Edge Agents
Purpose: Provision, monitor, and manage fleet agents that operate outside the central control plane (edge devices, gateways, collectors).
Enroll an Agent
- Step 1: Generate an enrollment token with appropriate TTL and scope.

- Step 2: Use the token in the agent bootstrap command on the device to register.
- Step 3: Agent shows up in inventory and begins heartbeat/telemetry reporting.

Decommission an Agent
-
Steps:
- Revoke enrollment token if still valid.
- Remove agent from inventory and optionally trigger data removal workflows.
- Update firewall/permission lists to block agent communication.

Operational Considerations
- Use single-use tokens for maximum security.
- Track ownership (who installed it) and physical location if required by compliance.
Troubleshooting
- Agent offline / missing heartbeat: check local network connectivity, token validity, and firewall egress permissions.