purplegreen MDM
Pilot preparation

purplegreen MDM

Every kiosk, one dashboard

Hosted device management for company-owned Android tablets that run as unattended kiosks, built on Google's Android Management API.

purplegreen MDM is being prepared for its first pilot; access is on request. The service has not entered production yet: everything described on this page is implemented and tested in the development release.

Who it is for

Organisations that run unattended tablets across many locations, with no IT staff on site. Typically one tablet per location, and tens to hundreds of locations.

  • Check-in kiosksMembers check themselves in at sports clubs and gyms.
  • Digital signageSchedules, menus and notices on a wall or counter.
  • Front desksVisitor registration and simple point-of-sale screens.

What it does

Fleet dashboard

One screen shows which tablets need attention and why: offline, not charging, not compliant, an outdated kiosk app, or a profile that is not applied. Counts per site show where to look first.

Dashboard and alerts docs
The dashboard with device counts, a needs-attention list grouped by flag, and a per-site table
Dashboard, development release with demo data.

Kiosk profiles

A profile is the kiosk configuration a tablet gets: a single app, a multi-app launcher, or a web kiosk. Profiles compile to Android Enterprise policies. Every save is a new version, so you can compare versions and roll back. Staged rollouts move a new version to chosen sites or tags first, then promote it or roll it back.

Which profile a tablet gets
A single-app profile: the kiosk app, runtime permissions, update mode, managed configuration, and saving a new version
A profile's Apps tab.

QR enrollment

A factory-reset tablet scans an enrollment QR code and joins its site, with Wi-Fi included when you want it. Printable provisioning sheets guide the person on site, and tablets can be pre-registered by serial number before they arrive.

Enrollment docs
A printable provisioning sheet for a site: the enrollment QR code, the Wi-Fi network, and step-by-step setup instructions
A provisioning sheet, with a demo token from the development release.

Remote actions

Reboot, lock, clear app data, change profile or move a tablet to another site, one at a time or in bulk. Wiping asks for the intent: "Lost or stolen" keeps factory reset protection, "Release to owner" clears it.

Remote actions docs
A device page with its actions bar, an attention banner, status details and the applied policy
A device page with an attention banner.

App catalog

Apps from managed Google Play, with managed configurations. Configurations can use per-device variables such as the serial number, so each tablet gets its own values from one profile.

Apps docs
The app catalog listing managed Google Play apps with their configurations and the profiles that use them
The app catalog.

Alerts and incidents

Alert rules open an incident when a condition holds for a tablet and resolve it when it clears. Notifications go by e-mail or to a signed webhook.

Alerts docs
Alert rules for offline and not charging, each with thresholds and notification channels
Rules and channels.

Sites, tags and access

Organise tablets by site and tag, with settings inherited from tenant to site to device. Site managers see and act only on their own sites. Each customer is a separate tenant.

Device list docs
The device list with filters for site, lifecycle, online state, compliance and tag
The device list.

How it works

  1. Bind your Android EnterpriseYour organisation connects its own Android Enterprise to purplegreen MDM.
  2. Enroll by QR codeA factory-reset tablet scans the site's QR code and enrolls as a fully managed device.
  3. Android Device Policy applies itGoogle's Android Device Policy on the tablet applies the profile. There is no custom agent on the device.

Security

Security built in from the start:

  • Tenant isolation in the database, with row-level security.
  • Secrets encrypted at rest, per tenant.
  • Append-only audit log.
  • Single sign-on (OIDC) with roles: owner, admin, site manager and read-only.
  • Hosting: EU (Hetzner, Germany), behind Cloudflare, planned for the pilot.

The service has not entered production yet; these controls are implemented and tested in the development release.

Documentation

Request access

Tell us about your tablets: how many, where, and what they run. Pricing on request.