You bought the endpoint agent. Is it actually on everything?
See which laptops are actually missing endpoint protection, device management or web gateway, reconciled against who still works at your company. Merges CrowdStrike, SentinelOne, Intune, Jamf, Kandji and Zscaler into one coverage matrix.
Three signals, one device
Endpoint protection (EDR)
Is the agent installed, and is it actually healthy? An agent that is present but not reporting is not protection.
CrowdStrike Falcon, SentinelOne
Device management (MDM)
Is the device enrolled and checking in, and is the disk encrypted? A device that stopped checking in months ago is a stale record, not a managed machine.
Microsoft Intune, Jamf Pro, Kandji
Web gateway (SWG)
Is the device enrolled in the gateway that is supposed to be filtering its traffic?
Zscaler Client Connector
Four states, not two
- Covered: A connected source confirms the capability is present and healthy on this device.
- Gap: A source that can see this device says the capability is missing. This is real, and it opens work.
- Unknown: The device exists on the roster but no connected source can speak to it. Visibly unknown, never quietly passed.
- Not deployed: You do not run a tool in this category at all. Excluded from scoring entirely, because a tool you never bought is not a failure.
How it works
- Connect what you run: Read-only credentials for the endpoint, device-management and gateway tools already in place. Nothing is installed on the devices themselves.
- Devices are merged: The same laptop seen by three tools under three different names becomes one canonical device, matched on serial, hostname and the signed-in user.
- Reconciled against the roster: Every device is matched back to the personnel roster synced from your identity provider, so a machine belonging to someone who left surfaces immediately.
- Gaps become work: A genuine gap opens an issue with an owner and a due date, and closes itself when the next run sees the fix.
Questions, answered
How do I check which devices are missing endpoint protection?
Connect your EDR, device-management and web-gateway tools to Proofsteady with read-only credentials. It merges their device lists into one canonical set, reconciles that against your personnel roster, and shows per device which of the three capabilities is present, missing, or unverifiable. Genuine gaps open a remediation issue with a due date.
Can you verify EDR is actually installed rather than just licensed?
Yes. Coverage is read from the EDR platform's own device inventory, so it reflects agents that have actually registered and are reporting, not seats purchased. An agent that is installed but unhealthy is reported separately from one that is absent.
What is device coverage in security compliance?
Device coverage is the proportion of your real devices that carry the security controls you claim to operate, such as endpoint protection, device management and disk encryption. Auditors sample it for SOC 2 and ISO 27001 because a policy requiring endpoint protection means nothing if a third of the fleet does not have it.
What happens if we do not use a web gateway at all?
That capability is marked not deployed and excluded from scoring. Proofsteady does not invent a gap for a category of tool you never bought, and it does not quietly pass it either. Only tools you actually run are scored.
How do you find devices belonging to people who have left?
Devices are reconciled against the personnel roster synced from your identity provider. When someone is marked terminated, any device still reporting under their name surfaces as an offboarding gap, which is the population an access-review auditor asks to see.
Which endpoint and device tools does Proofsteady support?
Endpoint protection from CrowdStrike Falcon and SentinelOne, device management from Microsoft Intune, Jamf Pro and Kandji, and web gateway enrollment from Zscaler Client Connector. All are read-only connections.