OpenFrame is on your phone now!

Assign Devices to a Monitoring Policy

GUIDEIMPLEMENTATIONMONITORINGOPENFRAME

Phase 4 — Monitoring & Policies · Step 4

Section

June 19, 2026

Published

Vladislav Marchenko

Vladislav Marchenko

Head Of Marketing

Assign Devices to a Monitoring Policy

Phase 4 — Monitoring & Policies · OpenFrame Onboarding

A policy or query only does something once it's pointed at devices. The device selector is the same on both the Add/Edit Policy and Add/Edit Query screens, so learn it once and it works everywhere. This guide covers picking devices, filtering by tag, and bulk-adding.


Before you start

  • You're in the Devices section of a policy or query you're creating or editing (Monitoring → Policies/Queries → Add or Edit → scroll to Devices).
  • Devices need the Fleet/osquery agent to be evaluable. The picker flags machines where the agent isn't installed.

The two targeting modes

At the top of the Devices section you'll see two options:

  • Select Specific Devices — choose individual machines to include. This is the mode available today.
  • Select Devices by Criteria — "automatically include all devices (current and future) that match your defined criteria." This is marked COMING SOON — when it ships, it'll let a policy auto-cover, say, "all Windows servers" without re-editing as devices come and go. For now, use specific selection.

Picking devices

The picker shows a table of Available Devices (and a Selected Devices (N) view of what you've chosen), with DEVICE, CUSTOMER, OS, and STATUS columns plus each device's last-online time.

  • Tick the devices you want to include.
  • Switch to the Selected Devices view to review exactly what's in scope.
  • Machines that read "Fleet agent is not installed" can be selected but won't return results until the agent is healthy — so confirm agent status first for anything important.

Filtering by Device Tags

This is the fast way to target a group. Click Device Tags to filter the picker down to machines carrying the tags you choose (the tagging scheme you set in Organize Devices with Device Tags, Phase 2). Filter to, say, Type: server, then add what's shown.

Note on tag targeting: filtering by tag narrows the picker so you can add the right machines quickly — but the selection is still a snapshot of those devices. Automatic, always-on tag/criteria targeting (where new matching devices join the policy on their own) is the Coming Soon "Select Devices by Criteria" mode. Until then, if you add devices later, revisit the policy to include them.


Bulk assignment

  • Add All Devices adds everything currently shown in the picker. Combine it with the Device Tags filter for a quick "all servers" or "all Windows" assignment: filter first, then Add All.
  • For a fleet-wide baseline check (e.g. encryption on), filtering off and Add All Devices assigns the whole fleet at once.

Save and verify

Save the policy or query. Then confirm the assignment took:

  • On a policy, the detail page's Devices table lists each assigned machine with PASSING/FAILING.
  • On a query, results start flowing from the assigned devices on the next scheduled run.

If a device you expected is missing, re-open the editor — it was likely filtered out of the picker (wrong tag, or agent-not-installed) when you saved.


Quick checklist

  • Used Select Specific Devices (auto criteria targeting is Coming Soon)
  • Filtered by Device Tags to find the right group fast
  • Used Add All Devices for bulk assignment where appropriate
  • Confirmed agent-installed status for important machines
  • Saved and verified the device list on the policy/query

What's next

With checks scoped to the right machines, the last piece is acting on failures — Understanding Alerts — Triage & Resolution walks the lifecycle from a device going non-compliant to getting it fixed.


Based on OpenFrame v0.9.19. "Select Devices by Criteria" is a roadmap item — re-check the console before treating tag auto-targeting as available.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
It is the total power a switch can supply across all its ports, which is almost always less than ports times the per-port maximum. Add up the device draws at their IEEE class: 802.3af phones at 12.95 W, 802.3at access points and cameras at 25.5 W, 802.3bt devices at 51 W or 71.3 W. Add 20% headroom and buy a switch whose total budget exceeds that figure.
It means one screen that shows the state of everything a team manages: devices, tickets, alerts and users. In practice the phrase covers three different products: a dashboard that reads from your other tools, a suite of separate modules from one vendor, and a platform where every module shares one database.
NOC stands for network operations center. It is the team, tooling and procedures that monitor and manage an organisation's IT infrastructure, including servers, endpoints, backups and cloud services as well as the network itself.
A NOC watches availability and performance and restores service when something fails. A SOC watches for threats and contains them. They share telemetry and often share incidents, so the handoff between them needs to be written down.
Providers price per monitored device or node band, by monthly incident volume, or per technician seat for white-label MSP arrangements. Published price lists are uncommon, so quotes depend on your device inventory and alert history.
For a single site with under a hundred devices, plan a day on site for discovery and the wireless survey, a week of passive counters for performance, and two days for the scan review and the report. Multi-site and heavily segmented networks scale roughly with the number of subnets, since each one needs its own discovery pass.
A one-page executive summary, the inventory and topology diagram, findings grouped by severity with evidence for each, a roadmap with costs and dates, and an appendix of raw scan output. Each finding carries what was found, the evidence, the risk, the fix, the cost, the owner and a target date.