Product Documentation

System Optix — Full Feature List

One console for endpoint management, security, and monitoring across Windows and macOS — built and extended in place, module by module. This is the current inventory, pulled straight from the running server's routes, each item marked by real status rather than assumed done.

Compiled from the live route table · 2026-08-26

110
Features
104
Live
5
Partial
1
Not built
Livereal data, verified working end-to-end
Partialreal, but with a known gap or an untested path
Not builtdisclosed in-app as missing, never faked
Dashboard & Live View6 features Device Management9 features Monitoring Suite13 features Productivity Suite8 features Reports & Alerts3 features Browser Control9 features Security13 features MDM — Windows & macOS19 features Adaptive Security6 features Remote Support & Self Service4 features Organization & People8 features AI & Automation6 features Platform & Admin6 features

Dashboard & Live View

6 features

Where a session starts — fleet health at a glance, then a click into any one screen.

Main DashboardLive

Org-wide live counts, real org name, push-cert status, license seat bar.

Live View gridLive

Thumbnail wall of every online device's current screen.

Live screen streamingLive

Full-size real-time stream of one device, remote-support grade.

Monitoring DashboardLive

Consolidated KPIs across the whole monitoring suite.

Screen MonitoringLive

Periodic screenshot capture, per-device gallery, fleet-wide feed.

Command CenterLive

Cross-module operational overview for admins running the floor.

Device Management

Win + Mac9 features

Enrollment through to day-to-day fleet control, including which of the 4 major systems a device actually participates in.

Devices listLive

Per-device toggles for Monitoring, MDM, Endpoint Security, Adaptive Security — nothing auto-enrolls.

Enrollment queuePartial

Approve or reject new device check-ins before any data collection starts.

Agent enrollment (Windows + macOS) is real. Windows Autopilot and Apple Business Manager zero-touch enrollment are not built — both need an external tenant (Azure/Intune, Apple Business Manager). Confirmed 2026-08-25: no such account exists yet — deliberately deferred, not a gap to chase right now.

Agent ManagementLive

Self-contained installer generator — token/key baked in, per-company personalized.

Agent downloadsLive

Windows EXE, macOS DMG (dual-process install), browser extension, mitm proxy module.

2026-08-25: macOS self-update fixed — the root daemon now performs the write on the per-user agent's behalf instead of it hitting its own root-owned file.

LocationsLive

Site/location grouping for multi-site fleets.

Emergency CenterLive

Fast-path panel for incident-response actions across devices.

Scheduled ScriptsLive

Remote script execution, one-off or scheduled.

Software change logLive

Install/uninstall diffs per device over time.

CSV / PDF exportLive

Device list and reports, exportable from every list view.

Monitoring Suite

Win + Mac13 features

Fleet-wide report per signal, plus a full per-device profile that merges all of them into one view.

Website MonitoringLive

Per-site time spent, category, real visit log including blocked visits.

Application MonitoringLive

Foreground app usage time, categorized.

System MonitoringLive

CPU/RAM/disk/network/GPU-usage/battery-health telemetry, live and historical (Windows).

2026-08-25: GPU usage and battery health turned out to have real cross-vendor reads after all (Windows' own GPU Engine performance counter; WMI battery capacity classes) — added for real, Windows only so far. CPU/GPU temperature stays honestly “Not collected” — no driver-free API exists on either OS.

USB MonitoringLive

Connect/disconnect events, files seen on a drive, drive inventory.

Print MonitoringLive

Document, printer, user, and page count per job.

Mic / Webcam MonitoringLive

Real start/end/duration sessions, not just a live-in-use flag.

File MonitoringLive

Create/delete/rename/modify events in key folders, sensitive-file flagging.

Keystroke MonitoringLive

Buffered capture, keyword summary plus full typed chunks.

Clipboard MonitoringLive

Per-copy text log, off by default.

Email & Chat MonitoringLive

Outlook, webmail, and messaging-app time; real webmail-open log.

Data Usage ReportLive

Real per-day download/upload MB, per device or fleet-wide.

Idle / Active ReportLive

Idle-vs-active seconds derived from real session + idle telemetry.

Full device profileLive

Every signal above merged: today panels, multi-day history, activity timeline, full alert history, tab and app-switch logs.

Productivity Suite

8 features

Turns the raw monitoring signal into a scored, work-vs-personal view of the day — no LLM, all statistical.

Productivity DashboardLive

Org-wide productivity score trend.

By user / team / departmentLive

Same scoring rolled up at three org levels.

Top applications / websitesLive

Ranked by time, classified productive/neutral/unproductive.

AttendanceLive

First-seen / last-seen derived attendance view.

Classification & scoring settingsLive

Admin-editable per-app/per-site classification, score weights, thresholds, working hours.

Scheduled reportsLive

SMTP-delivered productivity reports on a schedule.

Intent DetectionLive

No-LLM work/personal/neutral classification of today's activity.

Cross-Tab Workflow AnalysisLive

Reads the real app/tab switch log as a sequence, not a raw dump.

Reports & Alerts

3 features

The forwarding and export layer that sits over every other module.

Reports hubLive

Cross-module report index with CSV/PDF export.

Alert CenterLive

Every triggered alert, natural-language search, per-type rules.

Alert forwardingLive

Slack, WhatsApp, Teams, generic webhook, and email — configurable per alert type.

Browser Control

9 features

A force-installed extension (Chrome/Edge/Brave/Opera) plus a policy engine and a self-training risk model.

Recent visitsLive

Real per-visit URL log, blocked visits included.

Downloads & uploadsLive

File, source/destination, size, sensitive/blocked flags.

Cloud storage trackingLive

Uploads/downloads via Drive, Dropbox, and similar services.

Tab monitoringLive

Open/close/duplicate/pin lifecycle log per tab.

Browser SecurityLive

Malware/phishing block log from the extension.

Risk PredictionLive

No-LLM statistical model that self-trains per device from its own history.

Website time budgetsLive

Per-site daily time limits, enforced by the extension.

Extension statusPartial

Per-device, per-browser install/policy/detection state.

2026-08-26: found and fixed the real root cause of “not detected yet” — the force-install policy pointed at a plain-HTTP URL, and Chrome refuses to install a self-hosted extension over HTTP. Repointed to the server's existing HTTPS domain, registry now shows the corrected policy on the test device. Still not confirmed installing even after a full reboot — under further investigation, possibly a stricter newer-Chrome requirement around self-hosted (non-Web-Store) force-install.

Policy Engine blockingLive

Admin-defined block rules pushed live to the extension.

Security

Win + Mac13 features

Endpoint protection: scanning, hardening findings, and the incident surface, per device and fleet-wide.

Security OverviewLive

Fleet posture summary and per-device drill-down.

AntivirusLive

ClamAV integration — scan, quarantine, restore, definitions.

VulnerabilitiesLive

OS/software CVE findings by device and by type.

Network ThreatsLive

Detected malicious network activity per device.

Ransomware detectionLive

Behavioral suspicion signals, not signature-only.

Threat HuntingLive

Ad-hoc investigation surface across collected signals.

FirewallLive

Rule status and push-to-device management.

Antivirus QuarantineLive

Isolated-file management, restore or delete.

Threats XplorerLive

Cross-device threat correlation view.

Device ControlLive

Peripheral/port-level restriction management.

Executive SummaryLive

Leadership-facing security posture rollup.

Account RisksLive

Suspicious-login and account-risk findings.

Domains & FindingsLive

Domain-level risk view and a consolidated findings log.

MDM — Windows & macOS

Split consoles19 features

Full device-management consoles, kept separate by platform since Windows and macOS management differ in almost every particular.

MDM DashboardLive

Mosyle-style overview — push cert/APNs status, enrollment counts.

OrganizationLive

Org identity, structure, and MDM-wide settings.

Compliance EngineLive

Encryption, firewall, patch, and posture checks, platform-aware.

Compliance FrameworksLive

SOC 2 / CIS Benchmarks / ISO 27001 scorecards, mapped from the Compliance Engine's own 10 real dimensions.

2026-08-26: new — each framework maps to a real subset of the existing checks (no new data collection), labeled as a technical-control snapshot, not a certified audit.

Smart GroupsLive

Rule-based dynamic device grouping (macOS).

CertificatesLive

Cert install and lifecycle management.

Software LicensesLive

Per-app license tracking.

FileVault RecoveryLive

Escrowed recovery keys (macOS).

Update PolicyLive

OS/patch update scheduling and enforcement.

DNS FilteringLive

Profile-based DNS-level content filtering.

Windows ControlsLive

15-section control panel: power, privacy, features, services, network.

Windows PoliciesLive

Policy Engine with override/versioning, all 13 profile types wired end-to-end.

2026-08-25: re-audited against the live server — all 13/13 have a real enforcement builder, and the MDM-Group-vs-Policy-Engine conflict is resolved via a single precedence resolver. Earlier “3/13” note was stale.

HardeningLive

Overview, active rules, per-device status, and rule logs.

Detection & RemovalLive

Overview, per-device detections, settings, and logs.

Admin On-DemandLive

Temporary elevated-privilege grants (macOS), overview and audit log.

Zero TrustLive

Overview, devices, suggested tasks, trusted list, settings, and event logs.

MDM QuarantineLive

MDM-side isolation queue, separate from the Antivirus Quarantine above in Security.

Remote commands (Windows)Partial

Queue → deliver → execute → report pipeline, elevated, silent.

2026-08-25: core pipeline live-tested for the first time on real hardware (list_processes, list_services — both succeeded end-to-end). Disruptive types (lock/restart/shutdown/wipe) still untested — deliberately not run against a device that might be in active use.

iOS / iPadOS / AndroidNot built

No device type for these platforms exists in this MDM yet.

Windows and macOS only. Would need Apple Business Manager / Google business access this self-hosted platform doesn't have. Confirmed 2026-08-25: not a current priority.

Adaptive Security

6 features

A per-device opt-in layer for behavioral risk and automated response, independent of MDM and core Security.

OverviewLive

Enrolled-device status and recent activity.

DLPLive

Data-loss-prevention rule matches.

Behavior RiskLive

Anomalous-behavior scoring per device.

AutomationLive

Rule-triggered automated responses.

Web ActivityLive

Browsing-pattern risk signal, distinct from Browser Control's own.

IncidentsLive

Consolidated incident log for this module.

Remote Support & Self Service

4 features

Hands-on-device tooling for support staff, and a portal end users can reach themselves.

Remote Support sessionsLive

Live screen share, file pull/push, session status and history.

macOS interactive controlPartial

Mouse-click and keyboard input injection on macOS, matching Windows' remote-control support.

2026-08-26: new — Live View (screen streaming) already worked on macOS, this adds the actual control half via Quartz/CGEventPost. Needs Accessibility permission granted to the agent on that Mac; code-verified, not yet live-tested on a real device.

Self Service portalLive

End-user-facing dashboard and webview.

Policy Engine indexLive

Cross-profile-type policy browser with change history.

Organization & People

8 features

The org chart the rest of the platform hangs off of.

Organization directoryLive

Company-wide structure view.

Departments & TeamsLive

Grouping used across Productivity and reporting.

EmployeesLive

Directory with per-employee detail and photo.

Employee portalLive

Separate login, apps launcher, for end users.

Google Workspace / SSOPartial

Workspace connect and SSO login flow.

Real OAuth flow — needs the company's own Google client ID/secret before it does anything. Confirmed 2026-08-25: deliberately deferred until actually needed, not blocking anything today.

White-labelingLive

Per-company logo, brand name, accent color, and icon color — applied on login, sidebar, and browser tab title.

Public APILive

Bearer-key-authenticated read-only REST API (devices, alerts) for SIEM/external-tool integration, scoped to one company per key.

2026-08-26: new.

Billing / InvoicingLive

Real per-device/month invoice, auto-generated monthly off the company's actual device count.

2026-08-26: new. No payment gateway is connected (no Stripe/PayPal account exists) — marking an invoice paid is a manual admin action recording how it was actually settled, not an automatic charge.

AI & Automation

6 features

Two layers deliberately kept separate: a real LLM for open questions, and a deterministic engine for anything that must always give the same answer.

Ask AILive

Gemini-backed natural-language question answering over fleet data.

2026-08-26: expanded from real usage logs — “last online time”-style questions now get a direct answer instead of a generic punt, and more Roman-Urdu spelling variants of “what can you do” are recognized.

Bulk actions via chatLive

“Restart all Windows devices”, “lock all devices online” — platform/online-filtered, company-scoped.

Bulk software rollout via chatLive

“Install Chrome on all Windows devices” — queues a Self Service install across every match.

Custom alert rules via chatLive

“Alert me if a device is offline for 2 hours” — sets a real company-wide threshold, checked by the background status watcher.

Rules EngineLive

No-key deterministic playbook analysis, cross-checks the AI model's output.

Self-Healing WatchdogLive

Agent-side watchdog that restarts a dead monitoring process automatically.

2026-08-25: retrofit pushed to the existing fleet across all 3 companies (11 Windows devices queued) — no longer fresh-installs-only.

Platform & Admin

6 features

The access-control and operations layer underneath every module above.

RBACLive

Per-user feature permissions, UniFi-style assign UI, nav auto-hides unassigned features.

Users & Team AccountsLive

Account management within a company.

Audit LogLive

Who did what, when, across the platform.

Superadmin controlsLive

Cross-company management without visibility into any company's monitored content.

Asset ManagementLive

Hardware/license asset tracking.

SettingsLive

Per-company configuration for every module above.