New:System Graph 2.0See System Graph 2.0
Enterprise resource

Endpoint Agent Security Checklist

Security and IT review checklist for outbound endpoint agents on desktop, VDI, and segmented networks.

Checklist

  • Confirm outbound-only connectivity and firewall rules
  • Document agent identity and certificate rotation
  • Define capability matrix per environment
  • Review local evidence storage and retention
  • Validate redaction for screenshots and logs
  • Test desktop or VDI target application
  • Verify PAM integration for credentials
  • Check agent upgrade and rollback procedure
  • Inventory stale or offline agents
  • Map hybrid web/desktop journey coverage
  • Review Citrix/VDI session constraints
  • Validate signed capsule verification on agent
  • Confirm no inbound ports to protected networks
  • Audit trail sample for runs and denials
  • Segregation of duties for agent admin roles
  • Emergency disable/kill-switch procedure
  • Data residency alignment for local artifacts
  • Pen-test scope for agent binary integrity
  • Operational monitoring and alerting hooks
  • Representative workflow documented for security review

Related guides

01The operational surface

One surface for posture, operations, and what needs attention next.

The Zof home is not a marketing dashboard. It is the operational surface engineering, QA, and SRE teams use every day, quality posture, in-flight runs, coverage by module, and the actions a leader should look at next.

OPERATIONAL KPIs

  • Runs
  • Coverage
  • Risk

Live across every environment you ship to.

WORK SPINE

  • Specs
  • Tests
  • Schedules

From specification to scheduled regression.

GUARDRAILS

  • RBAC
  • SSO
  • audit

Every action attributable to a named human.

STAGING · LIVE/home
Zof AI home command center showing 12 runs at 94% pass, 3 open critical issues, 84% coverage, four module traceability bars, the specification pipeline, upcoming schedules, and recommended next actions with an active-runs sidebar.
Home view · Checkout Service · Staging · captured live from the product.
  • 01 · RUNS · 24H

    94% pass

    12 runs across staging

  • 02 · COVERAGE

    84%

    Across four modules

  • 03 · ACTIVE RUNS

    3 running

    Live on this branch

  • 04 · NEXT ACTIONS

    Recommended

    Triage gaps, new spec

Endpoint Agent Security Checklist | Zof AI