Organizations and devices
Manage organization access, enrollment, device groups, and policy scope.
An organization is the shared boundary for devices, AI inventory, findings, and governance policy. Personal API keys and scan jobs belong to the individual Control Plane account.
Invite people and enroll devices
Section titled “Invite people and enroll devices”An organization administrator can invite users through the dashboard’s organization controls. The invitation gives the person access; enrollment connects a particular Patronus installation to the organization.
The organization must also be enabled for Patronus governance. If a signed-in user cannot enter the dashboard, check organization membership and access before repeating device setup.
Follow the Discovery quickstart to enroll and verify the first device.
Assign device groups
Section titled “Assign device groups”Use Device Groups to create rollout groups and assign enrolled devices directly. A device belongs to at most one group. An unassigned device receives organization-wide policy rules; group-scoped rules are distributed to devices in their selected groups.
Group assignment is independent of a person’s membership or role. Review device assignments when rolling out a group-scoped policy.
Move an installation
Section titled “Move an installation”Moving an installation to another organization requires an explicit rebind and creates a new device identity. Confirm the target organization and review policy state after the move.
Review policy scope
Section titled “Review policy scope”Organization policy is authored in the dashboard and distributed to enrolled devices. Local rules can make treatment more restrictive but cannot weaken organization policy.
Product capability settings and organization configuration are separate from policy. Enabling a capability does not itself create an allow or block rule.
After a change, use policy rollout verification to confirm behavior on an affected device.