Your endpoints, always in the CMDB
ATLAS is Kovira's endpoint agent for Windows and Linux. Once installed, it keeps each machine's CMDB record current with hardware, software, and security posture. Included in every plan. See how it supports a current configuration record in our continuous discovery guide.
Know what is on every machine
Hardware and software, kept current without the audits.
ATLAS records the specs that matter when something breaks: CPU, RAM, storage, graphics, motherboard, and network configuration. Every check-in refreshes the record, so the data you look at today reflects the machine as it is today.
On the software side, you get the operating system version, patch state, and the full list of installed applications. The spreadsheet you update once a quarter (already out of date by lunchtime) becomes unnecessary.
Key capabilities
- CPU, RAM, storage, graphics, and motherboard
- Network interfaces and IP configuration
- Operating system version and patch status
- Installed software inventory
- Virtual machine detection
Compliance posture at a glance
Encryption, antivirus, and firewall state on every machine, always visible.
Every check-in brings back a snapshot of the endpoint's security state: disk encryption, antivirus and EDR, firewall, Secure Boot, and TPM. Windows and Linux report the same core signals, so compliance questions are answered from one view.
That data sits on every device record in your CMDB. 'Which machines are out of compliance?' stops being a weekend project. Workflow automations can pick up posture changes when the next ATLAS check-in commits them.
Key capabilities
- Disk encryption status
- Antivirus and EDR state
- Firewall state
- Secure Boot and TPM status
- Host-level enforcement signals
Always know what is online
Heartbeats between full check-ins, so nothing drifts unnoticed.
Between full scans, ATLAS sends a light heartbeat on a configurable interval. Kovira tracks when each machine was last seen and surfaces any agent that has gone quiet, so a missing laptop is not discovered three months after it walked out of the building. The heartbeat interval is yours to set, anywhere from one minute to 24 hours, depending on how chatty you want the agent to be.
Each heartbeat carries a quick read of how the machine is running: uptime, CPU and RAM usage, disk and network throughput. Enough to tell at a glance whether an endpoint is healthy, without another tab and another dashboard. The heartbeats are diagnostic only and never replace your endpoint security or RMM tooling: ATLAS reports posture for inventory and CMDB purposes, and coexists with whatever antivirus, EDR, and patch management you already have deployed.
Each accepted check-in is correlated against existing VECTOR, Microsoft 365, and ATLAS identities before it updates the canonical device CI. Administrators choose the heartbeat cadence that balances freshness and network overhead for their environment.
Key capabilities
- Configurable heartbeat interval (one minute to 24 hours)
- Silent agent detection on the dashboard
- Live telemetry: CPU, RAM, disk, network
- Coexists with antivirus, EDR, and RMM tools
- Correlated CMDB updates on every accepted check-in
- Windows and Linux
Manage the fleet without touching the machines
Pause, resume, and remotely uninstall agents from the workspace.
ATLAS agents accept commands on each check-in. From the Kovira workspace, an admin can pause an agent (so it stops reporting until resumed), resume a paused one, or schedule an uninstall on a specific machine or a group of them. The agent picks up the command on its next heartbeat, acts on it, and confirms back when an uninstall completes. The dashboard shows which machines have finished removal and which are still pending.
This matters during decommissions, incident response, and software-rollout windows. Decommissioning a laptop no longer means RDP-ing in to scrub the agent. Pausing reporting on a sensitive machine for a maintenance window no longer means uninstalling and reinstalling. A misbehaving agent on a noisy endpoint can be paused while the issue is investigated. None of those operations require touching the machine directly.
Agent traffic is authenticated and tamper-resistant, so a command cannot be forged in transit. API keys can be rotated from the workspace, so a suspected leak is revoked in one action without touching the agents. Agent changes are only ever accepted through Kovira's authenticated path, so a stray credential cannot alter the fleet on its own.
Key capabilities
- Pause an agent from the workspace, no machine access required
- Resume a paused agent on its next check-in
- Schedule remote uninstall with confirmation back from the endpoint
- Status updates automatically once removal completes
- Authenticated agent traffic with rotatable API keys
- Agent changes accepted only through the authenticated workspace
ATLAS endpoint agent: frequently asked questions
The questions IT teams ask before rolling ATLAS out to a fleet of endpoints.
What does ATLAS report from each endpoint?
Does ATLAS replace my antivirus, EDR, or RMM?
Is ATLAS visible to end users on the endpoint?
How do I install, update, or remove ATLAS without RDP-ing into every machine?
Can I pause an agent during a maintenance window?
Be ready to deploy ATLAS on launch day
ATLAS will be in every plan at launch, including the free tier. Register your interest and be ready to install it on your first machine the moment Kovira goes live.