Trust Center Sign in
Sign inContact us
Platform capability · Protect

Device Control

Govern connected device access

Bring removable and peripheral-device context into endpoint policy, audit, and exception workflows without hiding the enforcement boundary.

Request a demo
The capability

Make connected devices visible

Device control starts with knowing what is connected, what posture it presents, and which authority is responsible for enforcement.

Inventory the edge

Collect USB and peripheral-device posture through native endpoint surfaces.

Scope the policy

Relate device decisions to endpoint, user, posture, and declared operating intent.

Keep the record

Preserve device state, policy context, and exceptions for audit and investigation.

What it governs

A clearer boundary for peripherals

Security teams need both the inventory signal and an honest statement about which system is authorized to enforce a device policy.

Endpoint context

See the device posture

  • Connected device identity
  • USB and peripheral context
  • Endpoint and user scope
  • Observed changes over time
Governance boundary

Make authority explicit

  • Policy and exception context
  • Audit-ready device evidence
  • MDM-aware enforcement scope
  • Clear separation of visibility and action
How it stays governed

Visibility first. Enforcement with authority.

The endpoint can provide device posture and audit context while the enforcement authority remains explicit rather than implied.

Boundary · 01

Observe

Identify devices and changes through native inventory surfaces.

Boundary · 02

Authorize

Apply policy, exception, and deployment authority to the decision.

Boundary · 03

Prove

Record posture and enforcement outcome without overstating endpoint authority.

Current evidence

Helper-only / conditional

macOS USB and device posture is inventoried through IOKit with audit-only enforcement on the agent boundary.

Qualification

MDM is required for enforcement

Do not present this capability as universal endpoint blocking. Enforcement authority and deployment conditions must be established through the applicable MDM path.

See the boundary

Discuss device policy in your environment

Review device visibility, MDM authority, exception handling, evidence, and the maturity path with the Spacetime team.

Request a demo