Fleet Console gives you centralized visibility and control over Crawdad across your entire device fleet — per-device status, bulk operations, signed policy enforcement — without collecting a single byte of content.
Securing AI agents on a single machine is a solved problem. Doing it across hundreds of endpoints — with per-device status, consistent policy, and fleet-wide visibility — requires purpose-built tooling.
Which devices are protected? Which are pending enrollment? Which fell behind on policy? One machine is easy to check. Five hundred need a dashboard, not a spreadsheet.
Every device in the fleet needs the same detection floors, the same policy baselines, the same enforcement guarantees. Manual per-device configuration doesn't scale.
Enrolling devices one at a time, approving them individually, checking status by SSH — that's an ops burden that grows linearly with the fleet. Bulk operations eliminate it.
Fleet Console is built for real fleet scale. Browse your entire device inventory with pagination, search by hostname or status, sort by any column. Every device shows its protection status, last check-in, and policy compliance at a glance.
Fleet Console — 500 devices, per-device status, paginated inventory
Bulk select — select all 500 devices for batch approve/enroll
Multi-select individual devices or select the entire fleet at once. Approve pending enrollments in batch, update policy across a group, or take action on devices that have fallen out of compliance — all from a single operation.
Find any device instantly. Search by hostname, filter by enrollment status, narrow down to exactly the subset you need. When your fleet is 500 devices deep, you need search that works — not scroll.
Search — find any device by hostname or status
Each device runs the local-first Crawdad sidecar. Prompts, responses, and tool-call arguments stay on the device — raw content never leaves by default. Metadata-only telemetry egresses by default; content does not. The Fleet Console manages devices centrally via Ed25519-signed commands, not by collecting data.
Central management without central data collection. The zero-knowledge architecture holds at fleet scale.
Manage Crawdad across your entire client base from one console. Per-client scoping, multi-tenant device management, bulk enrollment. Your clients get local-first protection; you get fleet-wide visibility and control.
Learn more about Crawdad for MSPs →Roll Crawdad out across hundreds of endpoints with centralized policy enforcement, signed detection floors, and an immutable audit trail. Endpoint-scale protection with zero-knowledge architecture — nothing to breach at the center.
Learn more about Crawdad for Enterprise →Centralized management introduces a trust question: what stops the central admin from weakening protection? Crawdad answers it with cryptography, not policy.
Ed25519-signed enforcement floors ensure that critical protections — credential exfiltration detection, PII scanning — cannot be disabled from the console. The floor is cryptographic, not a policy toggle.
Every console action, every device state change, every policy update is logged to a Merkle-chained audit trail. Tamper-evident by construction — not by promise.
The console communicates with devices via Ed25519-signed commands. Devices verify the signature before executing. No unsigned instruction reaches the sidecar.
Request a walkthrough. We'll show you Fleet Console with your fleet size and deployment model in mind.