- Through Passport: every agent connected to Passport, who uses it, and whether it is idle or out of date.
- Outside Passport: MCP connections people configured directly in supported local agents, found by
passport discoverscans.
Agents through Passport
Open Inventory. The table has one row per agent: the people using it, its connections, the newest version in use, and when it was last active. Choose a row to see each install, its owner, where it runs, and its version.- Idle agents haven’t been used in 30+ days. Revoke the ones you don’t recognize.
- Out of date marks installs two or more versions behind the newest version of the same software in use. Passport CLI and every Desktop compatibility connection run the same Passport bridge, so they share one version line; other agents compare within their own versions.
- Search by person, agent, or device to find one install.
Connections outside Passport
Open Inventory → Outside Passport. Each finding becomes a clear decision:- approve the direct connection;
- ask the owner to move it behind Passport;
- allow it temporarily; or
- ask the owner to remove it.
Review the action queue
On Outside Passport, the action queue appears first and groups the same MCP found in several agents into one decision. For each item, review:- who owns it and how they described its purpose;
- which supported agents contain it;
- whether it could be routed through Passport; and
- the current admin decision.
How scans reach Passport
Every finding comes from the Passport CLI. On a member’s computer, run:
Your endpoint-management system decides what to do with exit code
5, such as notify, quarantine, or start its own remediation. Passport does not silently edit a managed device.
Passport Desktop no longer scans local agent configuration. Desktop is sign-in, connection repair, apps, activity,
and approvals;
passport discover is the only source of outside-Passport findings.What happens on a member’s computer
passport discover only reads supported configuration files, and Passport never edits them. A Route through Passport or Remove decision is a request to the owner, who makes the change in the agent that holds it; the next scan confirms the result.
Coverage and scan policy
Outside Passport says how many people’s computers reported a scan this week. Choose See who’s missing to list the people whose computers haven’t sent a scan, whose last scan is over a week old, or whose last scan couldn’t read agent settings. Project-level configuration, hosted agents, and computers that never runpassport discover are outside coverage.
Choose Scan policy in the page header to switch between:
- Personal (opt-in): each member decides whether their computer reports scans.
- Managed work computers: administrators run
passport discoverthrough device management (MDM) or an onboarding script.