Service
Device & Asset Management
Every laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.
- Zero-touch
- Device ships to the user, not to IT
- Posture
- Compliance state gates production access
- Same day
- Offboarding revokes access and wipes
Device management is unglamorous and it is where a surprising share of real-world compromise starts. An unencrypted laptop in a taxi. A contractor who left six months ago whose account still works. A fleet two major OS versions behind because updates were “disruptive”.
It is also where IT spend leaks — licences for people who left, hardware nobody can locate, refresh cycles driven by complaints rather than data.
The programme
Enrolment. Devices ship from the vendor directly to the employee. They power on, authenticate against your identity provider, and the device configures itself — encryption, policy, applications, certificates, VPN or zero-trust client. IT never touches the box. Apple Business Manager and Android Enterprise make this possible; Kandji, Jamf, Intune and SureMDM make it maintainable.
Baselines. One compliance definition across platforms: full-disk encryption on, screen lock within policy, OS within N versions of current, firewall enabled, EDR agent reporting, no local administrator for standard users. Devices that drift are reported, then remediated, then blocked.
Applications. A self-service catalogue so people install what they need without a ticket, with licensing tracked against actual assignment rather than against a purchase order from two years ago.
Lifecycle. Procurement, assignment, warranty, refresh eligibility and disposal — one record per asset, reconciled against what the MDM actually sees. The reconciliation is the point: the gap between the asset register and the enrolled fleet is where the missing devices live.
Offboarding. On the leave date: access revoked at the identity provider, device locked or wiped, licences reclaimed, asset marked for return. One workflow, triggered by HR, not by someone remembering.
Posture as an access condition
The reason to do this well is that it makes the security model possible. Once every device is enrolled and reporting, “is this device compliant?” becomes a signal your identity provider can act on.
Production access then requires a managed, encrypted, patched device — not a password and a hope. That single control removes a large class of credential-theft outcomes, and it is only available to organisations that got device management right first.
Who this is for
Companies growing past the point where IT is someone’s side responsibility; distributed and remote-first teams; organisations with field or frontline workforces on shared and rugged devices; and any team facing a security questionnaire that asks how they enforce encryption on endpoints.
Questions
Asked often enough to answer here.
We are a mixed Mac, Windows and Android shop. Does that work?
Yes, and it is the normal case. Kandji or Jamf for Apple, Intune for Windows, SureMDM for Android and rugged or kiosk devices. One compliance definition, enforced per platform, reported in one place.
What about rugged devices, kiosks and shared tablets?
SureMDM is strong here — kiosk lockdown, single-app mode, remote control and location for field fleets. We have run these programmes for distributed non-desk workforces.
Will employees hate it?
They hate badly configured MDM. A good programme means a device that works on day one, software available without a ticket, and no surveillance of personal activity. We draw that line explicitly in policy and configuration, and we publish it to staff.
How does this connect to security?
Device posture becomes a condition of access. An unencrypted or unpatched laptop does not reach production — enforced at the identity layer, not by asking nicely.
Also
The rest of the estate.
- InfrastructureWe take the estate you already have and make it legible, automated and boring.
- NetworkRouting, peering and address space — designed on paper, built as code, proven by withdrawal tests.
- CDN & EdgeYour own content network on your own address space — or a sane configuration of someone else's.
- SecurityReduce the number of ways in, then prove what happened on the ones that remain.
- On-PremA private cloud that behaves like a public one — self-service, API-driven, and yours.
- AI InferenceRun your models on hardware you control — for cost, for latency, or because the data cannot leave.
- ObservabilityKnow it broke before the customer does — and know which layer, in one click.
- All servicesOverview, delivery method and the things we will tell you not to buy.
Next step
Tell us what breaks at 3am.
A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.