What the product does
Supported operating systems, applications and platform fields are confirmed in the package schedule.
Guardian Endpoint Protection and Managed Patching combines compatible endpoint-security technology with Damocles policy, health, patch, restart, exception and remediation operations.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains supported device identifiers, customer mapping, health state, patch state, restart condition, action history, exception records and approved evidence. Installer secrets, platform credentials and raw upstream payloads remain restricted.
The proposal identifies protected endpoint quantity, supported operating systems, application list, policy, maintenance windows, restart handling, support, exclusions, reporting and the selected connector or licence.
The product does not imply support for every operating system, application, device type, network condition or patch, and it does not guarantee that every attack will be prevented or every update will install without impact.
Supported operating systems, applications and platform fields are confirmed in the package schedule.
Participant, business and provider views remain role and relationship scoped.
Managed patching is included for covered devices and supported software within the contracted scope.
A device can appear protected while its agent is unhealthy, its operating system is missing critical updates, a supported application remains exposed, a patch is waiting for restart or an exception has no owner and review date.
Guardian combines supported protection and patch information into one customer and provider workflow. Damocles operates the agreed policy, deployment, patch windows, failure follow-up and evidence. The selected endpoint technology remains an implementation detail named in the commercial schedule.
Identify missing, stale, degraded, unprotected and unsupported endpoint states across the agreed estate.
Track available, approved, deployed, failed, restart-required, deferred and exception states.
Record ownership, reason, compensating controls, expiry and evidence for devices or software outside normal policy.
Supported operating systems, applications and platform fields are confirmed in the package schedule.
Deploy or map the compatible endpoint agent and confirm customer, device and policy ownership.
Track agent status, policy, last-seen state, protection condition and supported remediation context.
Approve and deploy supported operating-system updates through agreed rings and maintenance windows.
Deploy supported third-party application updates included in the agreed software scope.
Identify pending restart state, communicate the requirement and track completion where supported.
Review installation failure, unsupported software, device-offline, deferral and approved exception conditions.
Participant, business and provider views remain role and relationship scoped.
Approved devices, operating system, last-seen state, protection health and customer ownership.
Protected, degraded, stale, missing and unsupported conditions with practical next steps.
Available, scheduled, installed, failed, deferred and restart-required states where supported.
Owner-ready work for offline devices, failed patches, restarts, unsupported software and policy exceptions.
Deployment, status, exception, action and review records supporting the customer outcome.
Estate-level protection, patch, exception and remediation summaries through Guardian.
Managed patching is included for covered devices and supported software within the contracted scope.
Prepare installers, map devices, apply policy and confirm health and customer ownership.
Maintain approved protection, scan, isolation, exclusion and update policy according to the service design.
Operate agreed maintenance windows, staged deployment rings, approval timing and restart rules.
Investigate supported patch failures, stale agents, offline devices, policy conflicts and installation conditions.
Record unsupported systems, business deferrals, compensating controls, owners and review dates.
Review coverage, health, patch success, failures, restarts, exceptions and unresolved customer actions.
The operating model balances security, application compatibility, business windows and required restart behaviour.
Confirm devices, operating systems, supported applications, ownership, maintenance windows and exclusions.
Deploy or map the agent, apply policy and validate customer and device health.
Identify protection gaps, available updates, vulnerable software, restart and exception conditions.
Use agreed rings and windows to deploy supported operating-system and application updates.
Investigate failures, offline devices, restarts, unsupported software and customer deferrals.
Retain status, actions, exceptions and service reporting through Guardian.
The product can support direct customers, NDIS providers and MSP-managed estates with different responsibility models.
Give a small IT team one managed service for protection, patching, restart and exception follow-up.
Protect the agreed provider-owned staff estate while keeping free participant accounts separate from managed endpoint licensing.
Use provider-scoped installers, device mapping, health, actions and consolidated wholesale billing.
Apply supported policy and patch scope across a defined mix of compatible desktop and server systems.
Track which supported applications are covered, current, failed, excluded or outside the managed scope.
Keep unsupported or deferred systems visible with owner, risk, compensating controls and review dates.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding begins with a clean device inventory and an explicit supported-software schedule. Damocles confirms device ownership, operating systems, critical applications, existing endpoint tools, administrator access, network paths, maintenance windows, restart requirements, remote-worker conditions and customer contacts. The package schedule identifies which software and systems are covered. A pilot group validates agent deployment, policy, application compatibility, update behaviour, restart communication, exclusion handling and Guardian mapping before broader rollout. Existing security agents are reviewed for coexistence or migration requirements. Go-live includes health baselines, deployment waves, user communication, exception handling, support paths, reporting and a documented process for lost, retired, rebuilt or transferred devices.
Guardian separates the endpoint product from the selected compatible protection technology. A supported connector must provide stable device identity, customer ownership, agent and protection health, operating-system and application context, patch or update state, timestamps and safe error information. The connector may be commercial, customer-owned or Damocles-provided. The proposal identifies the selected implementation, supported fields, operating systems, application catalogue and migration requirements. This avoids presenting one endpoint vendor as the Guardian product and allows future supported connectors to use the same customer experience. Connector changes require review of device identifiers, policy mapping, installer lifecycle, source health, historical continuity, update semantics and customer migration before activation.
Device, patch and exception records support operational review without exposing platform secrets. Guardian retains supported device identifiers, customer mapping, health state, patch state, restart condition, action history, exception records and approved evidence. Installer secrets, platform credentials and raw upstream payloads remain restricted. Patch reporting distinguishes deployment from completion. An update awaiting restart, a stale device or a failed installation is not represented as a completed remediation outcome. Historical reports use retained Guardian and source records. A device that disappears from the source is reviewed as retired, removed, stale or unmapped rather than silently treated as compliant.
Commercial scope is normally based on protected endpoints plus the agreed managed-service boundary. The proposal identifies protected endpoint quantity, supported operating systems, application list, policy, maintenance windows, restart handling, support, exclusions, reporting and the selected connector or licence. Major operating-system upgrades, unsupported or end-of-life software, bespoke packaging, emergency out-of-band change, application remediation and engineering beyond standard patch operation may require separate approval. The customer provides device access, ownership, maintenance authority and timely user or business decisions. Damocles provides the managed activities listed in the service schedule and records issues requiring customer action.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Yes where a supported connector exists and it provides the health, device, policy and update information required for the service.
Supported applications listed in the package schedule are included. Unsupported, custom and end-of-life software remain outside scope unless separately approved.
Guardian and the managed process identify the condition, communicate the requirement and track the device until completion or approved deferral.
Only where the selected platform, policy and service authority allow it. Emergency containment authority is defined before activation.
Not in Participant Free. Managed endpoint coverage applies only to explicitly licensed and authorised devices.
They remain visible as unsupported or exception records with owner, risk, compensating controls and a review plan.
The product does not imply support for every operating system, application, device type, network condition or patch, and it does not guarantee that every attack will be prevented or every update will install without impact.
Emergency change, unsupported software, major upgrades, complex remediation, lost-device response and incident containment are included only where expressly authorised and contracted.
Endpoint information remains customer and role scoped. Installer credentials, security policy secrets and raw platform payloads are not exposed in public or customer-safe views.
We will map the estate, existing technology, supported systems, application scope, maintenance windows, restart rules, exceptions and managed responsibilities.