VerOps Scout

VerOps Scout — overview
A lightweight endpoint agent that turns real application activity into utilization and adoption analytics — which tools are used, how much, and how that changes over time — plus hardware, installed software, users, presence and OS update posture. Current release: v0.6.1, enrollment-only authentication.
Installation and enrollment
Install Scout v0.6.1 from the preconfigured Windows setup wizard or the generic installers — the service registers, starts and (from v0.6.1) restarts onto your configuration — enroll with a limited-use token, and migrate any fleet still using a legacy api_key before you upgrade it.
Enrollment and device credentials
Scout authenticates by enrollment only from v0.6.0: a limited-use, expiring token in scout.toml exchanged once for that device's own scoped, individually revocable credential. Covers the two credentials, the X-Agent-Kind header, revocation, re-enrollment on re-deploy, and migrating a config that still names api_key, username or password.
Fleet: Agents, Groups, and Rulesets
Central configuration composed from Agents, Groups, and Rulesets — including the six Default rulesets, adding a process to a group, and their patterns.
Discovery vs Targeted
The two tracking modes and the discover-curate-target loop that turns an unknown fleet into a governed, low-volume estate.
Signals and the activity model
Activity levels 0-3 correlated from foreground, CPU, connections and bandwidth; and how per-app bandwidth works and its limits.
Collection policy and presence
The central collection policy — modules, polling and heartbeat cadence, and refresh hours applied on the next poll, no reinstall — plus the v0.4.0 collector modules including patch posture, and network-inferred office/remote presence against trusted office networks.
Update posture
The v0.4.0 patch-posture collector: what Scout reports on Windows and Linux, the strict cached-metadata-only guarantee, its remote switch and 6-hour refresh cadence, and why older agents read Unknown.
Automatic updates
Opt-in self-update from Scout v0.5.0: the two switches that must both be on, the stable / beta / pinned channels and percentage rollouts, the verify-execute-swap-rollback sequence on the endpoint, how an admin watches or halts a rollout, and what to migrate before rolling out v0.6.x.
Scout vs the Machine Agent
Why there are two collectors and one estate — target device, footprint, activity ceiling, deployment and the authentication models, which now differ: Scout is enrollment-only while the Machine Agent still supports an ingest api_key.
Value surfaces, dashboards and Vera
The utilization Products grid — weighted usage, usage tiers, window comparison and trends; group-scoped license reconciliation with confidence-qualified annual savings; redundancy detection with dangerous overlaps; policy enforcement with real-time violation alerts, a remediation workflow and time-boxed toleration; host lifecycle and tags; the Review queue; the dashboard data source; and Vera's usage/redundancy/policy tools.
Best practices and common mistakes
How to run inventory well: targeted-by-default, central config, tracking adoption over time, finding installed-but-unused tools, re-surveying to catch drift, closing the review queue — plus the mistakes to avoid.
Frequently asked questions
Privacy, enrollment-only authentication and the api_key removal, device keys, re-deploying an enrolled machine, network-based presence, collection modules, Scout vs Machine Agent, zero-apps, bandwidth, update cadence, utilization % and the window, weighted usage and usage tiers, license reconciliation, redundancy, policy enforcement, lifecycle, tags, automatic updates, and the feature gate.
Troubleshooting
Symptom-cause-fix for a service that refuses to start after the v0.6.x upgrade, an empty estate, an installed-but-unconfigured service, authentication and enrollment failures, a machine that enrolled with the wrong token or group, unavailable inventory surfaces, blank bandwidth, no focused activity, config not applying, new software not appearing, unknown update posture, and automatic updates that stall, fail or roll back.
Attendance tracking by location
Turn Scout's office/remote presence into a per-person daily attendance record, rolled up to weekly, monthly and yearly summaries you can chart. Off for every location until you switch it on, gated behind its own permission, and deliberately present/absent rather than hours on site.