Provisioning now
| Serial | Phase | Progress | Updated |
|---|
Unlock this device
Enter the tenant passphrase to load the private key into this browser session.
First-time setup (admin): create the tenant key →
Create tenant key (admin)
Generates an RSA keypair in your browser. The private key is wrapped with this passphrase and stored encrypted — the server cannot decrypt it. If the passphrase is lost it cannot be recovered (set up Shamir break-glass per SECURITY.md).
Lost the passphrase? Break-glass recovery →
Break-glass recovery (admin)
Paste the recovery shares (one per line — at least the threshold count) and set a new passphrase. The shares reconstruct the recovery key in your browser; the server only holds ciphertext.
Machines
| Serial | Name | Model | Last run | Baseline / drift | Client | Last seen |
|---|
Audit log
| When | Actor | Action | IP |
|---|
Clients
Recent activity (last 14 days)
Click a customer to open its workspace — machines, users, tokens, branding and licensing all live inside.
| Name | Machines | Active seats | Seat limit | Users | Created |
|---|
Add client
Your branding (white-label — applies to this portal)
Product name and accent colour apply to everyone in your account on next load.
Billing (seats across all your clients)
Loading…
| Invoice | Status | Amount | Date |
|---|
Notifications (weekly email digest)
API keys (programmatic access — authenticates as partner admin)
Use as Authorization: Bearer tpk_…. Scoped to your account; shown once on creation.
| Prefix | Label | Status | Created |
|---|
Customer
Overview (last 500 runs)
Loading…
Client settings
Machines (this client)
| Serial | Name | Status | Drift | Last seen |
|---|
Hardware inventory (search the fleet)
| Machine | Make | Model | CPU | RAM | Disk | OS | OS ver |
|---|
Patch status (last-patched per machine)
| Machine | Last patched | Age | Hotfixes |
|---|
Software inventory (installed apps across the fleet)
| App | Machine / count | Version |
|---|
Remote commands (runs on the machine's next check-in)
| Serial | Command | Status | Queued |
|---|
Scheduled maintenance (recurring — fires on all active machines)
| Command | When | Last run |
|---|
Provisioning profiles (what a build installs & configures)
Define reusable setups for this customer, then pick one when you request a build.
| Name | Updated |
|---|
New profile
Profile
Naming
pattern<prefix>{serial}
Local admin
Cleanup
Apps
Security
Updates & drivers
Windows edition
Domain join
Wi-Fi (optional)
Locale
Builds (pre-built, ready-to-download images for this customer)
Request a self-contained provisioning EXE, or a bootable USB/ISO, with this customer's config and a scoped token baked in. A build runner produces it; download it here when ready.
| Label | Kind | Status | Size | Requested |
|---|
Licensing (seats = machines active in last 30 days)
Users
| Role | Added |
|---|
API tokens (for the provisioning engine — set as TOTL_API_TOKEN)
| Prefix | Label | Status | Created |
|---|
Sign-in / SSO (public multi-tenant — WorkOS / Auth0)
Map this customer's identity to their tenant. On first SSO login a user is created automatically with the role below. Match by the broker's org id or by email domain.
| Match | Value | Role | Added |
|---|
Webhooks (notify Slack / Teams / PSA on events)
POSTs a signed JSON payload to your URL. Verify the X-Totl-Signature header (HMAC-SHA256 of the body) with the secret shown on creation.
| URL | Events | Format |
|---|
White-label branding
Rebrand the portal for this customer: product name and accent colour apply on next load.
Audit log (this client)
| When | Actor | Action | IP |
|---|
Break-glass recovery (your tenant's key — requires your passphrase)
Add M-of-N offline recovery to the existing tenant key without re-keying. Requires the current passphrase; shares are shown once for offline custodians.