CrossTenant
Home / Features / Device lifecycle

Device lifecycle

Every managed device across every customer: inventoried, actionable, and behind confirmation flows. ChromeOS, mobile, workstations, and managed Chrome browsers in one place, read live from Google's APIs.

Prefer email? Get in touch and we run onboarding with you.

What's included

ChromeOS fleet

Every enrolled ChromeOS device across your customers in one inventory: serial, model, OS version, and sync state. Device actions run from the same list, each behind an explicit confirmation.

chromeos last sync device actions

Mobile devices

Approve, block, or wipe mobile devices without switching into each customer's Admin console. Every action asks for explicit confirmation before it runs. Nothing fires on a misclick.

approve block wipe

Workstations

An endpoint inventory that merges Google's mobile-device and Cloud Identity records into one workstation view, deduplicated so the same machine never appears twice.

cloud identity deduplicated

Managed Chrome browsers

See each customer's Chrome Browser Cloud Management fleet, read-only: enrolled browsers and the machines they run on, alongside the rest of the device estate.

cbcm read-only

Cross-tenant device search

Find a device without knowing which customer owns it: at the all-tenants scope the device pages aggregate every fleet, and each row is tagged with its owning tenant.

all tenants per-tenant rows

Security actions audited

Wipe and deprovision-class actions are recorded in the per-tenant audit log: a tamper-evident, hash-chained record of who did what, where, and when.

hash-chained audit log

Two device sources depend on a switch at the customer's end rather than on CrossTenant. Chrome browser fleet data needs Chrome Enterprise Core, which is free to enrol in the Google Admin console. Endpoint data from Cloud Identity is an optional read-only grant, deliberately left out of first consent so an operator turns it on only when they want the wider Windows, macOS, and Linux coverage. Where either is off, the page stays visible and names the missing source and the way to enable it, rather than hiding the feature or showing an empty list as though it were a clean one.

Device lifecycle

Run every fleet from one screen

Device data is read live from Google's APIs the moment a customer is connected: no customer content stored at rest, no agent to deploy.