#quickstart

From nothing to a readable status board in about fifteen minutes: one workspace, one agent, one forwarding rule, and a decision about who can approve what.

##Before you start

You need three things, none of which take long to find.

  • Administrator rights on one device. Any machine will do - the first one is only there to prove the pipeline works.
  • Control of the mailbox people write to when something breaks, enough to add a forwarding rule. If that mailbox does not exist yet, create it now and point it at nothing; you will have something to forward to in step four.
  • The name of whoever will approve actions. One person is fine to begin with. This is the only decision in the setup that carries weight.

No directory migration required

The agent identifies devices by hardware and the signed-in account. Linking to Microsoft Entra ID or Google Workspace improves the user side of the inventory, but it is not a prerequisite and can be added on any afternoon afterwards.

##1 · Create the workspace

A workspace is one company. Service providers create one per client and manage them from a single board - see the service provider notes for how that nests.

Signing up gives you a workspace slug and an enrolment key. The slug appears in every command; the key is what lets an agent join.

what you get on signupkeep the key private
workspace   acme-traders
enrol key   ITB-7K4D-9PQ2-M1XV      # rotatable from Settings → Agents
region      ap-south                # where the workspace data lives

##2 · Install the agent on one device

Run the installer, enrol, and watch the device appear. Pick the platform you are sitting in front of.

###Windows

powershell, as administratorwindows 10 1809 and later, server 2016 and later
winget install Infotechbang.Agent --accept-package-agreements
infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV

# enrolled        desk-04
# mode            read-only
# first report    12s

###macOS

terminalmacos 13 and later, apple silicon and intel
brew install --cask infotechbang-agent
sudo infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV

# macOS will ask once for the system extension. Approve it in
# System Settings → Privacy & Security, then the agent reports in.

###Linux

shelldebian, ubuntu, rhel, rocky, alma
curl -fsSL https://pkg.infotechbang.com/install.sh | sudo sh
sudo infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV
sudo systemctl enable --now infotechbang-agent

# the unit runs as a dedicated service account with no shell

Verify before you widen

Run infotechbang-agent status on the device. You want mode: read-only and a check-in timestamp under a minute old. If the check-in is empty, the agent cannot reach agent.infotechbang.com on port 443 - that is the only outbound rule it needs.

##3 · Roll out the rest of the fleet

Three ways, depending on what you already run.

  • Group policy or Intune. Download the MSI and pass the workspace and key as properties. The device enrols silently on next policy refresh.
  • MDM for Macs. Upload the package and the configuration profile together, so the system extension is pre-approved and no user sees a prompt.
  • A shared enrolment link. For companies without device management: send the link, the person runs one installer, nothing is typed. The link can be set to expire and to cap the number of enrolments.
msi, silentgroup policy or intune
msiexec /i infotechbang-agent.msi /qn WORKSPACE=acme-traders KEY=ITB-7K4D-9PQ2-M1XV

# devices appear on the board as they refresh policy
# nothing is installed on the device beyond the agent itself

##4 · Connect intake

Requests should arrive where people already send them. Forward the mailbox rather than retraining everybody.

mail rulemicrosoft 365, google workspace, anything with forwarding
forward  it-help@acme-traders.com  ->  acme-traders@in.infotechbang.com

# first ticket      #2240 classified in 1.4s
# replies          stay threaded on the same ticket
# attachments      kept, including photos

WhatsApp intake is a QR scan from Settings → Intake and takes under a minute. The web form is live from the moment the workspace exists; drop the link on your intranet.

##5 · Decide who approves what

Three roles. Requesters raise and read their own tickets. Operators work the queue. Admins approve anything that touches a device.

dashboard · peopleroles
invite  ravi.k@acme-traders.com     role=admin      approvals: all
invite  ops@acme-traders.com        role=operator   approvals: patches only
invite  everyone@acme-traders.com   role=requester  approvals: none

# approval queue routed to ravi.k
# every approval is recorded with the device state either side

Pick a second approver early

A single approver is a single point of delay. Critical patches sitting in a queue because one person is on leave is the most common avoidable complaint we hear in week three.

##Your first status

Once two devices have reported, the board is worth reading. The same view is available from the command line, which is what most people end up using.

acme-traders · statusexit 0 pending
$ infotechbang status --org acme-traders reading 6 agents · last sync 9s ago DEVICES 6 online · 0 offline PATCHES 11 pending · 2 critical [awaiting first approval] LICENCES still matching · 3 of 6 devices TICKETS 1 open · 1 auto-sorted #2240 "wifi keeps dropping in the conference room" → restart AP-2 suggested · waiting for approval

A high pending-patch count on day one is normal and not a judgement on your estate. It is the first full audit most fleets have had; it falls quickly once you approve the first ring.

##Where the fifteen minutes actually goes

StepTypical timeWhat slows it down
Workspace created1 minNothing
First agent enrolled2 minmacOS extension approval needs a click
Intake forwarding3 minWaiting on whoever owns the mailbox
Roles and approvals4 minDeciding, not configuring
Fleet rollout5 min to set upPolicy refresh cycles, not the agent

The licence picture is the one thing that is not instant. It needs most of the fleet to have checked in before seat counts mean anything, which in practice is the same working day.

##Limits

Limits - what this does not do

  • The agent needs outbound HTTPS. It will not work on a fully air-gapped segment, and there is no store-and-forward relay for one.
  • Devices nobody can install software on - personal phones, a client's own kit, an unmanaged contractor laptop - can be recorded by hand but will not report state.
  • Network hardware is tracked as an asset with its firmware and uptime, but switches, access points and printers have no agent and cannot be patched from here.
  • Intake does not read a shared mailbox in place. Forwarding is deliberate: the original mailbox stays untouched and you can stop at any time by deleting one rule.