Skip to content

Scripts

Your Name edited this page Jul 18, 2026 · 1 revision

Scripts

Scripts are reusable commands you can run on devices — by hand, on a schedule as a monitor, or automatically as a remediation.

The script library

Create scripts under an organisation's Scripts tab. Each script has:

  • a name and optional category,
  • an interpreter: Shell (Linux / macOS) or PowerShell (Windows),
  • the body (the actual commands), and
  • optional attached files that are delivered alongside the script when it runs.

Running a script on a device

From a device (or the Remediate dialog), pick a script and run it. The agent executes it on the device and returns the exit code and output, which is stored in the organisation's run history. The device must be online.


Monitor scripts (script policies)

A monitor script turns any script into an alert. This is the Script policy option under Policies → New policy.

How it works

  1. You choose a monitor script and a cadence (check every 5 / 15 / 30 / 60 / 240 minutes).
  2. On each run, the agent executes the script on the target device(s).
  3. The exit code decides the result:
    • exit code 0 → healthy (no alert)
    • any non-zero exit code → alert (the policy is "raised")
  4. When the script's result flips to alerting, you get the same treatment as any policy: an email, an entry in Needs attention / the bell, and a record in the device's History.

Write your monitor scripts to exit non-zero when something is wrong. For example: exit 1 if a folder is missing, a certificate is near expiry, a queue is too deep, a required file is stale, etc. Exit 0 when everything is fine.

Optional auto-remediation

A monitor script can have a remediation script. When the monitor fails (non-zero exit), the remediation script runs automatically on that device to try to fix it. See Remediation.

So a monitor script policy is really a pair:

monitor script (detects: exit ≠ 0) → optional remediation script (fixes)

Run it now

Every script policy has a Run now button to execute the check immediately instead of waiting for the next scheduled run — handy while you're writing and testing it.

Examples

Goal Monitor script (exits non-zero on problem) Remediation
A service must be running sc query MyService | findstr RUNNING || exit 1 script that starts it
A disk mount must exist mountpoint -q /data || exit 1 script that remounts
A cert must be valid > 14 days check expiry, exit 1 if too soon notify / renew script

Monitor script vs template rule

  • A template rule (Low disk space, Device offline, …) is a ready-made monitor with a threshold — no scripting. See Policies and Monitors.
  • A monitor script is for anything the templates don't cover — you decide, in code, what "healthy" means.

Clone this wiki locally