Skip to main content
Velatir for Desktop is designed for a single deployment per device. The installer installs the stable agent root and payload; capability configuration, detection rules, browser policy, and payload updates arrive through the managed update path rather than customer-specific installers.

Safe defaults

Network capture is off by default. A configuration-fetch failure, unknown organisation, failed preflight, unhealthy capture state, or remote kill switch leaves the device in the connectivity-first state. The agent owns privileged network changes and independently re-checks the effective capability before starting capture. The lower-risk capabilities are separate from network capture:
  • device identity and heartbeat;
  • local AI-application detection;
  • directory identity enrichment;
  • browser policy reconciliation;
  • update and health reporting.
This allows an organisation to deploy the agent and establish device visibility without immediately changing its network path.

Staged updates

Updates are resolved from the organisation’s version pin, the current rollout ring, and the stable channel. Rollouts are staged and health-gated rather than sent to the entire fleet at once. The device retains the previous payload and applies updates through an atomic swap after capture has been safely torn down. The heartbeat reports the agent version, payload version, active and target capture drivers, capture engagement, health, and last update outcome. These signals support rollout bake windows, automatic halt decisions, and investigation of unhealthy devices.

Existing deployments

Existing deployments must be pre-seeded before a default-off payload is introduced. Their backend capability state must reproduce the behaviour they already rely on, and they must enter a late rollout ring rather than a canary ring. This avoids silently disabling active capture while preserving the safe default for new devices.

What administrators need to provide

A rollout needs one organisation-scoped ingest key. Platform and architecture determine the installer artifact; capability behaviour is selected by the backend after installation. Customer-managed browser policy and advanced certificate or machine-identity arrangements remain explicit overrides rather than hidden installer variants.