Skip to content
Patronus
Website

Organizations and devices

Manage organization access, enrollment, device groups, and policy scope.

An organization is the shared boundary for devices, AI inventory, findings, and governance policy. Personal API keys and scan jobs belong to the individual Control Plane account.

An organization administrator can invite users through the dashboard’s organization controls. The invitation gives the person access; enrollment connects a particular Patronus installation to the organization.

The organization must also be enabled for Patronus governance. If a signed-in user cannot enter the dashboard, check organization membership and access before repeating device setup.

Follow the Discovery quickstart to enroll and verify the first device.

Use Device Groups to create rollout groups and assign enrolled devices directly. A device belongs to at most one group. An unassigned device receives organization-wide policy rules; group-scoped rules are distributed to devices in their selected groups.

Group assignment is independent of a person’s membership or role. Review device assignments when rolling out a group-scoped policy.

Moving an installation to another organization requires an explicit rebind and creates a new device identity. Confirm the target organization and review policy state after the move.

Organization policy is authored in the dashboard and distributed to enrolled devices. Local rules can make treatment more restrictive but cannot weaken organization policy.

Product capability settings and organization configuration are separate from policy. Enabling a capability does not itself create an allow or block rule.

After a change, use policy rollout verification to confirm behavior on an affected device.