One document decideswhat every laptop installs.
No console button edits a machine. You change the description, and the fleet becomes what it says.
Settings flow down, and can be locked.
A value set for the organisation reaches every group and every device below it. A group can be more specific where that makes sense, and a higher scope can lock a value that the ones below may not weaken. Nothing is set in two places at once.
Policies carry their reason.
A policy is a bundle of settings with a name, a description, and the controls it answers to. It is assigned to the organisation or to a group, and the keys it locks are marked. An auditor reads the policy, not a spreadsheet about it.
Every device says what it ended up with.
For one laptop you can see every effective setting, which policy set it, and whether a lower scope may still change it. That is the same view your service desk uses and the same view an auditor asks for.
Not just managed. Provable.
Traditional MDM sends commands to a device and records whether they seemed to land. Sextant describes what the device should be, and the device builds itself into that. The difference shows up everywhere.
You describe the result
Not the steps to get there. Two laptops with the same description end up identical, whatever they were before.
You can show it
What a laptop runs is a fact you can hand over, not a claim. The audit trail is a side effect of the work.
A new laptop in one pass
Plug it in, walk away, pick up a finished machine. No image to maintain by hand.
One document for every laptop.site.audit.
Take it, run it, help build it.
The software is yours under the EUPL 1.2 and needs nobody’s permission. What the project needs is people: a laptop model we have never imaged, a language nobody has translated, a bug found by running it for real.