Most practices carry a device count in the payroll system, a second one in whichever tool got installed last, and a third that exists only in somebody's head. These four entries replace all three with one book: the hardware that exists, the condition each item is in, and whatever has gone silent.
Every control in this book is priced against a unit, so each of them rests on the practice knowing how many units exist. That figure is usually wrong, and wrong in the same direction every time: the machine bought in a rush, the laptop that went home with a leaver, the handset added to the mail tenant without a word to anybody.
N-able N-sight produces the figure and then keeps it honest, because hardware that stops checking in turns into an item on a list rather than a silent absence. Addigy does the equivalent for Apple hardware, which behaves differently enough to deserve tooling of its own instead of a checkbox.
Patching is unglamorous and it is where most of the difference gets made. The entry schedules it, applies it, and then confirms it, and confirmation is the part that counts, because a patch policy nobody verifies is a document rather than a control.
The filtering rides the agent already there, which is how a control leaves the building inside a laptop bag. The mobile entry covers whatever your staff read client mail on, which is an endpoint whoever bought it and whatever any policy says about it.
Billing hands over every figure below at page load. Present while you read; a quantity stands until you alter it.
Patching, health, inventory, scripting, and remote hands carried on one agent. A machine nobody observes is a machine nobody can honestly describe as patched.
| Settles on | N-able N-sight agent, installed once per machine |
|---|---|
| Nets | One managed device, observation and patching on one unit |
| Value date | Inventory lands the day the agent enrolls |
| Cleared by | The patch schedule is held by Fortify 24x7 engineers |
| Reconciled by | Patch and inventory reporting, dated per device |
Resolution and web requests are filtered at the device, which is why the control goes home in the bag instead of halting at your office door. Nothing needs racking.
| Settles on | N-able N-sight agent with filtering enabled |
|---|---|
| Nets | One managed device, on your network or well away from it |
| Value date | Applies from the first policy push onward |
| Cleared by | Category policy is held by Fortify 24x7 engineers |
| Reconciled by | Request and refusal records, device by device |
Apple hardware managed rather than taken on trust. Configuration is enforced, updates are scheduled, and a device is either compliant or it is named on a list.
| Settles on | Addigy, one enrollment for each Apple device |
|---|---|
| Nets | One Apple device, configuration and updates on one unit |
| Value date | Applies at the first enrollment check in |
| Cleared by | Configuration is held by Fortify 24x7 engineers |
| Reconciled by | Per device compliance state, carrying a date |
Whoever paid for it, a phone that client mail gets read on is an endpoint. This entry runs detection on the handset instead of trusting the platform to have covered it.
| Settles on | Zimperium, one app for each handset |
|---|---|
| Nets | One mobile device, practice owned or personal |
| Value date | Opens when the handset activates the app |
| Cleared by | Handset findings are read by Fortify 24x7 analysts |
| Reconciled by | Handset findings, filed with the rest of your record |
The device book tells you what exists and holds it in a known condition. What it will not do:
Heads up: card statements show FORTIFY 24X7 - FinShield Tech is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.