Every night the agent reads your whole estate - the CE+ assessment, the KEV risk register and its 14-day clocks, Microsoft 365 licence usage and ConfigMgr / Intune health - and turns what it finds into costed, explained proposals. You approve; Assure ships the fix through the hash-pinned automation catalogue. Nothing runs without your say-so.
Demo with representative sample data. On your estate the proposals are raised from your own live signals each night.
32
Open proposals
3
KEVs past 14-day clock
£23,412
Savings identified /yr
96%
Proposals approved
41
Fixes shipped (30d)
Proposal inbox The agent proposes — you decide
Risk register · KEVPatch Google Chrome - known-exploited vulnerability past the 14-day window
KEV overdueconfidence 0.95
58 known-exploited CVEs sit against the deployed build across 41 devices, and the oldest passed its CISA due date 4 days ago. Under CE+ v3.3 an in-scope update left beyond 14 days is an automatic failure - this is the estate's highest-priority fix. Chrome 138.x resolves all 58; AutoPack has the package staged.
Clears 58 KEV CVEs on 41 devices · removes a CE+ auto-fail exposure
Risk register · KEVPatch 7-Zip - known-exploited vulnerability on the clock
Due in 6 daysconfidence 0.90
One KEV-listed CVE against 7-Zip 23.x on 17 devices; the CISA due date is in 6 days. Remediating now keeps the estate inside the window with room to verify.
Remediated before the KEV due date · avoids the 14-day auto-fail
Microsoft 365Reclaim Microsoft 365 licences from never-active users
£4,236 /yrconfidence 0.90
11 licensed users have never shown activity in any Microsoft 365 service. Reassigning or removing these licences recovers the spend at the next renewal with no impact on working users.
~£4,236/yr recovered across 11 licences
Intune healthRetry failed Intune app installs
14 failuresconfidence 0.80
9 devices report failed app deployments, mostly content-download errors. The im-resync and im-clear-ime-cache automations in the catalogue resolve the common Intune error codes without a visit.
14 failed installs retried across 9 devices
Intune health · CE+Enable BitLocker on unencrypted Windows devices
3 devicesconfidence 0.90
Three Windows devices report unencrypted. Encryption gaps are a common secure-configuration finding at CE+ sampling - closing them now removes the risk of an awkward audit day.
3 devices encrypted · closes a common CE+ secure-configuration finding
Auto patch & deploy Supervised tierOpt-in, per client
Once a client opts in, low-risk reversible fixes - browsers and auto-updating apps first - stop waiting for a click. The agent packages, deploys to a pilot ring inside your maintenance window, verifies the vulnerability is actually gone, then promotes. Every step lands in the audit trail, and a kill switch stops the lot instantly.
22:00Detected
Chrome KEV lands in the nightly NVD/KEV sync; 14-day clock starts.
22:04Packaged
AutoPack builds Chrome 138.x to your PSADT standards, hash-pinned.
02:00Deployed · Ring 1
Pilot ring via Intune, inside the agreed maintenance window.
07:30Verified
Re-correlated: KEV count on Ring 1 falls to zero. Promote to Ring 2.
08:00Reported
Client-ready summary drafted: "41 devices remediated, 4 days inside the window."