Skip to main content
Velatir for Desktop is designed for a single deployment per device. The installer installs the stable agent root and payload; capability configuration, detection rules, browser policy, and payload updates arrive through the managed update path rather than customer-specific installers.

Safe defaults

A configuration-fetch failure or unknown organisation leaves the device in a fail-safe state: the agent keeps running, but it does not invent a capability setting. The capabilities that do run after a healthy config sync are independent of each other:
  • device identity and heartbeat;
  • local AI-application detection;
  • directory identity enrichment;
  • browser policy reconciliation;
  • update and health reporting.
This allows an organisation to deploy the agent and establish device visibility before turning on additional capabilities.

Staged updates

Updates are resolved from the organisation’s version pin, the current rollout ring, and the stable channel. Rollouts are staged and health-gated rather than sent to the entire fleet at once. The device retains the previous payload and applies updates through an atomic swap. The heartbeat reports the agent version, payload version, health, browser-delivery posture, and last update outcome. These signals support rollout bake windows, automatic halt decisions, and investigation of unhealthy devices.

What administrators need to provide

A rollout needs one organisation-scoped ingest key. Platform and architecture determine the installer artifact; capability behaviour is selected by the backend after installation. Customer-managed browser policy remains an explicit override rather than a hidden installer variant.