Skip to main content

About Comp AI Device Agent

Comp AI Device Agent is a lightweight desktop application that runs in your system tray and automatically monitors your device’s security compliance. It checks your device configuration every hour and reports the results to your organization’s Comp AI portal. The agent checks four security areas: Your device is compliant when all four checks pass.
The agent runs silently in your system tray and uses minimal system resources. It does not collect personal data, browsing history, or file contents.
Password Policy can report that the minimum is unknown. On Linux the minimum is only readable through pam_pwquality, which a stock Ubuntu install does not include. Where nothing enforces a configurable minimum, the agent says it could not determine the minimum password length and the check fails — it will not put a number on the card that the device does not actually enforce. See Troubleshooting below for what to do about it.

System Requirements

Installation

Log in to your organization’s Employee Portal and navigate to the Device Agent task. Click Download Agent to get the installer for your operating system.
  • macOS: Downloads a .dmg file. If you have an Apple Silicon Mac (M1/M2/M3/M4), the portal selects the correct version automatically. You can also switch between Apple Silicon and Intel using the dropdown.
  • Windows: Downloads a .exe installer.
  • Linux: Downloads a .deb package.
macOS: Double-click the downloaded .dmg file and drag the Comp AI Device Agent to your Applications folder.Windows: Double-click the downloaded .exe file and follow the installation wizard.Linux: Install the downloaded .deb package using your package manager or by double-clicking it:
After installation, the agent opens a sign-in window. Log in with your work email using the same method you use for the Employee Portal (email OTP, Google, or Microsoft).Device Agent Sign InOnce signed in, the agent automatically:
  1. Registers your device with your organization(s)
  2. Runs the first compliance check immediately
  3. Starts checking every hour in the background

Using the Device Agent

After signing in, the agent lives in your system tray (menu bar on macOS, system tray on Windows/Linux). Click the tray icon to open the status window. Device Agent Status Window The status window shows:
  • Compliance status — whether your device is compliant or needs attention
  • Individual checks — each of the four security checks with Pass/Fail status
  • Remediation options — for any failing check, the agent offers a way to fix it

Tray Icon Status

Fixing Failing Checks

When a check fails, the agent provides remediation options depending on what can be done automatically:
After fixing a failing check, click Run Checks Now to verify the fix immediately instead of waiting for the next hourly check.

Password Advisory on a Passing Check

The Password Policy check can also show a note on a check that is passing. If the agent has seen the enforced minimum go up and can date that change, and your password was last set before that date, the card adds a sentence saying so. On macOS it also offers a Change Password button that opens System Settings → Touch ID & Password; on Linux the same note appears with steps instead of a button. Windows does not show this note. This never fails the check and never makes your device non-compliant. It is not a claim that your password is too short — the agent cannot read the length of anyone’s password on any platform. All it knows is that your password predates the rule, so it may be shorter than the rule now requires. Changing your password clears the note at the next check.

Tray Menu Options

Right-click (or click on macOS) the tray icon to access:
  • Run Checks Now — trigger an immediate compliance check
  • View Details — open the status window
  • Start at Login — toggle whether the agent launches automatically when you log in (enabled by default)
  • Sign Out — sign out of the agent
  • Quit — close the agent completely
If you quit or sign out of the agent, your device will stop reporting compliance status to your organization. Your security administrator may follow up if your device stops checking in.

Verifying on the Portal

After the agent runs its first check, you can verify your device compliance status on the Employee Portal. The Device Agent task shows your device name, platform, and whether all security checks are passing. The portal updates automatically — it polls your device status every 30 seconds while the page is open.

Troubleshooting

  • Make sure you’re using the same email address you use for the Employee Portal
  • Check your internet connection
  • Try quitting the agent completely and reopening it
  • If using Google or Microsoft sign-in, make sure popups are not blocked
  • Click Run Checks Now to refresh the results
  • Review the failing check details — the agent shows what it detected
  • Use the remediation option provided (Fix, Open Settings, or View Guide)
  • Some changes (like enabling FileVault) require a restart to take effect
This means the agent could not establish a minimum it is willing to stand behind. Rather than report a number the device does not enforce, it says so and the check fails. There are a few reasons it happens: nothing on the device enforces a configurable minimum; a configuration file could not be read, so a setting that overrides the rest may be hiding in it; a value is written in a form libpwquality itself rejects; or a minimum is configured but is not actually binding — enforcing = 0 makes libpwquality warn about a weak password and accept it anyway, and local_users_only applies the rules only to accounts in /etc/passwd. When the agent was specifically denied permission to read a file, the card says that instead.The failing check’s View Guide option names which of these it found, so start there.On Linux — including a stock Ubuntu install, which has no pam_pwquality in its PAM stack — an administrator can install and configure it:
Then click Run Checks Now. The failing check’s View Guide option shows these same steps, and reports which setting is overriding the drop-in when one is.
  • macOS: Look in the menu bar at the top of your screen. The icon may be hidden — check the overflow area (click the >> or similar)
  • Windows: Click the up arrow in the system tray to see hidden icons
  • Linux: Check your desktop environment’s system tray or notification area
  • The agent may need to be reopened from your Applications folder
  • Wait up to 30 seconds for the portal to refresh
  • Click Run Checks Now in the agent to trigger a fresh report
  • Check that the agent is signed in (tray icon should be green, not gray)

Migrating from FleetDM

If your device previously had the FleetDM agent (fleetd) installed, you should uninstall it after setting up the new Comp AI Device Agent. The new agent fully replaces FleetDM, and having both running is unnecessary. Follow the official uninstall guide for your platform: How to uninstall fleetd

Manual Evidence Collection

For users who cannot install the agent on their device, manual evidence of device settings is required. Below are the required pieces of evidence and where to obtain them.

Windows 10 & 11

Enable BitLocker
  1. Press Start → type Manage BitLocker → open it.
    Take a screenshot of the BitLocker Drive Encryption window showing “On” for the C: drive.
  2. Select the drive (usually C:) → click Turn on BitLocker.
  3. Save the recovery key to Microsoft Account / USB / secure location.
  4. Restart if prompted.
Screen Lock after 15 Minutes
  1. Press Start → Settings → Personalization → Lock screen.
  2. Scroll down → click Screen timeout settings.
    Take a screenshot showing the screen timeout set to 15 minutes.
  3. Set Screen turns off = 15 minutes.
  4. In Settings → Accounts → Sign-in options → ensure Require sign-in is set to “When PC wakes up from sleep”.
    Take a screenshot of the Sign-in Options page showing this setting.
Minimum Password Length (Local Policy)
  1. Press Win + R, type secpol.msc, press Enter.
  2. Go to Account Policies → Password Policy.
  3. Set Minimum password length = 8+.
    Take a screenshot of the Password Policy window with “Minimum password length” = 8 or more.
(If using Microsoft/AD/Azure, enforce via policy centrally and screenshot the policy compliance in the admin portal.)Automatic Security Updates
  1. Settings → Update & Security → Windows Update.
  2. Select Advanced options → make sure Automatic updates are enabled.
    Take a screenshot of the Windows Update settings page showing automatic updates turned on.
Antivirus (Windows Defender)
  1. Settings → Update & Security → Windows Security.
  2. Open Virus & threat protection → ensure Real-time protection is on.
    Take a screenshot of the Windows Security window showing Real-time protection is ON.
Evidence gathered manually will be uploaded as a comment and attachment to the “Secure Devices” and “Device List” tasks with the user’s email of the device the evidence is for.

macOS (Monterey, Ventura, Sonoma, Sequoia)

Enable FileVault
  1. Open System Settings (or System Preferences in older versions).
  2. Go to Privacy & Security → FileVault.
  3. Click Turn On FileVault → enter password.
  4. Record recovery key.
    Take a screenshot of the FileVault settings page showing “FileVault is enabled for the disk.”
Screen Auto-lock (15 min)
  1. System Settings → Lock Screen.
  2. Set Start screen saver when inactive = 15 minutes.
    Take a screenshot showing the setting at 15 minutes.
  3. Set Require password after sleep or screen saver begins = Immediately.
    Take a screenshot showing “Require password immediately” is selected.
Minimum Password Length
  1. Native macOS UI doesn’t enforce this; requires Terminal or MDM.
  2. sudo pwpolicy -setglobalpolicy "minChars=8" — this adds a minimum alongside the stock FileVault policy rather than replacing the policy set, which is what pwpolicy -setaccountpolicies would do.
  3. If set via Terminal, take a screenshot of pwpolicy getaccountpolicies confirming the policy.
  4. If enforced by MDM (Jamf, Intune, etc.), screenshot the compliance screen from the MDM portal.
Automatic Security Updates
  1. System Settings → General → Software Update.
  2. Click Automatic Updates → enable all options (Install Security Responses & System files, etc.).
    Take a screenshot of the Automatic Updates options screen with all toggles enabled.
Antivirus (XProtect built-in)
  1. macOS automatically runs XProtect in the background.
  2. Simply ensure macOS is fully updated.
    Take a screenshot of the Software Update page showing the Mac is up to date.
Evidence gathered manually will be uploaded as a comment and attachment to the “Secure Devices” and “Device List” tasks with the user’s email of the device the evidence is for.

Ubuntu 20.04+ / Debian-based

Enable LUKS Disk Encryption
  1. LUKS encryption is typically configured during OS installation.
  2. To verify, run: lsblk -o NAME,TYPE,FSTYPE | grep crypt
    Take a screenshot showing the encrypted volume.
Screen Lock (15 min)
  1. Open Settings → Privacy → Screen Lock.
  2. Set Automatic Screen Lock Delay = 15 minutes.
    Take a screenshot showing the screen lock delay setting.
Password PolicyLinux enforces a minimum password length through pam_pwquality, not through /etc/login.defs — nothing reads PASS_MIN_LEN, so a screenshot of it is not evidence that anything is enforced.
  1. Confirm pam_pwquality is in the PAM stack:
    Stock Ubuntu does not ship it. An administrator installs it with sudo apt install libpam-pwquality (Debian/Ubuntu) or sudo dnf install libpwquality (Fedora/RHEL).
  2. Set the minimum in a drop-in file — the same file the agent’s Fix writes:
  3. Confirm nothing overrides it. A minlen= argument on the pam_pwquality line, a minlen in /etc/security/pwquality.conf, or a drop-in that sorts after 50-comp-ai.conf each win over this file. A positive dcredit, ucredit, lcredit or ocredit anywhere in the stack lets a password be shorter than minlen in exchange for mixing character types, and enforcing = 0 or local_users_only stops the minimum binding at all.
    Take a screenshot of the drop-in’s contents and of the pam_pwquality line.
Antivirus
  1. Verify ClamAV or another antivirus is installed and running:
  2. Alternatively, show AppArmor or SELinux is enforcing:
    Take a screenshot of the output showing active protection.
Evidence gathered manually will be uploaded as a comment and attachment to the “Secure Devices” and “Device List” tasks with the user’s email of the device the evidence is for.

Support

If you have questions or run into issues with the Device Agent, contact your IT administrator or reach out to us at hello@trycomp.ai.