Appearance
AI assistant
Two places, one assistant. Asset chat lives on every device page. Policy author lives on the policies list and on each policy's page. Both use your organisation's own AI provider key (Settings, AI) and are switched on per feature under Settings, AI, Feature controls.
Asset chat
Every device page has an Ask AI tab. Type a question such as "why does this machine not wake from sleep?" and the assistant works the problem the way an engineer would: stored data first, then the live device, then a proposal you approve or reject.
It uses your organisation's own AI provider key (Settings, AI). Nothing works until an administrator has added a key and switched on Asset chat under Settings, AI, Feature controls (the AI usage dashboard, per-feature enable). It starts off for existing organisations.
What it can do on its own
The assistant runs these without asking, and lists each one under its answer so you can see exactly what it looked at:
- Stored data. The device record, checks and their last values, alerts, collected event log rollups, software inventory, notes, tasks, the effective policy and recent history.
- Live read-only queries. System information, the process list, the service list and a live event log query from the running agent. If the device is offline these fail fast and the assistant says so.
- Catalogue diagnostics. A fixed, platform-curated list of read-only commands such as
powercfg /a,powercfg /lastwake, a seven-day sleep study reduced to text, Kernel-Power event history,dcdiag /q, disk health,ipconfig /alland DNS resolution. The assistant can only pick an entry from the list. It cannot write its own command here, and any parameter (a hostname, a number of days) is validated before it is used.
What needs your approval
Anything outside the catalogue, including any fix, arrives as a proposal card: the exact command, the shell it will run in, and the assistant's one-sentence reason. Nothing runs until you click Run. Reject sends the refusal back to the assistant, which will suggest something else or stop.
Rules worth knowing:
- One command per proposal. The assistant cannot queue several behind one click.
- A proposal expires after 15 minutes.
- Approving needs the
agents.cmdandagents.terminal.cmdpermissions, the same as running a command from the Terminal tab. - Read the command before you run it. It executes with the agent's privileges on the device.
Audit trail
Every catalogue diagnostic and every approved command is written to the device's History tab as a normal command run, attributed to you, and to a permanent record that keeps the command, who approved it, the exit code and the first part of the output. Conversations themselves are kept for 90 days by default (Settings, Data retention); the command record is never pruned.
Permissions
| Permission | What it allows |
|---|---|
ai.asset_chat.use | Open the Ask AI tab and send messages. Administrators and Technicians have it by default. |
agents.cmd, agents.terminal.cmd | Approve a proposed command. |
The tools the assistant may call are limited by your permissions, not the assistant's. A technician who cannot view event logs will find the assistant cannot either, and it will say so.
Policy author
On the Policies list, Author with AI opens a conversation for a new policy. On a policy's page, the Ask AI tab opens one for that policy. Describe what you want in plain English:
- "Create a policy to monitor Domain Controller event logs and services."
- "Add memory monitoring and event log checks for the XYZ line-of-business app."
- "Review this policy and tell me what is missing."
The assistant reads the policy's existing checks, the script library and the built-in check catalogue. When something is unspecified, a threshold, a service name, a schedule, it asks one question at a time, usually with quick-pick answers. When it has enough it produces a proposal card: every check and task it wants to add, update or remove, in the real policy schema, already validated by the same rules the policy editor uses.
Nothing changes until you click Apply. Untick any row you do not want. Applying needs the policies.manage permission and goes through the normal policy endpoints, so it is audited like a manual edit. A new policy is created at that moment; an existing one is amended in place. You can keep talking to refine the proposal before applying it.
What it cannot do, and will say so: filter an event log check by event id or source (the check type does not support it yet), invent scripts (it only uses scripts that already exist), or apply anything itself.
Permission: ai.policy_author.use, Administrators by default.
Choosing a model per feature
Under Settings, AI, Feature controls, Model per feature lets an administrator pick a different model for individual features. A frontier model for event log analysis and policy authoring, a faster balanced model for asset chat, is a sensible split. Asset chat and policy author require a Sonnet-class model or better; the smallest models are not offered for them.
Limits
- A conversation handles one message at a time. Wait for the answer, or the proposal, before sending the next.
- Each message allows the assistant up to eight tool calls and two minutes. If it runs out it summarises what it found and you can ask it to continue.
- Daily turn limits per organisation are set under Settings, AI, Feature controls (default 40 per day).
- Device data, including event log text and command output, is sent to your configured AI provider during a chat.