Management portal
Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.
Separate platform ownership from client operations, assign management scope and make temporary access expire deliberately.

CyberCursor uses a hierarchy that matches the responsibilities of a service owner and its clients. The platform Super Admin manages organizations and high-level system responsibilities; that role does not automatically operate customer endpoints. Each client has its own administrators, endpoints, groups and management assignments. This creates a useful boundary when a buyer asks who can access an employee computer. Establish the client organization first, provision its owner and complete account authentication before enrolling devices. The client administrator then makes operational access decisions within that client. This separation is part of the current pilot authorization model, not a substitute for an organization’s legal or privacy policies. Clearly document the account owners and the reasons for privileged access alongside your deployment plan.
A client administrator can create management users and assign selected endpoints or groups. Give each person the smallest operational scope that fits their recurring responsibilities, such as a site group or a small set of devices. Select view-only or control permission as appropriate for the remote work rather than assuming that every technician needs both. Current authorization follows the user’s active membership and assignment; a historical grant should not remain sufficient after scope changes. File and terminal privileges have their own administrator requirements and are not added by a management remote-access assignment. Review the people, endpoints and groups regularly, especially after role changes. Named access makes an operational record easier to interpret than a shared support login and gives a client a clear place to revoke responsibility.
Guest access is intended for a temporary, narrow support relationship. A client administrator selects specific endpoints, chooses the applicable remote permission and sets the expiry, up to thirty days in the current workflow. Use an expiry that matches the work rather than automatically choosing the maximum. A guest does not gain general device, group, file or terminal administration by receiving a remote share. Current endpoint scope, client status and expiry continue to matter when a session is requested and checked. Revoke the share early when the task is finished or circumstances change. Keep the purpose, recipient and agreed duration with the support record. This helps the client explain a contractor’s access without turning a one-time investigation into a permanent management assignment.
Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.
Windows and Mac apps for interactive screen access, terminal commands and bounded file modifications.
Identity, reports and authorized actions on the owned computer. Availability depends on endpoint readiness and OS permissions.
MFA strengthens account authentication, while current endpoint scope determines what an authenticated person may do. CyberCursor’s hosted pilot uses organization sign-in with an authenticator and recent-MFA requirements for sensitive administrative operations. The installed controller authenticates through the same account workflow and provides the required interactive channel for screen access, terminal commands and file changes. A browser session does not become eligible for direct endpoint control because it can display inventory. Likewise, a controller connection does not override a revoked assignment or expired guest share. During evaluation, test the allowed path and the refusal path: correct client, correct role, expired access, unrelated endpoint and a signed-out controller. Treat this as verification of your intended workflow rather than relying on an attractive sign-in screen as proof of authorization behavior.

Operational records help answer what was requested, what scope applied and what result was reported. CyberCursor’s pilot includes access and administrative workflows alongside audit context, with client separation and protected database access. Independent external audit anchoring, retention commitments and formal third-party certification remain separate release and governance work. That distinction matters when an enterprise buyer has a specific audit requirement. Define the evidence your team needs for a support event or administrative change, including the actor, endpoint, requested effect and actual outcome. Then check whether the current workflow provides it in a usable form. Do not infer SOC 2, ISO 27001 or another certification from a product feature. Evaluate the operational record against your process and use separately verified controls for formal compliance obligations.
Organizations, clients and high-level administration.
Assigned endpoints, groups, enrollment keys and operational workflows.
Explicitly shared endpoints with a scoped expiry, rather than whole-client access.
A useful access pilot includes the end of permission as well as its beginning. Create a scoped management assignment for an owned test endpoint, confirm the permitted remote path and then remove the assignment. Separately create a short-lived guest share and verify refusal after expiry or early revocation. Review whether active authorization checks close access as expected, and record the result rather than assuming that deleting a list entry ended every connection instantly. Keep endpoint file and terminal checks separate because their permissions differ from remote view/control. Complete the pilot with disabled test accounts and revoked temporary access. Contact connect@cybercursor.com with your support roles, client structure and audit evidence requirements so the evaluation can reflect the real people who will use the system.

Operational details matter as much as the interface.
The current hierarchy excludes Super Admin from endpoint operations. Client administrators manage their own operational access.
Current guest shares can have an expiry up to thirty days and can be revoked earlier. Choose a duration that fits the specific support task.
No. Current file and terminal operations require client administrator permission and recent MFA. Remote view/control assignments do not add those privileges.
The public pilot does not claim SOC 2, ISO 27001 or similar certification. Assess the observed controls against your requirements and use independently verified certification evidence where needed.
Connect this workflow to the rest of your endpoint workspace.
Understand Windows and Mac endpoints with hardware, operating-system, software and identity details in one client workspace.
Explore FEATURESPILOTInvestigate CPU, memory, storage, network and process activity with endpoint reports and clear freshness.
Explore FEATURESPILOTBrowse endpoint folders in the portal and use CyberCursor Remote for authorized file uploads and modifications.
ExploreStart with a conversation about your fleet, your workflows, and a controlled pilot.