Documentation

Start with the job you need to do.

ControlForge documentation is organized by responsibility, not by internal module names. Preview documentation is honest about which steps have physical or production evidence.

01

For platform owners

Create networks, enter any active network, appoint administrators, and keep authority attributable.

Preview documentationOwner guide
02

For network administrators

Invite the team, create endpoint accounts, handle reset requests, connect devices, and investigate findings.

Preview documentationAdmin guide
03

For people using a Mac

Sign in, change the initial password, connect this Mac, and understand its latest local report.

Preview documentationMac setup
04

For deployment teams

Validate the package, deploy Santa and ControlForge through MDM, preserve identity, and test lifecycle operations.

Preview documentationDeployment guide

A complete first connection

From a new account to a verified first report.

  1. 1
    Administrator creates the endpoint account

    The one-time initial password is shown once and delivered directly. No email server is required.

  2. 2
    The Mac user changes the initial password

    Enrollment remains unavailable until the required first-password step is complete.

  3. 3
    macOS authorizes the installed helper

    The short-lived grant is bound to that account, network, password revision, and exact device.

  4. 4
    The owner or administrator verifies the first report

    Connected does not mean healthy. The dashboard keeps reporting, component health, and findings distinct.

Engineering reference

Need the source-level documentation?

The repository contains the architecture, threat model, accepted detection subset, deployment runbooks, and current evidence boundaries.

Open GitHub