purplegreen MDM is being prepared for its first pilot. These pages describe the development release.
Dashboard, alerts and notifications
Every member sees the dashboard and incidents (a site manager only for its sites); only owners and admins change rules, channels and the heartbeat key ("Only owners and admins can change alert rules, channels and the heartbeat key. You can see the current setup.").
The dashboard
The tenant's first page, Dashboard: "Which tablets need attention, and why." It shows the fleet summary (devices, healthy, needs attention, open incidents, retired) and a Needs attention list grouped by flag, each with a one-line explanation. Filter by site, tag or flag. Retired tablets are counted but never flagged.
What each flag means
| Flag | Meaning (as the app explains it) | What to do |
|---|---|---|
| Offline | "The device has not reported within the offline threshold (Android reports about once a day, or the kiosk app heartbeat when the OFFLINE rule uses it)." | Check power and network at the site; see What "offline" means |
| Not charging | "The device has been running on battery for longer than the grace period, so it may switch off." | Check the charger and cable |
| Non-compliant | "The device reports that it does not apply one or more settings of its policy." | Open the device page, Compliance section |
| Outdated app | "The kiosk app version is below the configured minimum or below the newest version seen on other devices of this tenant." | Let the tablet update (Updates tab, update mode); set a minimum version on the app page if needed |
| Policy drift | "The device has not applied its desired policy version within the grace period after the last push." | Usually the tablet was offline; reboot it if it is online |
| Needs site | "The device enrolled without a site; assign one so it gets the right profile." | Assign site on the device page |
| Reprovision due | "The device has been offline for 240 days or more; after 270 days it must be re-provisioned to be recovered." | Bring the tablet online soon, or plan a factory reset and re-enrollment |
| Policy rejected | "Google rejected the device policy or it was never pushed, so the device cannot be moved to it." | Fix the profile (see the error on the profile) |
| Command outcome unknown | "A remote command may or may not have reached the device; check the tablet." | Look at the tablet; see Remote actions |
The device page shows the same flags in a banner with their explanations and the tablet's incidents.
Incidents
"An incident opens when a rule's condition holds for a tablet and resolves when it clears. Each one notifies the rule's channels when it opens and when it resolves." There is at most one open incident per tablet and rule. Alerts > Incidents lists them, newest first, with filters for status, rule, site and device.
- Non-compliant and Outdated app open an incident only after their grace period (30 minutes and 1 day by default); the other flags already include their wait.
- Disabling or deleting a rule closes its open incidents without a notification.
- Time-based conditions (offline, not charging, drift, reprovision) are checked every 5 minutes, so an incident can open up to 5 minutes after the threshold.
Rules
Alerts > Rules and channels: "Which conditions open an incident, and where the notifications go." One rule per flag type. Each has an on/off switch, its channels and its parameters (the form shows the allowed range and blocks saving outside it):
| Rule | Parameters (default) |
|---|---|
| Offline | Threshold in minutes (the tenant's 26 hours), "Use the app heartbeat instead of the MDM report" (off), app threshold in minutes (10, "Used only with the app heartbeat.") |
| Not charging | Grace in minutes (60) |
| Non-compliant | Grace in minutes (30) |
| Outdated app | Grace in minutes (1440) |
| Policy drift | Grace in minutes (1440) |
| Reprovision due | Days (240) |
Minutes go from 1 to 43200 (30 days), grace from 0 to 10080 (7 days), days from 1 to 365. The app heartbeat only counts while the Offline rule is on. A rule's parameters also set when its flag appears on the dashboard, even while the rule is off.
Channels
One address per channel ("use a mailing list to reach several people"). The email has the rule, opened or resolved, the tablet and a link to its device page.
Webhook
A webhook channel posts JSON to your https URL. The address must be public: private, internal and cloud-metadata addresses are refused, also if the name later resolves to one, and redirects are not followed.
When you create the channel (and whenever you change its URL) the page shows the signing secret once: "Webhook URL changed. A new signing secret replaces the old one: store it now." It disappears when you leave the page or after 10 minutes.
Verifying a delivery. "Every webhook request carries X-Purplegreen-Timestamp:
import { createHmac, timingSafeEqual } from 'node:crypto';
function verify(secret, headers, rawBody) {
const ts = headers['x-purplegreen-timestamp'];
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) return false; // replay window
const expected = `sha256=${createHmac('sha256', secret).update(`${ts}.${rawBody}`).digest('hex')}`;
const got = String(headers['x-purplegreen-signature'] ?? '');
return got.length === expected.length && timingSafeEqual(Buffer.from(got), Buffer.from(expected));
}
The body has event (incident.opened, incident.resolved or channel.test), the
tenant, the device (name, serial, site), the rule, the incident and the device details
(flags, last seen, app last seen, battery, charging, kiosk app version). A delivery can
arrive twice after a worker restart: deduplicate by incident id and event.
Webhook URLs often contain a token (Slack, Teams and similar), so purplegreen MDM
stores them encrypted and shows the full URL only to owners and admins; everyone else
sees a shortened form (scheme, host and the first part of the path followed by ...).
Send test and failed deliveries
Send test queues a test notification ("Send test also works on a disabled channel, so you can check it before turning it on."). Each channel shows its last delivery (pending while a test waits for its first attempt). A failed delivery is retried after 1, 5, 30, 120 and 720 minutes; after the sixth failed attempt it is marked failed. A disabled channel does not send incident notifications.
A failure is shown as a short code (for now the code itself, labels follow):
| Code | Meaning | What to do |
|---|---|---|
http_<status> |
Your endpoint answered with that HTTP status (for example http_500, or http_302: redirects are not followed) |
Check the receiving service; point the channel at the final URL |
timeout |
No answer within 5 seconds | Make the endpoint answer quickly (queue the work) |
refused_private_address, refused_url |
The URL now points at a private or not allowed address | Use a public https address |
dns_error, tls_error, connection_error |
The name does not resolve, the certificate is not valid, or the connection failed | Check DNS, the certificate and the firewall of the receiver |
smtp_not_configured, smtp_unavailable, smtp_auth_failed, smtp_rejected_<code> |
Email could not be sent (no mail server set up, unreachable, login refused, or the address refused with that code) | Ask the purplegreen MDM operator; check the address |
channel_disabled |
The channel is off | Turn it on |
invalid_payload, missing_secret, missing_target, unknown_error |
Internal problem | Report it to the purplegreen MDM operator |
Retired devices and the quota
The Retired tab of the devices list shows tablets that stay enrolled but are out of service: how long each has been offline, whether it is due for reprovisioning (240 days), when it was retired and its profile. The quota line counts your enrolled tablets (active, enrolling, retired and being wiped); the project-wide limit is shown only to the purplegreen MDM vendor. Retired tablets still count until they are wiped or removed, and after 270 days offline they must be set up again. A site manager sees only its sites in the list and the count.
Minimum app version
On an app's page in the App catalog, owners and admins can set a minimum version code: tablets below it get the Outdated app flag.
Heartbeat
If your kiosk app or its backend can post a heartbeat, see Heartbeat ingest: minute-level offline detection.