Product Documentation
System Optix — Full Feature List
One console for endpoint management, security, and monitoring across Windows and macOS — built and extended in place, module by module. This is the current inventory, pulled straight from the running server's routes, each item marked by real status rather than assumed done.
Compiled from the live route table · 2026-08-26
Dashboard & Live View
6 featuresWhere a session starts — fleet health at a glance, then a click into any one screen.
Org-wide live counts, real org name, push-cert status, license seat bar.
Thumbnail wall of every online device's current screen.
Full-size real-time stream of one device, remote-support grade.
Consolidated KPIs across the whole monitoring suite.
Periodic screenshot capture, per-device gallery, fleet-wide feed.
Cross-module operational overview for admins running the floor.
Device Management
Win + Mac9 featuresEnrollment through to day-to-day fleet control, including which of the 4 major systems a device actually participates in.
Per-device toggles for Monitoring, MDM, Endpoint Security, Adaptive Security — nothing auto-enrolls.
Approve or reject new device check-ins before any data collection starts.
Agent enrollment (Windows + macOS) is real. Windows Autopilot and Apple Business Manager zero-touch enrollment are not built — both need an external tenant (Azure/Intune, Apple Business Manager). Confirmed 2026-08-25: no such account exists yet — deliberately deferred, not a gap to chase right now.
Self-contained installer generator — token/key baked in, per-company personalized.
Windows EXE, macOS DMG (dual-process install), browser extension, mitm proxy module.
2026-08-25: macOS self-update fixed — the root daemon now performs the write on the per-user agent's behalf instead of it hitting its own root-owned file.
Site/location grouping for multi-site fleets.
Fast-path panel for incident-response actions across devices.
Remote script execution, one-off or scheduled.
Install/uninstall diffs per device over time.
Device list and reports, exportable from every list view.
Monitoring Suite
Win + Mac13 featuresFleet-wide report per signal, plus a full per-device profile that merges all of them into one view.
Per-site time spent, category, real visit log including blocked visits.
Foreground app usage time, categorized.
CPU/RAM/disk/network/GPU-usage/battery-health telemetry, live and historical (Windows).
2026-08-25: GPU usage and battery health turned out to have real cross-vendor reads after all (Windows' own GPU Engine performance counter; WMI battery capacity classes) — added for real, Windows only so far. CPU/GPU temperature stays honestly “Not collected” — no driver-free API exists on either OS.
Connect/disconnect events, files seen on a drive, drive inventory.
Document, printer, user, and page count per job.
Real start/end/duration sessions, not just a live-in-use flag.
Create/delete/rename/modify events in key folders, sensitive-file flagging.
Buffered capture, keyword summary plus full typed chunks.
Per-copy text log, off by default.
Outlook, webmail, and messaging-app time; real webmail-open log.
Real per-day download/upload MB, per device or fleet-wide.
Idle-vs-active seconds derived from real session + idle telemetry.
Every signal above merged: today panels, multi-day history, activity timeline, full alert history, tab and app-switch logs.
Productivity Suite
8 featuresTurns the raw monitoring signal into a scored, work-vs-personal view of the day — no LLM, all statistical.
Org-wide productivity score trend.
Same scoring rolled up at three org levels.
Ranked by time, classified productive/neutral/unproductive.
First-seen / last-seen derived attendance view.
Admin-editable per-app/per-site classification, score weights, thresholds, working hours.
SMTP-delivered productivity reports on a schedule.
No-LLM work/personal/neutral classification of today's activity.
Reads the real app/tab switch log as a sequence, not a raw dump.
Reports & Alerts
3 featuresThe forwarding and export layer that sits over every other module.
Cross-module report index with CSV/PDF export.
Every triggered alert, natural-language search, per-type rules.
Slack, WhatsApp, Teams, generic webhook, and email — configurable per alert type.
Browser Control
9 featuresA force-installed extension (Chrome/Edge/Brave/Opera) plus a policy engine and a self-training risk model.
Real per-visit URL log, blocked visits included.
File, source/destination, size, sensitive/blocked flags.
Uploads/downloads via Drive, Dropbox, and similar services.
Open/close/duplicate/pin lifecycle log per tab.
Malware/phishing block log from the extension.
No-LLM statistical model that self-trains per device from its own history.
Per-site daily time limits, enforced by the extension.
Per-device, per-browser install/policy/detection state.
2026-08-26: found and fixed the real root cause of “not detected yet” — the force-install policy pointed at a plain-HTTP URL, and Chrome refuses to install a self-hosted extension over HTTP. Repointed to the server's existing HTTPS domain, registry now shows the corrected policy on the test device. Still not confirmed installing even after a full reboot — under further investigation, possibly a stricter newer-Chrome requirement around self-hosted (non-Web-Store) force-install.
Admin-defined block rules pushed live to the extension.
Security
Win + Mac13 featuresEndpoint protection: scanning, hardening findings, and the incident surface, per device and fleet-wide.
Fleet posture summary and per-device drill-down.
ClamAV integration — scan, quarantine, restore, definitions.
OS/software CVE findings by device and by type.
Detected malicious network activity per device.
Behavioral suspicion signals, not signature-only.
Ad-hoc investigation surface across collected signals.
Rule status and push-to-device management.
Isolated-file management, restore or delete.
Cross-device threat correlation view.
Peripheral/port-level restriction management.
Leadership-facing security posture rollup.
Suspicious-login and account-risk findings.
Domain-level risk view and a consolidated findings log.
MDM — Windows & macOS
Split consoles19 featuresFull device-management consoles, kept separate by platform since Windows and macOS management differ in almost every particular.
Mosyle-style overview — push cert/APNs status, enrollment counts.
Org identity, structure, and MDM-wide settings.
Encryption, firewall, patch, and posture checks, platform-aware.
SOC 2 / CIS Benchmarks / ISO 27001 scorecards, mapped from the Compliance Engine's own 10 real dimensions.
2026-08-26: new — each framework maps to a real subset of the existing checks (no new data collection), labeled as a technical-control snapshot, not a certified audit.
Rule-based dynamic device grouping (macOS).
Cert install and lifecycle management.
Per-app license tracking.
Escrowed recovery keys (macOS).
OS/patch update scheduling and enforcement.
Profile-based DNS-level content filtering.
15-section control panel: power, privacy, features, services, network.
Policy Engine with override/versioning, all 13 profile types wired end-to-end.
2026-08-25: re-audited against the live server — all 13/13 have a real enforcement builder, and the MDM-Group-vs-Policy-Engine conflict is resolved via a single precedence resolver. Earlier “3/13” note was stale.
Overview, active rules, per-device status, and rule logs.
Overview, per-device detections, settings, and logs.
Temporary elevated-privilege grants (macOS), overview and audit log.
Overview, devices, suggested tasks, trusted list, settings, and event logs.
MDM-side isolation queue, separate from the Antivirus Quarantine above in Security.
Queue → deliver → execute → report pipeline, elevated, silent.
2026-08-25: core pipeline live-tested for the first time on real hardware (list_processes, list_services — both succeeded end-to-end). Disruptive types (lock/restart/shutdown/wipe) still untested — deliberately not run against a device that might be in active use.
No device type for these platforms exists in this MDM yet.
Windows and macOS only. Would need Apple Business Manager / Google business access this self-hosted platform doesn't have. Confirmed 2026-08-25: not a current priority.
Adaptive Security
6 featuresA per-device opt-in layer for behavioral risk and automated response, independent of MDM and core Security.
Enrolled-device status and recent activity.
Data-loss-prevention rule matches.
Anomalous-behavior scoring per device.
Rule-triggered automated responses.
Browsing-pattern risk signal, distinct from Browser Control's own.
Consolidated incident log for this module.
Remote Support & Self Service
4 featuresHands-on-device tooling for support staff, and a portal end users can reach themselves.
Live screen share, file pull/push, session status and history.
Mouse-click and keyboard input injection on macOS, matching Windows' remote-control support.
2026-08-26: new — Live View (screen streaming) already worked on macOS, this adds the actual control half via Quartz/CGEventPost. Needs Accessibility permission granted to the agent on that Mac; code-verified, not yet live-tested on a real device.
End-user-facing dashboard and webview.
Cross-profile-type policy browser with change history.
Organization & People
8 featuresThe org chart the rest of the platform hangs off of.
Company-wide structure view.
Grouping used across Productivity and reporting.
Directory with per-employee detail and photo.
Separate login, apps launcher, for end users.
Workspace connect and SSO login flow.
Real OAuth flow — needs the company's own Google client ID/secret before it does anything. Confirmed 2026-08-25: deliberately deferred until actually needed, not blocking anything today.
Per-company logo, brand name, accent color, and icon color — applied on login, sidebar, and browser tab title.
Bearer-key-authenticated read-only REST API (devices, alerts) for SIEM/external-tool integration, scoped to one company per key.
2026-08-26: new.
Real per-device/month invoice, auto-generated monthly off the company's actual device count.
2026-08-26: new. No payment gateway is connected (no Stripe/PayPal account exists) — marking an invoice paid is a manual admin action recording how it was actually settled, not an automatic charge.
AI & Automation
6 featuresTwo layers deliberately kept separate: a real LLM for open questions, and a deterministic engine for anything that must always give the same answer.
Gemini-backed natural-language question answering over fleet data.
2026-08-26: expanded from real usage logs — “last online time”-style questions now get a direct answer instead of a generic punt, and more Roman-Urdu spelling variants of “what can you do” are recognized.
“Restart all Windows devices”, “lock all devices online” — platform/online-filtered, company-scoped.
“Install Chrome on all Windows devices” — queues a Self Service install across every match.
“Alert me if a device is offline for 2 hours” — sets a real company-wide threshold, checked by the background status watcher.
No-key deterministic playbook analysis, cross-checks the AI model's output.
Agent-side watchdog that restarts a dead monitoring process automatically.
2026-08-25: retrofit pushed to the existing fleet across all 3 companies (11 Windows devices queued) — no longer fresh-installs-only.
Platform & Admin
6 featuresThe access-control and operations layer underneath every module above.
Per-user feature permissions, UniFi-style assign UI, nav auto-hides unassigned features.
Account management within a company.
Who did what, when, across the platform.
Cross-company management without visibility into any company's monitored content.
Hardware/license asset tracking.
Per-company configuration for every module above.