Fleet actions
Fleet actions let an operator validate an installation, repair the Forge deployment, or rotate its enrollment token on an exact set of selected devices. Before execution, Forge checks that every selected device can receive the requested action and shows the intended targets for review. A readiness result does not expand the selection to other devices in the same group or source. After confirmation, the action view reports progress and the result for each device. Forge reads back device state so a successful request can be distinguished from a completed change. If only part of the selection succeeds, the successful devices remain complete and the remaining devices can be retried without rerunning the action across the full fleet.Runtime
The optionalruntime object controls how Access policies handle candidate AI
activity and enhanced detection.
These settings affect runtime classification. They do not authorize an endpoint
or provider operation by themselves.
Remediation object
Trigger phases
Not every phase is valid for every policy action.require_approval denies or holds the initial operation. Any cleanup is an
explicit part of resolving that request, not an automatic side effect of the
initial match.
Surfaces
The Console loads the backend-owned remediation catalog and shows only actions
eligible for the selected surface, policy action, trigger phase, and installed
integrations.
Action reference
Browser and account
Processes and applications
Managed configuration
Targets
Forge can derive a target only from a positiveeq or in condition on a
field compatible with the chosen action. Negated conditions never authorize a
target.
Examples of derivable target fields include:
If
target is omitted, exactly one compatible target must be derivable.
Explicit targets must also be selected by a compatible positive condition.
recordOnly is the only targetless remediation.
Actions containing WhenProven or WhenKnown are conditional by design.
Insufficient evidence or an incapable integration produces a remediation
diagnostic; Forge does not guess a target or report success.