through Guardian.

What Damocles manages

Damocles operates the agreed endpoint policy and patch lifecycle.

Managed patching is included for covered devices and supported software within the contracted scope.

ON

Onboarding and deployment

Prepare installers, map devices, apply policy and confirm health and customer ownership.

PO

Policy operation

Maintain approved protection, scan, isolation, exclusion and update policy according to the service design.

PW

Patch windows and rings

Operate agreed maintenance windows, staged deployment rings, approval timing and restart rules.

FF

Failure follow-up

Investigate supported patch failures, stale agents, offline devices, policy conflicts and installation conditions.

EX

Exception governance

Record unsupported systems, business deferrals, compensating controls, owners and review dates.

SR

Service review and reporting

Review coverage, health, patch success, failures, restarts, exceptions and unresolved customer actions.

Operating lifecycle

From device enrolment to protected and reviewable patch state.

The operating model balances security, application compatibility, business windows and required restart behaviour.

01

Define scope

Confirm devices, operating systems, supported applications, ownership, maintenance windows and exclusions.

02

Onboard

Deploy or map the agent, apply policy and validate customer and device health.

03

Assess

Identify protection gaps, available updates, vulnerable software, restart and exception conditions.

04

Approve and deploy

Use agreed rings and windows to deploy supported operating-system and application updates.

05

Follow up

Investigate failures, offline devices, restarts, unsupported software and customer deferrals.

06

Evidence and report

Retain status, actions, exceptions and service reporting through Guardian.

Common use cases

Common endpoint-protection and patching use cases.

The product can support direct customers, NDIS providers and MSP-managed estates with different responsibility models.

SB

Small-business endpoint estate

Give a small IT team one managed service for protection, patching, restart and exception follow-up.

ND

NDIS provider staff devices

Protect the agreed provider-owned staff estate while keeping free participant accounts separate from managed endpoint licensing.

MS

MSP customer fleet

Use provider-scoped installers, device mapping, health, actions and consolidated wholesale billing.

HY

Mixed operating systems

Apply supported policy and patch scope across a defined mix of compatible desktop and server systems.

AP

Application patch governance

Track which supported applications are covered, current, failed, excluded or outside the managed scope.

EX

Legacy-system exceptions

Keep unsupported or deferred systems visible with owner, risk, compensating controls and review dates.

Operating model

How Guardian Endpoint Protection and Managed Patching is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding begins with a clean device inventory and an explicit supported-software schedule. Damocles confirms device ownership, operating systems, critical applications, existing endpoint tools, administrator access, network paths, maintenance windows, restart requirements, remote-worker conditions and customer contacts. The package schedule identifies which software and systems are covered. A pilot group validates agent deployment, policy, application compatibility, update behaviour, restart communication, exclusion handling and Guardian mapping before broader rollout. Existing security agents are reviewed for coexistence or migration requirements. Go-live includes health baselines, deployment waves, user communication, exception handling, support paths, reporting and a documented process for lost, retired, rebuilt or transferred devices.

IN

Connector and integration model

Guardian separates the endpoint product from the selected compatible protection technology. A supported connector must provide stable device identity, customer ownership, agent and protection health, operating-system and application context, patch or update state, timestamps and safe error information. The connector may be commercial, customer-owned or Damocles-provided. The proposal identifies the selected implementation, supported fields, operating systems, application catalogue and migration requirements. This avoids presenting one endpoint vendor as the Guardian product and allows future supported connectors to use the same customer experience. Connector changes require review of device identifiers, policy mapping, installer lifecycle, source health, historical continuity, update semantics and customer migration before activation.

EV

Data, evidence and reporting

Device, patch and exception records support operational review without exposing platform secrets. Guardian retains supported device identifiers, customer mapping, health state, patch state, restart condition, action history, exception records and approved evidence. Installer secrets, platform credentials and raw upstream payloads remain restricted. Patch reporting distinguishes deployment from completion. An update awaiting restart, a stale device or a failed installation is not represented as a completed remediation outcome. Historical reports use retained Guardian and source records. A device that disappears from the source is reviewed as retired, removed, stale or unmapped rather than silently treated as compliant.

CM

Commercial unit and responsibilities

Commercial scope is normally based on protected endpoints plus the agreed managed-service boundary. The proposal identifies protected endpoint quantity, supported operating systems, application list, policy, maintenance windows, restart handling, support, exclusions, reporting and the selected connector or licence. Major operating-system upgrades, unsupported or end-of-life software, bespoke packaging, emergency out-of-band change, application remediation and engineering beyond standard patch operation may require separate approval. The customer provides device access, ownership, maintenance authority and timely user or business decisions. Damocles provides the managed activities listed in the service schedule and records issues requiring customer action.

Frequently asked questions

Questions buyers ask about Guardian Endpoint Protection and Managed Patching.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can Guardian use our existing endpoint platform?

Yes where a supported connector exists and it provides the health, device, policy and update information required for the service.

Q2

Are third-party applications patched?

Supported applications listed in the package schedule are included. Unsupported, custom and end-of-life software remain outside scope unless separately approved.

Q3

What happens when a restart is required?

Guardian and the managed process identify the condition, communicate the requirement and track the device until completion or approved deferral.

Q4

Can Damocles isolate a device?

Only where the selected platform, policy and service authority allow it. Emergency containment authority is defined before activation.

Q5

Are participant-owned devices included?

Not in Participant Free. Managed endpoint coverage applies only to explicitly licensed and authorised devices.

Q6

What happens to unsupported systems?

They remain visible as unsupported or exception records with owner, risk, compensating controls and a review plan.

Scope and boundaries

Protection and patch coverage follow the licensed device, supported platform and approved managed-service scope.

The product does not imply support for every operating system, application, device type, network condition or patch, and it does not guarantee that every attack will be prevented or every update will install without impact.

Emergency change, unsupported software, major upgrades, complex remediation, lost-device response and incident containment are included only where expressly authorised and contracted.

Endpoint information remains customer and role scoped. Installer credentials, security policy secrets and raw platform payloads are not exposed in public or customer-safe views.

Take the next practical step

Review the devices, applications and patch responsibilities that are currently falling between teams.

We will map the estate, existing technology, supported systems, application scope, maintenance windows, restart rules, exceptions and managed responsibilities.