CyberCursor Remote 0.4.1 · Endpoint 0.3.2 · Easier desktop sign-inExplore the pilot builds
GUEST ACCESS

Share one endpoint. For a set time. By name.

Give an outside specialist or a temporary helper exactly the endpoints they need, in view-only or control mode, with an expiry the server enforces. Revocation closes an open session, and every change is audited.

CYBERCURSOR / GROUPSILLUSTRATIVE VIEW
CyberCursor groups interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
CHAPTER 01

A guest is a person, not a password

A client administrator creates a guest from Users and access by entering a name, an individual email or login, the specific endpoints to share, view-only or control, and an expiry. A new identity receives a temporary password that is shown once in the creation result; the administrator passes it on directly, and the recipient must change it and configure an authenticator at first sign-in. An existing identity keeps its own password and multi-factor setup, because this flow never resets credentials. No email is sent automatically, so nothing leaves the platform without the administrator deciding it should. Guest access never discloses or copies the endpoint's permanent password; the guest inherits the creating administrator's current saved grant instead. The same personal login then works in CyberCursor Remote, where only the shared, remotely usable endpoints appear.

CYBERCURSOR / GROUPSILLUSTRATIVE VIEW
CyberCursor groups interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
CHAPTER 02

Expiry is mandatory and server-enforced

Every guest membership carries an expiry. The form proposes three days, and the server accepts anything from one minute to thirty days; there is no indefinite guest. The expiry is not a reminder for the administrator to act on later. A guest session's deadline is capped at the membership expiry, so a session cannot outlive the share that allowed it. Each authenticated request and each bound relay check resolves the current enabled memberships, which means access does not survive an expired membership through a cookie or a connection proof issued earlier. Expired and revoked memberships do not consume active user capacity under the company plan, so short-lived shares are not penalised. When a share needs to continue, the administrator edits the expiry explicitly using the displayed revision, and that change is audited like any other.

CYBERCURSOR / GROUPSILLUSTRATIVE VIEW
CyberCursor groups interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
CHAPTER 03

Scope is endpoints, never the client

A guest sees exactly the endpoints that were selected and nothing else. There is no group-wide scope for guests, no pairing or password storage, no administration of management users, no platform access, no scripts or jobs and no provider administration. Device reads for guests and management users are filtered by tenant, organization and effective device scope, so a listing cannot leak a computer outside the share. Jobs, audit, artifacts and provider listings are denied for these scoped roles, and group listings do not reveal unrelated groups or their members. Assigning an offline sample endpoint demonstrates scope but cannot create a usable relay, because a live agent and a saved grant are required for remote access. Scope is recomputed from current membership on every request, and an empty scope yields no devices rather than all devices.

01

Management portal

Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.

02

Desktop controller

Windows, macOS and Linux apps for interactive screen access, terminal commands and bounded file modifications.

03

Endpoint agent

Identity, reports and authorized actions on the owned computer. Availability depends on endpoint readiness and OS permissions.

INFOGRAPHIC

The access hierarchy.

Platform owner, client workspace, scoped management users and named guests with expiry.

Access hierarchyA platform owner above a client workspace. The client creates scoped management users and named guests with mandatory expiry. Management users reach all assigned endpoints; a guest reaches two shared endpoints.01 / PLATFORM02 / CLIENT03 / DELEGATION04 / ENDPOINTSPLATFORM OWNEROrganizations, clients, high-level administrationCLIENT WORKSPACENorthstar ITOwns endpoints, groups, enrollment keys and usersMANAGEMENT USERSScope: assigned endpoints and groupsOperational workflows inside that scope onlySCOPEDNAMED GUESTSSelected endpoints · expiry is mandatoryAccess ends on the date set when sharingEXPIRESONLINELON-FINANCE-04WindowsONLINENYC-DESIGN-12macOSONLINEAMS-SUPPORT-07WindowsONLINEBER-ENG-02macOSONLINELON-RECEPT-01WindowsOFFLINENYC-MKTG-08macOSONLINEAMS-QA-03WindowsONLINEBER-OPS-06macOSALL ASSIGNED ENDPOINTSTWO SHARED ENDPOINTSFICTIONAL EXAMPLE DATA · SCOPES AND EXPIRY FOLLOW THE SHIPPED ACCESS MODEL
The access hierarchyShipped access model
CHAPTER 04

Revocation closes the relay immediately

Authorization is checked before each forwarded input and every second while a session is idle. Revoking or expiring a guest closes an active relay, followed by cleanup of the private provider share, and a failed recheck closes the relay as well. Several other events invalidate delegated access without touching the guest record: removing the administrator's saved grant for that endpoint, changing the endpoint password, disabling remote access on the endpoint, or disabling the parent membership that the share was created under. Revoke disables this client's membership; Restore access is an explicit, audited regrant that reapplies current scope and quota checks rather than silently reviving the old one. Account mutations are audited without passwords. A reviewer can therefore see who shared which endpoint with whom, when it was changed, and when it ended.

Conceptual architectural operations screens
Original editorial illustration · Conceptual architecture
CHAPTER 05

Management users for ongoing work

Guests are for specific endpoints and a short time. For regular support staff the client administrator creates management users instead, assigning endpoints and groups, choosing view-only or control, and optionally setting an expiry. A management user can update the membership of assigned groups using already authorized endpoints, but cannot enroll or revoke endpoints, create new groups, manage accounts, run scripts or jobs, change providers or grant higher authority. Group scope is recomputed from current group membership on every request, so moving a computer out of a group removes it from every management user who only had access through that group. A person authorized by several clients signs in once and chooses the workspace in the controller. The platform owner, the Super Admin, administers organizations and cannot pair endpoints or open remote sessions at all.

01 / PLATFORM

Super admin

Organizations, clients and high-level administration.

02 / ORGANIZATION

Client & managers

Assigned endpoints, groups, enrollment keys and operational workflows.

03 / DELEGATION

Time-limited guest

Explicitly shared endpoints with a scoped expiry, rather than whole-client access.

CHAPTER 06

Test revocation as seriously as access

A short acceptance test proves the boundary. Create a guest on a disposable, owned endpoint with a one-hour expiry. Sign in as that guest in CyberCursor Remote and confirm that only the shared endpoint appears, that other computers and groups are absent, and that the portal shows no jobs, audit or artifacts. Open a session, then revoke the share from the administrator account and confirm the session closes and the endpoint's privacy bar clears. Let a second share expire and confirm the guest can no longer sign in to that workspace. Finally, restore access and check that the regrant appears in the audit record with the current scope. The release records include fifty-four hierarchy checks covering these paths, but your own observations on your own computers are the evidence that matters for a pilot.

Angular monitors and laptops connected around a navy gateway cube
Original editorial illustration · Conceptual architecture
EVALUATION NOTES

Questions to take into your pilot.

Operational details matter as much as the interface.

What is the longest a guest share can last?

Thirty days. The server accepts expiries from one minute to thirty days, and the form proposes three days. There is no indefinite guest; to continue a share, edit the expiry explicitly and the change is audited.

Does a guest receive an email invitation?

No. Nothing is sent automatically. A new identity's temporary password is shown once to the administrator who created it, and the recipient must change it and set up an authenticator at first sign-in.

Can a guest see other devices in the client?

No. Device reads are filtered to the selected endpoints, group listings do not reveal unrelated groups or members, and jobs, audit, artifacts and provider listings are denied to guests.

What happens to an open session when I revoke a guest?

Authorization is rechecked before each forwarded input and every second while idle, so the relay closes within about a second of revocation. The private share is then cleaned up and the outcome is recorded.

Build your next endpoint workspace.

Start with a conversation about your fleet, your workflows, and a controlled pilot.