Skip to content

Policy assignment

Policies attach to child accounts and flow to devices through mappings.

Order of operations

  1. Child account exists with weekly schedule and allowed hours
  2. Device mapping links child to (system_id, linux_username)
  3. Optional overlays:
  4. Web filter sources (domain manifest)
  5. App policy profiles
  6. Approval modes
  7. Platform device policy (Linux polkit / Android AMAPI fields)

Sync path

Trigger Behavior
Agent online (Linux/Windows) Immediate WebSocket commands
Agent offline Persisted in pending_command; flushed on reconnect (policy snapshots coalesce to latest DB state)
Android idle FCM sync_policies wake or ~4h WorkManager
Nintendo/Xbox Worker cloud push on schedule change

Agents may send policy_sync_check to pull latest domain manifest hashes (secondary path after reconnect flush).

Verify

Use Verify on a mapping or child profile to run validate_user and refresh sync badges.