Official Deployment Guide

Deploy GuardSphere with confidence.

Plan and complete a GuardSphere deployment across ChromeOS, Android, Windows, or a mixed device environment.

This guide explains the journey from deployment preparation and Device Agent installation through enrollment, policy synchronization, verification, and ongoing governance. It is designed for families, schools, enterprises, institutions, and other authorized organizations managing supported devices.

What this guide covers

One deployment reference for every supported environment.

ChromeOS-only deployment
Android-only deployment
Windows-only deployment
Mixed platform deployment
Supported enrollment methods
Pilot verification and production rollout

Detailed, organization-specific deployment progress remains available in the authenticated GuardSphere Deployment Assistant after an organization account has been created.

Start here

Choose your deployment scenario.

Select the path that matches the devices you plan to manage. Organization type does not limit platform choice. A family, school, enterprise, or institution may deploy any supported platform that fits its environment.

01Managed Chromebooks

ChromeOS deployment

Deploy the GuardSphere ChromeOS Extension centrally through Google Workspace using Force Install.

After installation, an authorized school administrator or delegated IT staff member opens the extension on each managed Chromebook and completes enrollment before the device is issued to a student.

02Android phones and tablets

Android deployment

Install the GuardSphere Android Device Agent and enroll each device into the appropriate GuardSphere organization and group.

GuardSphere supports multiple enrollment methods. The detailed Android section explains how administrators choose the appropriate method for their rollout.

03Windows computers

Windows deployment

Install the GuardSphere Windows Device Agent and complete enrollment before the computer enters active use.

Windows deployment can be used by families, schools, enterprises, institutions, and other supported organization types.

04Multiple device platforms

Mixed deployment

Deploy ChromeOS, Android, and Windows devices within the same GuardSphere organization.

A mixed deployment provides one administrative environment for device visibility, policy assignment, governance, reporting, and operational review.

Deployment lifecycle

A controlled path from preparation to ongoing operation.

Although installation differs by platform, every successful GuardSphere rollout follows the same operational lifecycle. Administrators should verify a pilot deployment before expanding to larger groups of devices.

01

Prepare

Confirm organization access, administrators, groups, users, device capacity, and rollout responsibilities.

02

Install

Install the correct GuardSphere Device Agent or centrally deploy the ChromeOS Extension.

03

Enroll

Connect each device to the correct GuardSphere organization and deployment group.

04

Verify

Confirm that the device appears correctly, checks in, receives policy, and begins reporting expected signals.

05

Operate

Review policy activity, device health, governance information, reporting, and rollout readiness.

06

Improve

Refine policies and expand deployment only after the pilot environment behaves as expected.

Device enrollment

Choose a supported enrollment method.

GuardSphere administrators create enrollment access from the device enrollment page. The administrator chooses the method that fits the device, rollout size, and operational environment.

The currently available methods are QR, Link, Code, Email, and NFC. Because NFC is marked as not reliable in the current product, it should not be treated as the primary method for a production deployment.

Enrollment is separate from installation

Installing the GuardSphere Device Agent or ChromeOS Extension does not by itself connect the device to an organization. Enrollment completes that connection and should be verified before the device enters normal use.

01Available

QR

Creates a QR-based enrollment option that can be used during device enrollment.

02Available

Link

Creates a link-based enrollment option that can be opened on the device being enrolled.

03Available

Code

Creates a code-based enrollment option for workflows where an enrollment code is entered on the device.

04Available

Email

Creates an email-based enrollment option for delivering enrollment access through email.

05Not reliable

NFC

NFC appears as an available enrollment method in GuardSphere, but it is currently marked as not reliable and should not be the primary production enrollment method.

Current guidance: Use QR, Link, Code, or Email for a production rollout unless NFC reliability has been separately verified for the intended deployment.

Administrator responsibility

Complete enrollment before handing over the device.

For managed environments, an authorized administrator or delegated deployment staff member should complete and verify enrollment. This reduces the risk that a device is issued without being connected to GuardSphere.

Recommended enrollment sequence

  1. 1Create the appropriate groups before enrollment.
  2. 2Create an enrollment invite for the intended platform.
  3. 3Choose QR, Link, Code, Email, or another verified method.
  4. 4Associate the invite with the correct group where applicable.
  5. 5Complete enrollment on the target device.
  6. 6Confirm the device appears and begins checking in.
Next section

ChromeOS deployment

Continue to the ChromeOS deployment guide for Google Workspace Force Install, administrator-led enrollment, pilot verification, and the rollout sequence for managed Chromebooks.

Continue to ChromeOS
ChromeOS deployment

Deploy GuardSphere to managed Chromebooks.

The recommended ChromeOS deployment path is centralized installation through Google Workspace. The school or organization uses Google Workspace Admin to force-install the GuardSphere ChromeOS Extension on managed Chromebooks.

Force installation places the extension on the Chromebook, but the device must still be enrolled into the correct GuardSphere organization and group. An authorized administrator or delegated IT staff member should complete and verify that enrollment before the device is issued to a student or other user.

Deployment sequence

Complete the rollout in controlled stages.

Prepare groups and policies before enrolling devices. Begin with a small pilot, verify that the extension and GuardSphere telemetry are operating correctly, and only then expand deployment to additional organizational units or Chromebook groups.

01

Prepare the GuardSphere organization

Create the organization, confirm access, create the required groups, add administrators, and prepare policies before deploying the extension.

02

Prepare Google Workspace

Confirm that the Chromebooks are enterprise-enrolled and placed in the correct Google organizational units for the intended rollout.

03

Force-install the extension

Use Google Workspace Admin to deploy the GuardSphere ChromeOS Extension to the selected organizational unit.

04

Open the installed extension

An authorized administrator or delegated IT staff member should open the installed GuardSphere extension on each managed Chromebook.

05

Complete device enrollment

Enroll the Chromebook into the correct GuardSphere organization and group using a supported enrollment method.

06

Verify the device

Confirm that the Chromebook appears in GuardSphere, checks in, receives the intended policies, and begins reporting the expected browser and domain signals.

07

Complete a pilot rollout

Test the deployment with a limited class, grade, staff group, or Chromebook cart before expanding to the full fleet.

Administrator-led enrollment

Do not rely on students to enroll managed Chromebooks.

The administrator or delegated deployment staff should open the installed extension and complete enrollment on every managed Chromebook. This ensures that the device is connected to GuardSphere and protected by the intended policies before normal student use.

Force installation and GuardSphere enrollment are separate stages. The presence of the extension alone does not confirm that the Chromebook has been enrolled into the organization.

Verification checklist

Confirm deployment before expanding the rollout.

The extension is visible on the managed Chromebook.
The device appears on the GuardSphere Devices page.
The device is assigned to the intended GuardSphere group.
The device reports a recent last-seen time.
The intended policy is associated with the device or its group.
Browser or domain activity begins appearing where enabled.
Policy decisions and review activity begin appearing where applicable.
Important distinction

Google Workspace deployment does not replace GuardSphere enrollment.

Google Workspace

Delivers and maintains the GuardSphere ChromeOS Extension on the selected managed Chromebooks.

GuardSphere enrollment

Connects the Chromebook to the correct GuardSphere organization, group, policies, device record, and administrative workflow.

Next deployment scenario

Android deployment

Continue to the Android deployment guide to compare DPC and normal deployment, review supported enrollment choices, verify the device, and complete a controlled pilot rollout.

Continue to Android
Android deployment

Choose the Android management model that fits the device.

GuardSphere supports two Android deployment approaches: DPC deployment and normal Device Agent deployment. The correct choice depends on who owns the device, how much management authority the organization requires, and what level of control has been authorized.

DPC deployment is intended for fully managed devices. Normal deployment is intended for environments that require GuardSphere protection and reporting without giving GuardSphere full management authority over the Android operating system.

Android deployment modes

Select the level of Android management required.

Review both options before beginning the rollout. The selection should be based on device ownership and authorized management needs, not simply on which option provides the most control.

Full device management

DPC deployment

D

GuardSphere operates as the Device Policy Controller and receives full management authority over the enrolled Android device.

Appropriate for

Organization-owned or fully managed Android devices where the administrator requires strong control over the device.

Deployment characteristics

Strong device-level policy enforcement
Administrative control over the managed device
GuardSphere cannot be removed by the device user without an administrator uninstall code
Suitable for controlled organizational deployments

Important: Choose this mode only when the organization is authorized to fully manage the device and users have been informed of the management arrangement.

Standard device agent

Normal deployment

N

GuardSphere is installed as a standard Android Device Agent and uses the permissions enabled for that deployment.

Appropriate for

Devices where GuardSphere should provide protection, policy enforcement, and reporting without taking full management control of the Android operating system.

Deployment characteristics

Standard GuardSphere enrollment
Policy synchronization and supported enforcement
Reporting based on enabled permissions
Appropriate for lighter-control and consent-based deployments

Important: The available protection and reporting depend on the permissions granted and the capabilities enabled on the device.

DPC protection

DPC deployment prevents unauthorized removal.

In a GuardSphere DPC deployment, the user cannot uninstall the Device Agent without an administrator-provided uninstall code. This helps ensure that a fully managed device remains under the organization's approved management and protection.

Device user

Cannot independently remove GuardSphere from the fully managed device.

Administrator

Authorizes removal by providing the appropriate administrative uninstall code.

Audit expectation

Security-sensitive removal actions should remain administrator-authorized and auditable.

Deployment responsibility

The organization must ensure that full device management is authorized and appropriate.

DPC deployment sequence

Fully managed Android rollout

01

Confirm full-management authority

Confirm that the organization owns or is authorized to fully manage the Android device before beginning DPC enrollment.

02

Prepare groups and policies

Create the intended GuardSphere group and assign the required policies before enrolling the device.

03

Install or provision GuardSphere

Begin the supported GuardSphere DPC installation or managed-device provisioning process on the target Android device.

04

Complete enrollment

Connect the device to the correct GuardSphere organization and group using a supported enrollment method.

05

Grant required management access

Complete the device-management and permission setup required by the GuardSphere DPC deployment.

06

Verify protection and telemetry

Confirm that the device appears in GuardSphere, checks in, receives policies, and begins reporting the expected signals.

Normal deployment sequence

Standard Android Device Agent rollout

01

Prepare the organization

Create the intended group, prepare policies, and confirm that the organization has capacity for the Android device.

02

Install the Android Device Agent

Install GuardSphere on the target Android phone or tablet using the available distribution route.

03

Choose an enrollment method

Use QR, Link, Code, Email, or another currently supported and verified enrollment method.

04

Complete device enrollment

Connect the device to the correct GuardSphere organization and group.

05

Enable required permissions

Grant the permissions needed for the intended protection, reporting, location, accessibility, or network-control features.

06

Verify the device

Confirm that the Android device checks in, receives policies, and begins reporting the expected telemetry.

Enrollment options

Installation mode and enrollment method are separate choices.

Choosing DPC or normal deployment determines the Android management model. The administrator must still complete GuardSphere enrollment using a currently supported enrollment method such as QR, Link, Code, Email, or NFC where separately verified.

Android verification checklist

Confirm the selected deployment mode is functioning.

The Android device appears on the GuardSphere Devices page.
The device is assigned to the intended organization and group.
The device reports a recent last-seen time.
The intended policy is assigned and synchronized.
Required Android permissions are enabled for the selected deployment mode.
Expected app, usage, location, network, or policy signals begin appearing where enabled.
For DPC deployments, uninstall protection is confirmed before the device enters normal use.
Next deployment scenario

Windows deployment

Continue to the Windows deployment guide for Device Agent installation, enrollment, service activation, policy synchronization, authorized uninstall, verification, and pilot rollout.

Continue to Windows
Windows deployment

Install, enroll, and verify the GuardSphere Windows Device Agent.

GuardSphere supports managed Windows computers used by families, schools, enterprises, institutions, and other authorized organizations. The Windows deployment path combines the Device Agent, enrollment utility, background service, policy synchronization, and administrator-authorized uninstall workflow.

Installation alone does not complete deployment. The computer must be enrolled into the correct GuardSphere organization, the Windows service must be running, and the administrator must verify that the device is checking in and receiving the intended policy.

Microsoft Store release coming soonCreate organization
Windows deployment architecture

Understand the components installed on the computer.

The Windows deployment uses several cooperating components rather than a single visible application. Administrators should understand these components before testing installation, operation, and authorized removal.

W

Windows Device Agent

The primary GuardSphere component responsible for running the managed-device workload on the Windows computer.

W

Windows service

Runs the GuardSphere background workload, maintains device communication, and supports policy synchronization and reporting.

W

Enrollment utility

Provides the administrator-facing process used to connect the Windows computer to the appropriate GuardSphere organization.

W

Authorized uninstall

Provides the approved administrative path for removing GuardSphere from a managed Windows computer.

W

Uninstall verifier

Supports verification of administrator-authorized removal before protected GuardSphere components are removed.

Windows operating flow

Installation and enrollment activate the managed-device workflow.

After the Windows Agent is installed and enrollment succeeds, the service maintains the device connection, synchronizes applicable policies, and reports supported device information to the GuardSphere platform.

1Install approved Windows package
2Open enrollment utility
3Complete GuardSphere enrollment
4Start or confirm Windows service
5Synchronize assigned policy
6Verify heartbeat and reporting
Deployment sequence

Complete Windows deployment in controlled stages.

Begin with one or a small number of computers. Verify service operation, policy synchronization, reporting, and authorized uninstall before expanding deployment to additional users or groups.

01

Prepare the GuardSphere organization

Confirm organization access, device capacity, groups, administrators, and policies before installing the Windows Device Agent.

02

Install the Windows Device Agent

Install the approved GuardSphere Windows package on the target computer. Public Microsoft Store distribution will be linked when the Store release is available.

03

Open the enrollment utility

Use the GuardSphere Windows Enrollment utility to begin connecting the computer to the correct organization.

04

Complete device enrollment

Use a supported enrollment method and ensure that the device is associated with the intended GuardSphere organization and group.

05

Confirm service activation

Verify that the GuardSphere Windows service is installed, running, and able to communicate with the GuardSphere platform.

06

Verify policy synchronization

Confirm that the computer receives the intended policy and begins reporting heartbeat, device status, and supported enforcement information.

07

Complete a pilot rollout

Validate installation, enrollment, policy behavior, reporting, and authorized uninstall on a small number of computers before wider deployment.

Protected removal

Use the authorized uninstall workflow.

GuardSphere removal from a managed Windows computer should be an administrator-authorized action. The approved uninstall path uses the GuardSphere Authorized Uninstall and verification components rather than relying on direct removal of protected files or services.

Do not test tamper protection by manually deleting GuardSphere files, registry state, or services. Use the supported administrator-authorized workflow so that removal remains controlled and auditable.

Windows verification checklist

Confirm deployment before expanding the rollout.

The GuardSphere Windows package is installed successfully.
The Windows enrollment process completes without error.
The device appears on the GuardSphere Devices page.
The device is connected to the correct organization and group.
The GuardSphere Windows service is installed and running.
The device reports a recent heartbeat or last-seen time.
The intended policy is assigned and synchronized.
Expected Windows policy and device signals begin appearing where enabled.
The authorized uninstall path is tested before wider rollout.
Troubleshooting approach

Inspect the current state before reinstalling.

A missing device, delayed check-in, or policy issue does not always require reinstallation. Confirm enrollment, service state, organization assignment, network communication, and policy assignment first.

Device does not appear

Confirm enrollment completed successfully and that the device was connected to the intended organization.

Service is not running

Check that installation completed correctly and confirm the GuardSphere Windows service state.

No recent check-in

Confirm network access, service activity, and the device enrollment state before reinstalling anything.

Policy is not applied

Confirm that the device or its group has the intended policy assignment and that synchronization has completed.

Uninstall is blocked

Use the administrator-authorized uninstall workflow rather than attempting to remove protected components directly.

Next deployment scenario

Mixed platform deployment

Continue to the mixed deployment guide to coordinate ChromeOS, Android, and Windows within one GuardSphere organization using shared groups, policies, enrollment planning, verification, and phased rollout.

Continue to mixed deployment
Mixed platform deployment

Manage ChromeOS, Android, and Windows in one organization.

A mixed deployment brings supported device platforms into the same GuardSphere organization while preserving the correct installation, enrollment, verification, and operating process for each platform.

GuardSphere groups and policies provide shared organizational structure, but platform-specific deployment differences still matter. ChromeOS uses Google Workspace deployment, Android requires a choice between DPC and normal deployment, and Windows uses the Windows Device Agent and service architecture.

Unified operating model

Different device platforms, one GuardSphere control environment.

Each supported platform follows its own installation and verification path, then reports into the same organization for device visibility, policy assignment, governance, and operational review.

1ChromeOS Extension
2Android Device Agent
3Windows Device Agent
4GuardSphere organization
5Shared groups and policies
6Unified administration and reporting
Platform deployment paths

Preserve the correct workflow for each operating system.

A mixed deployment should not collapse every platform into one generic checklist. Complete installation, enrollment, and verification according to the actual requirements of each platform.

ChromeOS
Installation

Deploy the GuardSphere ChromeOS Extension through Google Workspace Force Install.

Enrollment

An authorized administrator or delegated IT staff member opens the extension and completes enrollment.

Verification

Confirm extension presence, device registration, recent activity, policy assignment, and browser or domain reporting where enabled.

Android
Installation

Choose DPC deployment or normal Device Agent deployment based on ownership and authorized management requirements.

Enrollment

Complete enrollment using one of the currently supported enrollment methods.

Verification

Confirm permissions, policy synchronization, recent activity, expected telemetry, and uninstall protection where DPC is used.

Windows
Installation

Install the GuardSphere Windows Device Agent using the approved distribution package.

Enrollment

Use the Windows enrollment utility to connect the computer to the correct organization and group.

Verification

Confirm service operation, heartbeat, policy synchronization, reporting, and the administrator-authorized uninstall path.

Mixed rollout sequence

Roll out by platform and group in controlled phases.

The safest mixed deployment starts with accurate inventory, organization structure, and separate platform pilots. Expand only after each deployment path has been independently verified.

01

Map the device environment

Identify which ChromeOS, Android, and Windows devices will be managed, who owns them, and which groups or departments they belong to.

02

Create shared organization structure

Create GuardSphere groups that reflect classes, departments, households, teams, locations, or device ownership before enrollment begins.

03

Prepare policies

Create and assign policies at the organization or group level while accounting for platform-specific enforcement differences.

04

Choose each platform path

Use Google Workspace for ChromeOS, select DPC or normal deployment for Android, and install the Windows Device Agent for Windows computers.

05

Create platform-specific enrollment invites

Generate enrollment access for the correct platform and group rather than using one unstructured invite for the entire rollout.

06

Run separate pilot groups

Verify a small ChromeOS, Android, and Windows pilot before combining the results into a broader production rollout.

07

Verify unified visibility

Confirm that devices from every platform appear in the same organization with correct groups, policies, health, and recent activity.

08

Expand in controlled phases

Roll out by platform, group, department, class, household, or location only after the corresponding pilot is stable.

Policy planning

Share policy intent without assuming identical enforcement.

GuardSphere policies belong to the organization and can be assigned to groups and devices. However, the effective behavior of a policy may depend on the capabilities and permissions available on the target operating system.

Verify the actual result on each platform before treating a policy as production-ready for the entire mixed fleet.

Mixed deployment verification

Confirm every platform and the unified organization view.

All expected platforms appear in the same GuardSphere organization.
Every device is assigned to the correct organization and group.
Platform-specific installation and enrollment steps were completed.
Each device reports a recent last-seen or heartbeat time.
Policies are assigned at the correct organization, group, or device scope.
Expected telemetry appears for each platform where enabled.
ChromeOS, Android, and Windows pilot groups were verified independently.
Administrators understand the removal and uninstall model for each platform.
The production rollout is divided into manageable phases.
Common mixed-deployment risks

Avoid shortcuts that make a multi-platform rollout difficult to govern.

Mixed environments become difficult when platform differences, ownership, group structure, and verification are ignored. Preserve clear deployment boundaries even though administration is unified.

One invite for every device

Avoid using a single unstructured enrollment invite across unrelated platforms and groups. Separate invites make assignment and troubleshooting clearer.

Assuming identical enforcement

A shared policy model does not mean every operating system enforces every control in exactly the same way.

Scaling before platform verification

A successful ChromeOS pilot does not automatically confirm that Android or Windows deployment is ready.

Ignoring device ownership

Especially on Android, device ownership and authorized management level determine whether DPC or normal deployment is appropriate.

Mixing unassigned devices

Create groups before enrollment so devices do not accumulate without clear policy or administrative ownership.

Treating installation as completion

Every platform still requires enrollment, policy synchronization, recent activity, and operational verification.

Next guide section

Pilot verification and production rollout

Continue to the shared verification framework for all deployment scenarios, including pilot readiness, device check-in, policy confirmation, telemetry review, rollout approval, and production expansion.

Continue to rollout verification
Pilot verification and production rollout

Verify a small deployment before expanding to production.

A successful GuardSphere deployment is not measured only by whether the Device Agent or Extension was installed. Administrators must confirm enrollment, device communication, policy behavior, reporting, permissions, and operational readiness before expanding to a larger device population.

The pilot should be small enough to troubleshoot safely but realistic enough to represent the intended production environment. Mixed deployments should maintain separate platform checks even when the devices belong to the same organization.

Pilot sequence

Move from preparation to production approval in controlled stages.

Complete each stage before treating the pilot as production-ready. Do not allow a successful installation to hide unresolved enrollment, policy, telemetry, permission, or support problems.

01

Define the pilot

Choose a limited class, department, household group, staff group, location, device cart, or small device set that represents the intended production environment.

02

Prepare structure and policy

Create the required groups, managed people, administrators, scopes, policies, and assignments before enrolling the pilot devices.

03

Install and enroll

Complete the correct platform-specific installation and enroll every pilot device into the intended GuardSphere organization and group.

04

Confirm device communication

Verify that every pilot device appears in GuardSphere, reports a recent last-seen or heartbeat time, and remains connected during normal use.

05

Verify policy behavior

Confirm that intended policies synchronize and that allowed, blocked, scheduled, or monitored activity behaves as expected on each platform.

06

Review reporting and evidence

Inspect device activity, logs, policy decisions, telemetry, governance information, and reports that apply to the selected deployment.

07

Resolve pilot issues

Correct enrollment, group assignment, permission, service, policy, reporting, or operational problems before approving expansion.

08

Approve production rollout

Expand only after the responsible administrator confirms that the pilot is stable, documented, supportable, and appropriate for broader deployment.

Before pilot enrollment

Confirm deployment readiness.

These checks should be completed before the first pilot device is enrolled.

The organization account has active access for the planned deployment.
The available device allowance supports the pilot and the next rollout phase.
Groups are created before devices are enrolled.
Managed people and responsible administrators are added where required.
Administrator roles and scopes are appropriate for the pilot.
Policies are created and assigned to the intended groups or devices.
The correct installation path has been selected for each platform.
Enrollment invites are associated with the intended platform and group.
Users, administrators, and custodians understand the deployment model.
Before production expansion

Confirm pilot success.

These checks provide evidence that the pilot is stable enough for the next rollout phase.

Every expected pilot device appears in the GuardSphere Devices page.
Each device is connected to the correct organization and group.
Every device reports a recent last-seen or heartbeat time.
The intended policies are assigned and synchronized.
Expected enforcement behavior has been tested.
Expected logs, telemetry, or reporting signals are appearing where enabled.
Platform-specific permissions or services are operating correctly.
Authorized uninstall or removal paths are understood and verified where applicable.
No unresolved issue would become more difficult after wider rollout.
Production rollout model

Expand by evidence, not by assumption.

Each rollout phase should produce enough operational evidence to justify the next one. Device count should increase only after the current group is stable and supportable.

Phase 1

Technical pilot

Deploy to a very small number of devices managed by administrators or trusted pilot users. Confirm installation, enrollment, check-in, policy synchronization, and reporting.

Phase 2

Operational pilot

Expand to one representative group, class, department, family group, device cart, or location. Observe normal use and resolve operational issues.

Phase 3

Controlled expansion

Add more groups or locations in manageable batches. Review device health, policy behavior, and support demand after each batch.

Phase 4

Production rollout

Complete the wider deployment only after earlier phases are stable and administrators can support enrollment, verification, policy review, and authorized removal.

Phase 5

Ongoing governance

Continue reviewing device status, policy outcomes, logs, governance evidence, usage insight, reports, and changing organizational needs.

Rollout hold conditions

Pause expansion when the deployment state is uncertain.

A temporary pause is safer than multiplying an unresolved issue across many devices. Investigate and verify the current state before adding another rollout group.

Devices are missing

Pause expansion if expected devices do not appear in GuardSphere after enrollment.

Check-in is unreliable

Do not expand while devices have inconsistent heartbeat, last-seen, or service activity.

Policies are unclear

Pause if administrators cannot confirm which policy applies or why a device is behaving differently from expectations.

Telemetry is incomplete

Do not rely on reports or governance conclusions until the expected platform signals are actually appearing.

Permissions are inconsistent

Resolve missing Android permissions, ChromeOS extension state, Windows service issues, or other platform-specific setup differences.

Removal is not understood

Administrators should understand authorized uninstall and unenrollment before a protected deployment is expanded.

Ongoing operation

Deployment continues after enrollment.

Device governance requires regular review. Administrators should confirm that devices remain connected, policies remain appropriate, reporting remains useful, and new operational risks are addressed.

The authenticated Deployment Assistant provides organization-specific progress tracking and readiness detection after an organization has been created.

Weekly operational review

Review the deployment as an operating system, not a one-time project.

1Review recently seen and offline devices.
2Confirm new devices joined the correct groups.
3Review policy assignments and recent policy decisions.
4Investigate unexpected blocked or allowed activity.
5Review app, domain, usage, location, or device signals where enabled.
6Check governance, review queues, compliance, or workforce information where available.
7Review failed enrollment, reporting, or support cases.
8Document required policy or deployment adjustments.
Next guide section

Frequently asked questions

Continue to answers about installation, enrollment, platform choice, administrator responsibility, device ownership, mixed environments, authorized uninstall, pilot rollout, and the authenticated Deployment Assistant.

Continue to questions
Frequently asked questions

Common GuardSphere deployment questions.

Review answers about platform choice, installation, enrollment, administrator responsibility, device ownership, Android management, Chromebook deployment, Windows removal, mixed fleets, pilot verification, and production rollout.

Need organization-specific guidance?

Continue inside the Deployment Assistant.

After creating an organization, authenticated administrators can use live readiness checks, saved progress, and direct links to the tools required for their actual rollout.

Documentation principle

This guide documents verified GuardSphere deployment behavior. Product capabilities, store availability, permissions, and deployment workflows should be updated here whenever the actual implementation changes.

Deployment answers

Select a question to view the answer.

26 questions
01

Which GuardSphere deployment scenario should I choose?

Choose according to the devices you need to manage. Use the ChromeOS path for managed Chromebooks, the Android path for Android phones and tablets, the Windows path for Windows computers, and the mixed deployment path when one organization manages more than one supported platform.

02

Does my organization type limit which platforms I can deploy?

No. Platform choice is based on the devices being managed, not only on organization type. A family may manage Android and Windows devices, a school may manage ChromeOS, Android, and Windows devices, and an enterprise or institution may also operate a mixed fleet.

03

Is installing the Device Agent or Extension enough?

No. Installation places the GuardSphere software on the device, but enrollment connects that device to the correct GuardSphere organization and group. Administrators must also verify device check-in, policy synchronization, and expected reporting before considering deployment complete.

04

Which enrollment methods are currently available?

The current GuardSphere device enrollment page provides QR, Link, Code, Email, and NFC. NFC is marked as not reliable in the current product and should not be treated as the primary method for a production rollout unless it has been separately verified for the intended environment.

05

Should students enroll managed Chromebooks themselves?

No. After the GuardSphere ChromeOS Extension is force-installed, an authorized school administrator or delegated IT staff member should open the extension and complete enrollment on each managed Chromebook before the device is issued to a student.

06

Does Google Workspace Force Install automatically enroll a Chromebook in GuardSphere?

No. Google Workspace delivers and maintains the ChromeOS Extension on selected managed Chromebooks. GuardSphere enrollment is a separate step that connects the Chromebook to the correct organization, group, policies, device record, and administrative workflow.

07

Can a school deploy GuardSphere without Google Workspace?

The documented centralized ChromeOS deployment path uses Google Workspace Force Install for managed Chromebooks. Android and Windows devices follow their own deployment paths. Any alternative ChromeOS installation workflow should be verified against the current product and the school's device-management environment before rollout.

08

What is the difference between Android DPC and normal deployment?

DPC deployment gives GuardSphere full device-management authority and is intended for devices the organization is authorized to fully manage. Normal deployment installs GuardSphere as a standard Device Agent and provides protection, enforcement, and reporting according to the permissions and capabilities enabled on the device.

09

When should Android DPC deployment be used?

Use DPC deployment when the device is organization-owned or otherwise authorized for full management, and when the organization requires stronger device-level control and protected removal. The organization should confirm ownership, authority, user notice, and operational responsibility before selecting this mode.

10

Can a user uninstall GuardSphere from an Android DPC device?

A user cannot uninstall GuardSphere from a DPC-managed device without an administrator-provided uninstall code. Removal should remain an administrator-authorized and auditable action.

11

What determines the capabilities of normal Android deployment?

Normal Android deployment depends on the permissions granted and the product capabilities enabled on the device. Administrators should verify the intended protection, policy, usage, accessibility, location, network, and reporting behavior during the pilot rather than assuming all signals are active.

12

How is GuardSphere removed from a managed Windows computer?

GuardSphere should be removed through the administrator-authorized uninstall workflow. The Windows architecture includes authorized-uninstall and verification components so removal can remain controlled rather than relying on direct deletion of protected files, registry state, or services.

13

Where can I download the Windows Device Agent?

The intended public distribution route is the Microsoft Store. Until the Store release is available, the public Deployment Guide should display Windows as coming soon rather than link visitors to an unavailable listing.

14

Where can I download the Android Device Agent?

The Android Device Agent is intended for Google Play distribution. Until the public Play Store listing is available, the landing page and Deployment Guide should present Android as coming soon rather than provide a non-public download route.

15

Can one GuardSphere organization manage multiple platforms?

Yes. ChromeOS, Android, and Windows devices can coexist in the same GuardSphere organization. They can share organization structure, groups, policy assignments, administrative visibility, governance, and reporting while retaining platform-specific installation, permission, telemetry, and removal requirements.

16

Does one policy behave identically on ChromeOS, Android, and Windows?

Not necessarily. Policies are managed within the GuardSphere organization, but effective enforcement can depend on the capabilities, services, permissions, and operating-system controls available on each platform. Administrators should verify policy behavior separately on every deployed platform.

17

Should one enrollment invite be used for an entire mixed fleet?

Separate enrollment invites are preferable when platforms, groups, classes, departments, households, or deployment batches differ. Clear invite boundaries improve assignment, rollout control, verification, and troubleshooting.

18

Why should groups be created before enrollment?

Creating groups first allows devices to join the correct class, department, household, team, location, or device cohort from the beginning. This reduces unassigned devices, avoids cleanup work, and helps ensure the intended policies apply immediately.

19

Why should policies be assigned before devices are enrolled?

Assigning policies before enrollment helps newly enrolled devices receive the intended rules during their first synchronization. Administrators should still verify the actual policy assignment and enforcement result after the device checks in.

20

How large should the first deployment pilot be?

The pilot should be small enough to troubleshoot safely but realistic enough to represent the intended environment. It may use a small class, department, household group, staff group, device cart, location, or limited set of administrator-controlled devices.

21

When is a pilot ready for production expansion?

A pilot is ready when expected devices are enrolled, correctly grouped, recently seen, receiving the intended policies, producing expected signals, and operating without unresolved issues that would become harder to correct at greater scale. Administrators should also understand support and authorized-removal procedures.

22

When should a production rollout be paused?

Pause when devices are missing, check-in is unreliable, policy assignment is unclear, expected telemetry is absent, platform permissions are inconsistent, or administrators do not understand the supported uninstall or unenrollment process. Resolve and verify the current state before adding more devices.

23

What happens after an organization account is created?

Authenticated administrators gain access to the GuardSphere Deployment Assistant. It provides organization-specific progress tracking, readiness detection, operational checklists, and direct links to groups, users, policies, enrollment, devices, Google Workspace, geofences, governance, workforce tools, reporting, and billing.

24

Does the public Deployment Guide replace the Deployment Assistant?

No. The public guide helps prospective and new administrators understand deployment scenarios before signing in. The authenticated Deployment Assistant uses the organization's actual configuration and progress to guide its operational rollout after account creation.

25

Can GuardSphere deployment be completed without a pilot?

A pilot is strongly recommended. It allows administrators to validate installation, enrollment, communication, permissions, policy behavior, reporting, and removal procedures without exposing the entire fleet to an unresolved deployment issue.

26

How often should administrators review the deployment?

Deployment continues after enrollment. Administrators should regularly review device connectivity, group placement, policy assignments, enforcement decisions, expected telemetry, governance information, reports, failed workflows, support cases, and required adjustments.

Ready to begin?

Create your organization and continue with guided deployment.

Start with a controlled pilot, verify the selected platform path, and use the authenticated Deployment Assistant to track readiness as your GuardSphere rollout progresses.

Choose your next step

Create an organization to begin deployment, book a demonstration, or return to the main GuardSphere website.