CyberCursor Remote · Mac 0.3.4 · Windows 0.3.3Explore the pilot builds
ENDPOINT GLOSSARY

A shared language for a better operating model.

Practical definitions that help buyers, administrators and support technicians describe the same endpoint workflow clearly.

CYBERCURSOR / WORKSPACEILLUSTRATIVE VIEW
CyberCursor workspace interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
CHAPTER 01

Endpoint, agent and controller

An endpoint is the particular computer being managed. The agent is the installed component that establishes its identity, reports observations and performs permitted work on that computer. The controller is the installed application the operator uses for interactive access. In CyberCursor, CyberCursor Endpoint runs on the managed Windows computer or Mac, while CyberCursor Remote runs on the operator’s own Windows computer or Mac. These are separate roles even when both computers use the same operating system. The web portal is a third surface for client administration and observation. Keeping these words distinct makes a deployment instruction clearer: download the controller for the technician, the agent for the target, then verify the target’s reports before attempting screen or input access through the authenticated controller.

CYBERCURSOR / CONTROLLERILLUSTRATIVE VIEW
CyberCursor controller interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
CHAPTER 02

Client, administrator, management user and guest

A client is the organization that owns and manages its endpoint workspace. Its administrator makes operational access decisions and manages client resources. A management user receives selected endpoint or group responsibility for recurring remote work. A guest receives a narrower endpoint share with an expiry for temporary remote access. Platform Super Admin is a different role responsible for company-level system administration, and the current CyberCursor hierarchy excludes that role from endpoint operations. These labels describe permission relationships, not interchangeable job titles. File and terminal access also have separate administrator requirements, so remote control permission does not automatically mean general management authority. When preparing a pilot, name the actual people and permitted tasks behind each role, then test both the allowed path and refusal after an assignment or share changes.

ENDPOINT / PERFORMANCE CONTEXTFICTIONAL EXAMPLE
Apple
Northstar-Mac-07Example hardware · macOS · Last report 10:42
CPU12%

Processor activity

MEMORY36%

Working memory

STORAGE78%

Used capacity

Illustrative metrics and timestamp · No live endpoint connection
CHAPTER 03

License key, enrollment and device identity

An enrollment key is a protected credential that authorizes installation into a client or group. Enrollment is the process that turns that authorized setup request into an individually identified device. In the current CyberCursor flow, the installer asks for a client or group key and an agent name; a group key also assigns the new endpoint to that group. The device then receives its own enrolled identity and certificate. The reusable key is not the endpoint’s remote-login password, and it does not become an unlimited billing entitlement. Revoking it stops future setup and unused grants, while already enrolled devices remain separate records. This distinction is useful for deployment teams: protect and rotate installation credentials deliberately, and use the endpoint workflow when the intention is to remove an existing device or stop its access.

01

Management portal

Fleet overview, performance, inventory, groups, licenses and administrative context. File listings are read-only.

02

Desktop controller

Windows and Mac apps for interactive screen access, terminal commands and bounded file modifications.

03

Endpoint agent

Identity, reports and authorized actions on the owned computer. Availability depends on endpoint readiness and OS permissions.

CHAPTER 04

Live, last known, unavailable and unknown

Live describes a reading backed by a current connection and sufficiently fresh reporting. Last known describes a preserved observation that may still be useful but does not represent the current device state. Unavailable means that a counter or operation cannot currently provide a usable result; it is different from a real numeric zero. Unknown describes an operational outcome that has not been reconciled, such as work accepted before connectivity was lost. These distinctions prevent a dashboard from creating false certainty. In CyberCursor’s endpoint profile, timestamps and reporting gaps matter to performance interpretation. In operational jobs, missing results should not automatically trigger repeated mutation. During evaluation, disconnect an owned test endpoint and inspect how its information changes, then reconnect and obtain a new observation before treating the old record as current.

Conceptual architectural operations screens
Original editorial illustration · Conceptual architecture
CHAPTER 05

Artifact, target, canary and maintenance ring

An artifact is the specific script or package proposed for execution, identified by its version and relevant integrity evidence. A target is an explicitly selected endpoint that the job is intended to affect. A canary is a representative first target used to check the change before additional devices proceed. A maintenance ring is an operational grouping used to plan that staged evaluation. CyberCursor’s automation preview freezes job targets and supports bounded canary gating; those controls are different from a claim of unrestricted production rollout. Choose the canary based on actual platform and application context, and define the expected independent result before execution. A familiar group name does not guarantee that every member is suitable for a particular package. Review artifact assumptions, target identity, limits and recovery together as one intended change.

01 / PLATFORM

Super admin

Organizations, clients and high-level administration.

02 / ORGANIZATION

Client & managers

Assigned endpoints, groups, enrollment keys and operational workflows.

03 / DELEGATION

Time-limited guest

Explicitly shared endpoints with a scoped expiry, rather than whole-client access.

CHAPTER 06

Requested, accepted, reported and verified

An operation can be requested without being accepted, accepted without returning a complete result, and reported as completed without independently proving its intended effect. Verified means that the relevant endpoint condition has been inspected against a defined acceptance criterion. For a software update, that might be an observed installed version; for a small file transfer, the resulting size, checksum and expected content; for remote support, actual screen and intended input behavior. A successful sign-in or published download is not the same acceptance category. Keep these stages explicit in support records and rollout decisions, and preserve uncertainty when evidence is missing. This shared vocabulary helps a team read a dashboard without overstating completion. Contact connect@cybercursor.com if a pilot requirement needs a clearer definition or an agreed evidence check.

CYBERCURSOR / WORKSPACEILLUSTRATIVE VIEW
CyberCursor workspace interface illustration with fictional Northstar IT devices
Product illustration · Fictional device and organization data
EVALUATION NOTES

Questions to take into your pilot.

Operational details matter as much as the interface.

Are an agent and a controller the same installer?

No. The agent runs on the managed endpoint; the controller runs on the operator’s computer. Choose the correct component and processor architecture for each role.

Does unavailable mean a reading is zero?

No. Zero is a valid reported measurement; unavailable means a usable observation is missing or cannot currently be obtained.

What makes a job result verified?

Define the intended endpoint condition and inspect it independently. A request, successful process status or returned message alone may not prove the expected effect.

Is an enrollment key a subscription guarantee?

No. It authorizes setup. Company plan, subscription state and endpoint limits remain independently enforced.

Build your next endpoint workspace.

Start with a conversation about your fleet, your workflows, and a controlled pilot.