Policy assignment¶
Policies attach to child accounts and flow to devices through mappings.
Order of operations¶
- Child account exists with weekly schedule and allowed hours
- Device mapping links child to
(system_id, linux_username) - Optional overlays:
- Web filter sources (domain manifest)
- App policy profiles
- Approval modes
- Platform device policy (Linux polkit / Android AMAPI fields)
Sync path¶
| Trigger | Behavior |
|---|---|
| Agent online (Linux/Windows) | Immediate WebSocket commands |
| Agent offline | Persisted in pending_command; flushed on reconnect (policy snapshots coalesce to latest DB state) |
| Android idle | FCM sync_policies wake or ~4h WorkManager |
| Nintendo/Xbox | Worker cloud push on schedule change |
Agents may send policy_sync_check to pull latest domain manifest hashes (secondary path after reconnect flush).
Verify¶
Use Verify on a mapping or child profile to run validate_user and refresh sync badges.