Operator Guides

Runbooks & Device Groups

Operators can group endpoints under Acme Corp sites and save repeatable runbooks. Cohort 01 still expects humans in the loop for consequential work.

Local runbook library

Open Runbooks to create and review reusable endpoint work without a GitHub account:

  • Library: find and run local runbooks (including starter examples).
  • Build: name an outcome, set an approval guardrail, and author one script lane per OS you support.
  • Variables: reusable non-secret and secret values by scope.
  • History: inspect execution state and output.

A runbook is one outcome (for example “Keep workstations awake”), not one file. FlowRMM picks the Windows / macOS / Linux lane that matches the selected endpoint.

Guardrails

  • observe: read-only work can run immediately.
  • remediate_within_bounds: a reviewed repair can run on one selected endpoint.
  • approval_required: creates a pending Action until a human Approves & runs.
  • human_only / blocked: never agent-executable.

Capturing a recent Action into a draft never re-runs it automatically.

Device groups

Use static or dynamic groups to organize Acme Corp endpoints for targeting. Keep consequential fan-out behind the same approval habits you use for single-endpoint Actions: Cohort 01 is not “set and forget” fleet remediation.

What stays out of the public promise

Visual DAG internals, raw HTTP compiler details, and unattended multi-OS fan-out are not the Cohort 01 marketing claim. Evaluate runbooks on whether your operators can review, approve, and reuse work safely.

Related guides

Want hands-on help evaluating Cohort 01? Book a demo or apply for Cohort 01.