Management portal
Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.
Give an outside specialist or a temporary helper exactly the endpoints they need, in view-only or control mode, with an expiry the server enforces. Revocation closes an open session, and every change is audited.

A client administrator creates a guest from Users and access by entering a name, an individual email or login, the specific endpoints to share, view-only or control, and an expiry.
Every guest membership carries an expiry.
A guest sees exactly the endpoints that were selected and nothing else.
Authorization is checked before each forwarded input and every second while a session is idle.
Guests are for specific endpoints and a short time.
A short acceptance test proves the boundary.
A client administrator creates a guest from Users and access by entering a name, an individual email or login, the specific endpoints to share, view-only or control, and an expiry. A new identity receives a temporary password that is shown once in the creation result; the administrator passes it on directly, and the recipient must change it and configure an authenticator at first sign-in. An existing identity keeps its own password and multi-factor setup, because this flow never resets credentials. No email is sent automatically, so nothing leaves the platform without the administrator deciding it should. Guest access never discloses or copies the endpoint's permanent password; the guest inherits the creating administrator's current saved grant instead. The same personal login then works in CyberCursor Remote, where only the shared, remotely usable endpoints appear.

Every guest membership carries an expiry. The form proposes three days, and the server accepts anything from one minute to thirty days; there is no indefinite guest. The expiry is not a reminder for the administrator to act on later. A guest session's deadline is capped at the membership expiry, so a session cannot outlive the share that allowed it. Each authenticated request and each bound relay check resolves the current enabled memberships, which means access does not survive an expired membership through a cookie or a connection proof issued earlier. Expired and revoked memberships do not consume active user capacity under the company plan, so short-lived shares are not penalised. When a share needs to continue, the administrator edits the expiry explicitly using the displayed revision, and that change is audited like any other.

A guest sees exactly the endpoints that were selected and nothing else. There is no group-wide scope for guests, no pairing or password storage, no administration of management users, no platform access, no scripts or jobs and no provider administration. Device reads for guests and management users are filtered by tenant, organization and effective device scope, so a listing cannot leak a computer outside the share. Jobs, audit, artifacts and provider listings are denied for these scoped roles, and group listings do not reveal unrelated groups or their members. Assigning an offline sample endpoint demonstrates scope but cannot create a usable relay, because a live agent and a saved grant are required for remote access. Scope is recomputed from current membership on every request, and an empty scope yields no devices rather than all devices.
Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.
Windows, macOS and Linux apps for interactive screen access, terminal commands and bounded file modifications.
Identity, reports and authorized actions on the owned computer. Availability depends on endpoint readiness and OS permissions.
Platform owner, client workspace, scoped management users and named guests with expiry.
Authorization is checked before each forwarded input and every second while a session is idle. Revoking or expiring a guest closes an active relay, followed by cleanup of the private provider share, and a failed recheck closes the relay as well. Several other events invalidate delegated access without touching the guest record: removing the administrator's saved grant for that endpoint, changing the endpoint password, disabling remote access on the endpoint, or disabling the parent membership that the share was created under. Revoke disables this client's membership; Restore access is an explicit, audited regrant that reapplies current scope and quota checks rather than silently reviving the old one. Account mutations are audited without passwords. A reviewer can therefore see who shared which endpoint with whom, when it was changed, and when it ended.

Guests are for specific endpoints and a short time. For regular support staff the client administrator creates management users instead, assigning endpoints and groups, choosing view-only or control, and optionally setting an expiry. A management user can update the membership of assigned groups using already authorized endpoints, but cannot enroll or revoke endpoints, create new groups, manage accounts, run scripts or jobs, change providers or grant higher authority. Group scope is recomputed from current group membership on every request, so moving a computer out of a group removes it from every management user who only had access through that group. A person authorized by several clients signs in once and chooses the workspace in the controller. The platform owner, the Super Admin, administers organizations and cannot pair endpoints or open remote sessions at all.
Organizations, clients and high-level administration.
Assigned endpoints, groups, enrollment keys and operational workflows.
Explicitly shared endpoints with a scoped expiry, rather than whole-client access.
A short acceptance test proves the boundary. Create a guest on a disposable, owned endpoint with a one-hour expiry. Sign in as that guest in CyberCursor Remote and confirm that only the shared endpoint appears, that other computers and groups are absent, and that the portal shows no jobs, audit or artifacts. Open a session, then revoke the share from the administrator account and confirm the session closes and the endpoint's privacy bar clears. Let a second share expire and confirm the guest can no longer sign in to that workspace. Finally, restore access and check that the regrant appears in the audit record with the current scope. The release records include fifty-four hierarchy checks covering these paths, but your own observations on your own computers are the evidence that matters for a pilot.

Operational details matter as much as the interface.
Thirty days. The server accepts expiries from one minute to thirty days, and the form proposes three days. There is no indefinite guest; to continue a share, edit the expiry explicitly and the change is audited.
No. Nothing is sent automatically. A new identity's temporary password is shown once to the administrator who created it, and the recipient must change it and set up an authenticator at first sign-in.
No. Device reads are filtered to the selected endpoints, group listings do not reveal unrelated groups or members, and jobs, audit, artifacts and provider listings are denied to guests.
Authorization is rechecked before each forwarded input and every second while idle, so the relay closes within about a second of revocation. The private share is then cleaned up and the outcome is recorded.
Connect this workflow to the rest of your endpoint workspace.
Understand enrolled endpoints with hardware, operating-system, software and identity details in one client workspace.
Explore FEATURESPILOTInvestigate CPU, memory, storage, network and process activity with endpoint reports and clear freshness.
Explore FEATURESPILOTBrowse endpoint folders in the portal and use CyberCursor Remote for authorized file uploads and modifications.
ExploreStart with a conversation about your fleet, your workflows, and a controlled pilot.