Remote support is trust with a keyboard. Remote makes the trust checkable: every session gets an anomaly score, elevated sessions are recorded by policy, approvals have a 15-minute SLA, and standing access is scored like the sessions it enables.
The recordings library has 160 entries and one row marked Missing. Most tools would call that 99% and move on; this one raises the gap as an alert with the session id attached. The missing row is the feature.
remote.cedxsystems.com — live build
Runs on demo data. Devices and principals in the captures are the demo tenant's rows, not customers.
160 sessions elevated15 of them unrecorded — counted, not excused
90% record coverageon ended elevated sessions; the 10% is an open alert
56 standing grants at high riskpersistent access, scored like sessions
What it is
Three surfaces that make trust checkable.
320 sessions, anomaly score on each
Attended, unattended and elevated sessions in one list with status, device, agent, duration, anomaly and a recording flag. Session 8f2a ended elevated after 37 minutes with anomaly 68 and REC: No — the exact session the off-hours alert names.
Attended, unattended, elevated as kinds
Anomaly score and REC flag on every row
REC: No is a first-class value, not a blank
remote — screen-2
180 devices, standing access in plain sight
The fleet list shows OS, online state, group, whether it holds a standing grant, and at what privilege — a warehouse node online with root standing, an offline laptop still holding domain admin. Forty-eight agents are stale, 33 of them on critical devices.
Standing yes/no and privilege level per device
Online 102 of 180 — 57%, printed
Stale agents counted, criticals called out
remote — screen-3
Every elevated session on tape — except one
The recordings library lists status, duration, size and elevation per recording: live, retained, expiring — and missing. The missing one is 37 minutes on a point-of-sale device, the same session the overview alert describes at 23:14.
Live, retained, expiring, missing as states
Duration and size per recording — 920MB largest
14 recordings expiring, counted on the card
remote — screen-4
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/remote.
remote.cedxsystems.com
01 — Overview
The estate's trust, scored
Estate health reads 58% — record coverage 90%, devices online 57%, 56 standing grants at high risk, 29 agents on shift. The alerts are specific: a standing grant idle 47 days that keeps domain admin; an off-hours elevated session at 23:14 with no recording; 64MB moved on an elevated database session.
Sessions by state: 207 ended · 37 active · 36 waiting · 40 failed
9 approvals already past the 15m SLA
Break-glass dual control shown as a chart marker
02 — Sessions
Who is on which machine, right now
Three hundred twenty sessions in the window with the queue visible: 37 active, 36 waiting an average of four minutes. Elevated sessions carry their own count — 160 — and 15 of them are marked unrecorded in the column, not in a footnote.
High anomaly: 7 sessions at score ≥55
Active, waiting, ended, failed filters
Search by session, device, agent or ticket
03 — Devices
The fleet, with privilege visible
One hundred eighty enrolled devices across databases, warehouses, kiosks, tablets and print fleets. Standing grants and privilege levels are columns — so “which machines can be touched without asking” is a filter, not an audit project.
76 standing grants across the fleet
Root, domain admin, local admin, break-glass levels
Online, away and offline as chips
04 — Recordings
The tape library, gap included
One hundred sixty recordings with the elevated-coverage card at 90%. The policy gap — one missing recording — is listed with its session and device, next to 14 expiring recordings and 64K MB of storage.
Coverage 90% on ended elevated sessions
The missing row names session and device
Expiring state makes retention visible
Who runs it
Three roles keep the access honest.
Roles, not references. We have no named customers yet, so nobody is quoted, credited or claimed as one — and this page ships without photography rather than with a synthetic frame.
Support lead
Works the waiting queue — 36 sessions, four minutes average wait — and takes the attended ones with the customer watching.
waiting · 36
Security reviewer
Owns standing access: 56 high-risk grants, and the idle-47-day domain admin first. Approvals past the 15-minute SLA land on this desk too.
standing high risk · 56
Device fleet admin
Chases the 48 stale agents — 33 on critical devices — and the 78 machines not online when they should be.
stale agents · 48
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
320sessions in the window207 ended · 37 active · 36 waiting · 40 failed
160elevated sessions15 of them unrecorded
90%record coverage on ended elevatedpolicy gap: 1, listed by name
22approvals pending9 already past the 15-minute SLA
Sessions by state — 320 in the windowfrom the overview panel
Ended207
Failed40
Active37
Waiting36
Record coverage, ended elevatedthe 10% gap is an open alert, not a footnote
Recorded · 90%
Missing · policy gap, count 1
Devices online102 of 180 enrolled
57%
Online · 102
Offline or away · 78
How it runs
A session's life, in the order it actually happens.
01
Request
Unattended or elevated access starts as an approval — 22 pending, 9 already past the 15-minute SLA, counted on the overview.
02
Connect
Sessions run attended, unattended or elevated, each with an anomaly score accumulating as it goes — 7 currently high.
03
Record
Elevated sessions are taped by policy at 90% coverage, and the single gap is an open alert with the session id attached.
04
Review
Standing access is scored like the sessions it enables — 56 grants at high risk, idle ones flagged with their privilege named.
One record
Remote access, on the same record as everything else.
A remote session usually starts as a ticket and ends in an audit. The estate keeps both ends — same workspace, same Ask AI button.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Remote is not generally available. What opens today is the live build on demo data — devices, sessions and principals in the captures are the demo tenant's rows.
Record coverage is 90% in the demo, not a guarantee. The product's stance is that the gap must be visible — and on the recordings screen, it is.
Anomaly scores flag sessions for a person. The demo shows scoring and alerts, not automatic termination, and we do not claim auto-kill here.
What you see is session support with an audit spine, not a full privileged-access suite — the approvals shown cover unattended and elevated sessions.
No audit or compliance certification has been issued. What we can evidence about hosting and access is on the security page.
Yes. Every screenshot is a capture of the running build, open at /app/remote. It runs on demo data — the devices and principals are the demo tenant’s rows.
Which sessions get recorded?
Elevated sessions, by policy — the coverage card reads 90% for ended elevated sessions, and the one policy gap is listed with its session id and device rather than averaged away.
What is standing access?
Persistent grants that let a principal reach a device without a per-session approval — 76 across the demo fleet, 56 scored high risk. The overview flags the idle ones: one grant unused for 47 days still holds domain admin.
How do approvals work?
Unattended and elevated sessions start as requests with a 15-minute SLA. Twenty-two are pending in the demo and nine are already past SLA — the overview counts them rather than hiding the queue.
Is Remote audited or certified?
No certification has been issued. What we can evidence about hosting, encryption and access is on the security page.
The session list is live. Check the tape.
Live build, demo data, no card. Then ask which of your machines can be touched without asking.