One document decideswhat every laptop installs.

No console button edits a machine. You change the description, and the fleet becomes what it says.

Settings flow down, and can be locked.

A value set for the organisation reaches every group and every device below it. A group can be more specific where that makes sense, and a higher scope can lock a value that the ones below may not weaken. Nothing is set in two places at once.

The Sextant configuration editor with a scope selector for organisation, group and device
The configuration editor, at the scope you picked.

Policies carry their reason.

A policy is a bundle of settings with a name, a description, and the controls it answers to. It is assigned to the organisation or to a group, and the keys it locks are marked. An auditor reads the policy, not a spreadsheet about it.

A Sextant policy showing its settings, its locked keys and the controls it maps to
One policy: its settings, the keys that are locked, and the controls it answers to.

Every device says what it ended up with.

For one laptop you can see every effective setting, which policy set it, and whether a lower scope may still change it. That is the same view your service desk uses and the same view an auditor asks for.

A device in the Sextant console with every effective setting and the policy that set it
One device, and every setting that reaches it.

Not just managed. Provable.

Traditional MDM sends commands to a device and records whether they seemed to land. Sextant describes what the device should be, and the device builds itself into that. The difference shows up everywhere.

You describe the result

Not the steps to get there. Two laptops with the same description end up identical, whatever they were before.

You can show it

What a laptop runs is a fact you can hand over, not a claim. The audit trail is a side effect of the work.

A new laptop in one pass

Plug it in, walk away, pick up a finished machine. No image to maintain by hand.

One document for every laptop.site.audit.

Take it, run it, help build it.

The software is yours under the EUPL 1.2 and needs nobody’s permission. What the project needs is people: a laptop model we have never imaged, a language nobody has translated, a bug found by running it for real.