RD RemoteDesk IT Product wireframes V1.1 · PRD V2.0 §17 + revision brief 2026-08-01 · Mac only · Volt design system · LIVE = implemented in the Phase 1 console skeleton (2026-08-08)
Wireframe specification · for the engineering team · revision V1.1

RemoteDesk IT — Product Wireframes V1.1

One coherent product, two surfaces: RemoteDesk IT Console for administrators and RemoteDesk Agent for employees. The Mac is managed through Apple MDM and enriched by the Agent. The prototype must demonstrate that RemoteDesk can manage the device, support the employee, understand eligible work context, and operate the full employee-device lifecycle — without collapsing those permissions into employee surveillance. (PRD §17.19) V1.1 is a revision, not a redesign: the two-surface architecture, Mac-only scope, MDM/Agent dual channel, canonical Device Detail, privacy boundary and all eight state matrices are unchanged. What changed is the perceived center of gravity — Enterprise IT + Device Operations first, Work Intelligence optional.

Source PRD V2.0 · chapter 17 + revision brief 2026-08-01 Functional detail chapters 5–6 Scope V1 · Mac only Fidelity Low-fi content · on-system tokens
What changed in V1.1 — the product hierarchy this document now encodes
Hierarchy · navigation, dashboards, copy and visual weight all follow it
1 · DEVICE — is my Mac ready?
2 · SECURITY — is it protected and compliant?
3 · SUPPORT — one click to IT help
4 · LIFECYCLE — Day-1 ready → recovery
5 · WORK Optional — workspace-configurable
First impression target: “The company IT app that keeps my Mac ready, secure and supported.” Work Intelligence appears after that impression is formed — and disappears entirely when the workspace turns it off.
Revision map · R01–R09 → where it landed
R01 Agent nav IT-first, WORK group vanishes when off → all Part B frames, A-00
R02 Agent Home default screen → A-00 · new
R03 My Device answers four questions → A-03
R04 Work Intelligence workspace-configurable → C-11
R05 Menu bar: support-first, Timer conditional → A-01
R06 Overview second layer: Employee & Device Operations → C-01
R06b Day-1 Readiness as product concept → C-12 · new
R07/07b Lifecycle workflows + Recovery Detail → C-10, C-13 · new
R08 Engineering language out of product UI → C-03 drawer + legend below
R09 Console “Work” → “Work Records” → C-09
Final naming (PRD §17.1) — use these names everywhere
LayerFinal nameMeaning
ProductRemoteDesk ITCustomer-facing product and website module.
Admin web appRemoteDesk IT ConsoleCloud management console.
Mac clientRemoteDesk AgentSoftware installed on employee Macs.
Remote screen viewingNot offeredRemoved by design (ADR-0002, 2026-08-08) — incompatible with the privacy posture.
MDM layerApple Device ManagementUnderlying management capability, not a separate product brand.
Naming decision: do not call the client Remote Desktop Agent. Do not call the overall product Remote Desktop. Those names imply a narrow remote-control product. Revision 2026-08-08 (ADR-0002/0005): real-time screen viewing, remote terminal and file transfer are all removed — remote support is a read-only diagnostic bundle only. The product cannot see an employee’s screen, control the device, or read files.
V1 scope: Mac only (PRD §17.3)
Build now
macOS enrollment / Apple MDM · Mac inventory and health · FileVault, firewall, OS compliance · configuration profiles, Wi-Fi, VPN, certificates · software inventory/deployment · read-only diagnostics (no screen / terminal / files — by design) · My Day, Timeline, Timer, Work Summary, Timesheet · procure, assign, recover, wipe, reassign
Defer
Windows, Linux · iOS, Android · cross-platform policy abstraction · proprietary EDR · autonomous AI IT operator · conversational AI IT · mobile work tracking · full warehouse automation
Two-channel Mac model (PRD §17.5) — every screen annotates which channel feeds it
MDMApple MDM channel
Enrollment / managed state · configuration profiles · FileVault / security policy · Wi-Fi / VPN / certificates · OS management / restrictions · managed software · lock / wipe
AGENTRemoteDesk Agent channel
Employee desktop UI · My Day / Timeline / Timer · work-context processing · Private Mode / exclusions · heartbeat / diagnostics · diagnostic-collection consent UX
A third chip, CLOUD, marks data computed or stored server-side (RemoteDesk Cloud: Organization, Employee, Device, Policy, Command, Compliance, WorkSession, TimeEntry, RemoteSession, LifecycleEvent — §17.4). The Console never reads NanoMDM storage directly.
How to read these wireframes
Annotation chips — engineering language lives outside the frames (R08)
MDM AGENT CLOUD — data sources feeding the screen (§17.16). New in V1.1: these chips appear only in each screen’s annotation rows and footers — their sanctioned home in this wireframe doc — never inside the product UI itself.
In-frame product UI uses friendly labels instead: Management · Managed RemoteDesk · Connected Security · Compliant. Admins who need channel internals open the Technical details drawer (C-03).
Wireframe · Demo data — every frame; numbers are small illustrative counts, not targets
STATE → Part C — chips on screens use the eight state matrices in the state reference sheet
Each screen ends with an engineering annotation block: permissions, state transitions, confirmations, errors, audit.
State chip color language (semantic colors, never volt)
Healthy / positive Transitional / attention Failed / violation Not yet / inactive Formal / submitted Dormant / terminal Private / excluded
Volt is the brand accent: primary CTAs, active nav, highlights. It never encodes status, and volt text on light surfaces always uses volt-700 #6E8A00. Dashed frames marked Alternate state show required non-happy-path variants (Part E).
Product principles carried through every screen
Managed does not mean monitored. Admin work screens show approved and submitted outputs only — never raw activity. Quiet, not invisible. The employee can always see, in one glance, what is being captured and who can see what. Employee screens must not look like monitoring software (§17.16). Demo people use role + city (e.g. “Software Engineer · Tokyo”); Alex Rivera appears only because §17.9 names him canonically. Serials are masked SN ····.
V1.1 acceptance criteria — sign-off table for the design team
#All ten must be YES before V1.1 is doneProven bySign-off
1Seeing the Agent for the first time, it reads as an IT / device product firstA-00 · A-01 default state · A-03
2With Work Intelligence off, the product still stands completeA-00 IT-only variant · C-11 preset A · A-01
3The Timer is no longer the default visual centerA-01 — Timer is a conditional appendage only
4An employee can tell at a glance whether the Mac is secure and healthyA-00 status dots · A-03 · A-01
5An employee can request IT support in one clickA-00 IT Support block · A-01 · A-04
6An admin can see who is Day-1 Not ReadyC-12 · C-01 operations layer
7An admin can complete a full device recoveryC-13 · C-10 offboarding strip · D-6
8An MDM admin still cannot automatically see raw work activityC-09 principle · A-08 · C-03 Work-tab rule
9High-fi UI no longer shows MDM / AGENT / CLOUD engineering labelsC-03 friendly labels + Technical details drawer · cover legend
10Remote screen viewing is not offered — remote support is diagnostics-first (ADR-0002)C-03 action bar · C-07 · naming table above
DeliverableDevelopers implement from this document plus Part C (badge vocabulary) and Part D (flows). Where this document, PRD V2.0 §17 and the revision brief disagree, the brief wins on emphasis/IA and §17 wins on scope.
PriorityP0 screens: C-01…C-07, C-12 and all of Part B. P1 screens: C-08…C-11, C-13. Priority order of the product: device operations → remote support → lifecycle → work intelligence (§17.10). High-fi demo focus: Day-1 Readiness (C-12) and Device Recovery (C-13).
Design systemTokens embedded here are a condensed copy of assets/css/tokens.css (Volt v1.0): ink #10131C/#1B1E26/#232733 · volt #CDFF05 (text-on-light #6E8A00) · paper #F6F6F3 · slate scale · semantic success/warning/danger · Archivo + IBM Plex Mono · radii 2/4/8px.
C-01 · IT Console · IT overview · P0 · revised in V1.1 (R06)

Two layers: is the fleet healthy — and are the people ready?

Key outcome (§17.8): understand fleet health and exceptions — plus, new in V1.1, the Employee & Device Operations layer: new hires approaching Day-1, shipments, recoveries and inventory. This second layer is the start of the divergence from pure MDM: Jamf watches devices, RemoteDesk operates the employee-device relationship. Every tile deep-links into the matching filtered screen.

DataMDMAGENTCLOUDStatesDevice · Compliance · MDM → Part C
console.remotedesk.io/overviewWireframe · Demo data

Overview

Demo Company · 12 Macs · last aggregation 2 min ago
Managed Macs
12
of 13 invited
Online now
9
Agent heartbeat < 5 min
Non-compliant
2
View exceptions →
Enrolling
1
1 failed · retry →
Support sessions
1
active now · view →
Exceptions · needs actionsorted by severity
MacBook Pro 16 · SN ····
Data Analyst · Singapore
Non-compliantFileVault off
MacBook Pro 14 · SN ····
Alex Rivera · Software Engineer · Tokyo
Needs attentionOS update overdue
MacBook Air 13 · SN ····
Backend Engineer · Manila
FailedEnrollment profile rejected
Enrollment funnel
3
Invited
1
Enrolling
12
Managed
Recent audit events
14:21 · remote session ended · audit ✓
13:48 · policy “Baseline security v3” edited
11:02 · Mac enrolled · QA Engineer · Osaka
Employee & device operationsSecond layer · new in V1.1
New hiresnext 7 days
3
Device ready 2/3
Needs device 1
Shipping
2
1 outbound · new hire, arrives Mon
1 return · recovery, arrives Fri
Recovery1 overdue
2
1 in transit · on schedule
1 return overdue · 4 days
Inventoryby city
Tokyo4
Singapore2
Hong Kong1
DataTiles are CLOUD aggregations: “Managed” from MDM enrollment state, “Online” from Agent heartbeat (< 5 min), compliance from CLOUD rule evaluation over MDM inventory. Operations layer aggregates People records, LifecycleEvents and shipping fields (CLOUD).
PermissionsAny IT Console role sees this screen. Work data never appears here — the Work Records area (C-09) has its own role check (§17.11).
StateTile taps navigate to C-02 pre-filtered (e.g. Non-compliant → compliance=Non-compliant). Exception rows deep-link to C-03/C-04. New hires → C-12; Recovery → C-13; Shipping/Inventory → the matching Lifecycle sub-pages.
LoadingTiles render as gray skeleton blocks until the first aggregation returns; exceptions list shows 3 skeleton rows (see Part E). The operations layer keeps its own skeleton — fleet health never blocks on people data.
C-02 · IT Console · All devices · P0

Every Mac, both channels, one table

Key outcome (§17.8): find every Mac and its employee, MDM, Agent and compliance state. MDM and Agent are independent channels and get independent columns — never merge them into a single “status”. Chips use the Part C vocabulary.

DataMDMAGENTCLOUDStatesDevice · MDM · Agent · Compliance → Part C
console.remotedesk.io/devicesWireframe · Demo data

All Macs

12 devices · exceptions sorted first
MDM All Agent All Compliance All Group All
DeviceEmployeeMDMAgentComplianceLast seen
MacBook Pro 14
SN ····
Alex Rivera
Software Engineer · Tokyo
HealthyOnlineNeeds attention2 min ago
MacBook Pro 16
SN ····
Data Analyst · SingaporeHealthyOnlineNon-compliant5 min ago
MacBook Air 13
SN ····
Backend Engineer · ManilaFailedNot installedUnknown
MacBook Air 13
SN ····
Frontend Engineer · HanoiPendingNot installedUnknown
MacBook Air 13
SN ····
Product Designer · OsakaHealthyOfflineCompliant3 d ago
MacBook Pro 14
SN ···· Recovery
Unassigned · offboardingEnrolledOfflineUnknown6 d ago
Showing 6 of 12 · phase: table paginates at 50
Alternate state · EmptyPart E
MAC
No Macs yet
Send your first enrollment invitation to bring a Mac under management.
Alternate state · Loading / console offlinePart E
Connection lost. Showing data cached at 14:02. States may be stale — retry.
DataMDM column from Apple MDM check-ins; Agent column from Agent heartbeats; compliance computed in CLOUD. “Last seen” = most recent of the two channels; hover reveals per-channel timestamps.
StateChips come straight from Part C matrices. A device-level chip (e.g. Recovery) renders next to the serial. Default sort: exceptions first, then last-seen desc.
InteractionRow click → C-03. Filters combine (AND). Search matches device name, employee, serial, group label.
ErrorsIf the fleet query fails, keep the table skeleton and show the cached-data banner (alternate state above); never render an empty table as if the fleet were empty.
C-03 · IT Console · Device detail · Overview tab · P0 · canonical layout §17.9

The canonical device page: one Mac, both channels, six tabs

Key outcome (§17.8): operate one Mac across Security, Software, Support, Work, Lifecycle and History. This header block is the canonical layout every tab reuses. The action bar hosts one support action — Collect diagnostics (read-only). Screen viewing, terminal and file transfer are deliberately not offered (ADR-0002/0005).

DataMDMAGENTCLOUDStatesDevice · MDM · Agent · Compliance → Part C
console.remotedesk.io/devices/mbp14-····Wireframe · Demo data
Devices / All Macs / MacBook Pro 14
IMG
Alex Rivera · Software Engineer · Tokyo
MacBook Pro 14 · Apple Silicon · SN ····
Management · Managed RemoteDesk · Connected Security · Compliant Technical details ▾
Read-only, requires employee consent + writes an audit event → C-07
Overview Security Software Work Lifecycle History
Device
EmployeeAlex Rivera
SerialSN ····
ModelMacBook Pro 14 · Apple Silicon
OSmacOS 15.5
StatusTechnical details ▾
ManagementManaged
RemoteDeskConnected v0.9
Last seen2 min ago
Recent historyHistory tab →
14:21 · support session ended · audit ✓
09:03 · profile “Wi-Fi Corp” installed
Aug 5 · compliance re-evaluated · pass
Mini-frame · Technical details drawer (admin-only) · R08collapsed by default
Channel internals live here — behind one click, for admins who need them — so the product UI stays free of engineering vocabulary.
MDM channelEnrolled · Healthy last check-in 14 min
AGENT channelOnline v0.9 · heartbeat 2 min
CLOUD policyBaseline security v3 · evaluated 12 min ago
EnrollmentUDID ···· · profile v3 · APNs ok
CanonicalHeader (identity + 3 friendly status chips + action bar + tabs) is fixed across tabs C-03/C-04 and the Work/Lifecycle/History tabs. The 3 chips map to MDM (Management · Managed), Agent heartbeat (RemoteDesk · Connected), CLOUD policy (Security · Compliant) — channel names surface only in the Technical details drawer (R08).
PermissionsAction-bar buttons disabled when Agent is Offline (tooltip explains which channel is missing). Sensitive actions require admin re-auth + employee consent → C-07 flow.
StateWork tab shows only policy-allowed work records (rules in C-09); it renders a permission-denied explainer when the admin lacks the work role (Part E).
AuditEvery command, profile push, support session and lifecycle event on this device appears in History with actor + timestamp; history is read-only.
C-04 · IT Console · Device detail · Security tab · P0

Security posture with reasons, not just verdicts

Key outcome (§17.8): see FileVault, firewall, OS and policy exceptions for one Mac. Compliance is a computed verdict — always show which rule produced it and the one-click remediation, with confirmation and audit.

DataMDMCLOUDStatesCompliance → Part C
console.remotedesk.io/devices/mbp14-····/securityWireframe · Demo data
Alex Rivera · MacBook Pro 14 SN ····
OnlineManagedNeeds attention
Overview Security Software Work Lifecycle History
FileVault
On
Recovery key escrowed ····
Firewall
On
Stealth mode on
OS posture
Update available
15.5 installed · 15.6 available 9 d
Screen lock
Policy applied
Require after 5 min
Compliance · Baseline security policy v3Needs attention
FileVault enabledrule: disk encryption requiredPass
Firewall enabledrule: firewall onPass
!OS update overduerule: install updates within 14 days · 9 of 14 elapsed
Rules come from Policies (C-11). “Send update command” asks for confirmation, then issues an MDM command and writes an audit event.
DataPosture facts (FileVault, firewall, OS version) from MDM inventory; verdicts computed in CLOUD against the assigned policy. No Agent data is needed on this tab.
StateCompliance states: Compliant / Needs attention / Non-compliant / Unknown. A device Offline > 7 days degrades to Unknown rather than keeping a stale verdict.
ConfirmRemediation buttons open a confirm dialog naming the exact MDM command and the target device; destructive commands (lock/wipe) additionally require typed confirmation (C-10).
ErrorsA failed command surfaces inline on the rule row (Failed chip + error code + retry) and in History — never silently.
C-05 · IT Console · Enrollment · P0

Invitation to managed, with every stalled step visible

Key outcome (§17.8): get a new Mac from invitation to managed state. Enrollment crosses three systems — invitation (CLOUD), MDM profile (MDM), Agent install (AGENT) — so the pipeline shows each device’s exact position, including Failed.

DataCLOUDMDMAGENTStatesMDM · Agent → Part C
console.remotedesk.io/devices/enrollmentWireframe · Demo data

Enrollment

Invitation → MDM profile → RemoteDesk Agent → managed
3
Invitation sent
1
Pending
1
Enrolling
12
Managed
In-flight enrollments
EmployeeInvitedStateLast event
Frontend Engineer · HanoiAug 5PendingInvitation opened · profile not yet installed
Product Manager · TokyoAug 6EnrollingMDM profile installing on device
Backend Engineer · ManilaAug 4FailedProfile install rejected · MDM-102
QA Engineer · OsakaAug 7ManagedEnrolled · Agent install queued
Send enrollment invitation
Email linkCode
Before joining, the employee sees the org’s device-management and work-capture policies (A-02).
StatePer-device MDM states (Part C): Not enrolled → Pending → Enrolled → Healthy, with Failed as a branch that keeps the invitation valid. Agent install is a separate track (Not installed → Installing → Online).
DataInvitation lifecycle is CLOUD; profile install events come from the MDM protocol; Agent install status arrives with the first heartbeat.
ErrorsFailed rows keep the raw MDM error code and a retry that re-issues the profile. Two consecutive failures escalate to an exception on C-01.
AuditInvitation sent/opened, enrollment, profile install and Agent install each write an audit event (§17.13 acceptance).
C-06 · IT Console · Security & compliance · P0

Fleet posture and the exceptions that break it

Key outcome (§17.8): see FileVault, firewall, OS and policy exceptions across the fleet. Fractions, not gauges: posture reads “11 of 12”, and every exception carries its reason and remediation.

DataMDMCLOUDStatesCompliance → Part C
console.remotedesk.io/securityWireframe · Demo data

Security & compliance

Baseline security policy v3 · applies to all Macs · evaluated hourly
FileVault on
11/12
1 exception
Firewall on
12/12
no exceptions
OS current
10/12
2 updates overdue soon
Compliant Macs
10/12
2 exceptions ↓
Exceptions · with reasons
DeviceEmployeeRule failedStateSince
MacBook Pro 16 SN ····Data Analyst · SingaporeFileVault must be onNon-compliant2 d
MacBook Pro 14 SN ····Alex Rivera · Software Engineer · TokyoOS update within 14 daysNeeds attention9 d
Row → the device’s Security tab (C-04). Remediation = confirm dialog → MDM command → audit event → re-evaluate (flow D-5).
DataPosture facts from MDM inventory; rule evaluation and exception list computed in CLOUD. Devices in Unknown (offline > 7 d) are listed separately, not counted as compliant.
PermissionsRemediation requires the device-admin role; viewing posture is available to all Console roles. This area never links into Work data.
StateFixing the rule flips the device Needs attention/Non-compliant → Compliant on next evaluation; the exception row animates out and History records the transition.
Confirm / auditEvery remediation shows the exact command before sending and lands in the audit log with actor, device, command, result.
C-07 · IT Console · Remote support (diagnostics) · P0

Diagnostics — a read-only health snapshot, with consent

Key outcome (§17.8): when an employee reports a problem, IT collects a read-only diagnostic bundle — the one and only remote-support capability (ADR-0005). No screen viewing, no remote terminal, no file access: RemoteDesk cannot control the device or read its files. The bundle lifecycle (Idle → Requested → Collecting → Collected / Failed) is visible throughout, and §17.16 requires consent + audit on collection.

DataAGENTCLOUDStatesRemote support → Part C
console.remotedesk.io/support/diagnosticsWireframe · Demo data

Diagnostics

Bundle lifecycle:
Idle Requested Collecting Collected/ Failed
Support requests
Frontend Engineer · HanoiRequested
“External display not detected after OS update.” · 5 min ago
runs on the Mac’s next check-in, with consent
Recent diagnostics · audit
Aug 7 14:21 · Diagnostic #4 · collected · consent ✓ · audit ✓
Aug 6 16:04 · Diagnostic #3 · collected · consent ✓ · audit ✓
Aug 2 11:30 · Diagnostic #2 · declined by employee · audit ✓
Diagnostic #5 — Alex Rivera · MacBook Pro 14 Collected14:21
Read-only: a health snapshot the employee consented to. IT sees these fields, never the screen, a shell, or file contents (ADR-0005).
os_version · macOS 26.6.1 (25G76)
uptime · 39h 38m
disk_free · 17.2 GB of 460 GB
network · en0 192.168.1.24 · DNS 1.1.1.1
top_processes · WindowServer, Chrome, node … (15)
battery · 88% · Normal · 214 cycles
Every field is a query from the employee-visible diagnostic set (A-08). Collection is written to the audit log (C-11).
Alternate state · Failed collectionFailed
CollectingFailed
Bundle could not be collected. The employee declined, or the device stayed offline past the request window. Nothing was collected; the attempt is still audited.
ScopeDiagnostics is read-only: no screen viewing (ADR-0002), no remote terminal, no file transfer (ADR-0005). The bundle is a fixed set of health queries — device state, not files, not activity.
PermissionsConsent is separate from MDM admin rights (§17.11): collection needs the employee’s acceptance, and the exact query set is visible to them in the Agent’s Privacy Center (A-08).
StateIdle → Requested (IT initiates) → Collecting (Agent runs the query set on next check-in) → Collected / Failed. Each transition is timestamped and audited.
AuditEvery collection writes an audit entry with who requested it and when (C-11); the recent-diagnostics list is the queryable record (§5.4).
C-08 · IT Console · Software · P1

Inventory in, required apps out

Key outcome (§17.8): inventory and install/update/remove company apps. Marking an app required starts the deploy flow (D-4); each device reports its own install state back through the two channels.

DataMDMAGENTCLOUDStatesInstall states (per device)
console.remotedesk.io/softwareWireframe · Demo data

Software

Required apps · deployed via MDM managed apps · versions reported by Agent
Required appsInventory
AppRequired forInstalledState
RemoteDesk Agent v0.9All Macs11/12Update required · 1
SlackAll Macs12/12Installed
FigmaDesign group2/3Installing · 1
Endpoint AVAll Macs10/12Failed · 1 Pending · 1
Inventory snapshotby app · fleet-wide
AppVersions seenMacsOutdated
Chrome2 versions123
Zoom1 version90
Per-device install states
Not installedPendingInstallingInstalledUpdate availableFailed
Clicking a count opens the per-device list with the raw MDM/install error for Failed rows.
DataDeploy/update/remove commands travel over MDM (managed software §17.5); fine-grained installed-version telemetry comes from the Agent heartbeat; the required-app policy object lives in CLOUD.
StateMarking required → target devices go Pending → Installing → Installed; failure keeps the error and retries are explicit, never silent loops.
ConfirmRemoving an app from devices requires confirmation listing affected Macs; removal is audited.
FlowSee D-4: mark required → deploy → device reports version (also visible to the employee in A-03 My Device).
C-09 · IT Console · Work Records · Timesheets · P1 · renamed in V1.1 (R09)

Work Records: outputs, not activity

Key outcome (§17.8): review approved and submitted work records only — never raw activity. This area is intentionally boring: what employees chose to submit, and the approvals queue. Nothing here knows which apps anyone used. Renamed from “Work” to “Work Records” in V1.1 because the name must say what admins actually receive: approved and submitted outputs — records, not a window into work.

DataCLOUDStatesTime entry → Part C
Managed does not mean monitored
The Console has no raw activity, timelines, app or website data, no screenshots, and no productivity scoring of any kind (§5.14). Employees review and submit in the Agent (A-06/A-07); admins see submitted records only. Visibility is governed by the workspace work role — being an MDM administrator grants nothing here (§17.11).
console.remotedesk.io/work-records/timesheetsWireframe · Demo data

Timesheets

Week 32 · submitted and approved records
Week 32Team All
Entry states Draft · employee-side onlyNeeds ReviewApprovedSubmittedExportedConflict
EmployeeWeekProject · matterHoursStatus
Software Engineer · TokyoW32Client A · Platform38.5Submitted
Product Designer · OsakaW32Client B · Brand36.0Approved
Data Analyst · SingaporeW32Internal · Reporting12.5Needs Review
Backend Engineer · ManilaW31Client C · Integrations41.5Conflictreturned to employee
QA Engineer · OsakaW31Client A · Platform39.0Exportedpayroll ✓
Approvals queue · 1
Data Analyst · Singapore · Internal · Reporting · 12.5h
Narrative: “Weekly reporting pipeline maintenance and Q3 dashboard prep.”
PermissionsThis whole area requires the workspace work role (approver/manager per policy). MDM/device admins without it see a permission-denied explainer, not the data (§17.11, Part E).
StateTime-entry machine (Part C): Draft → Needs Review → Approved → Submitted → Exported, plus Conflict. Draft never leaves the employee’s Mac view; the legend row marks it employee-side.
ConflictOverlap detection flags Conflict and returns the week to the employee to resolve in A-07; admins cannot edit employee entries, only approve or return with a note.
Anti-goalNo leaderboards, no scores, no per-minute views, no “active time” meters — by design, not omission (§5.14, §17.16).
C-10 · IT Console · Lifecycle · P1 · deepened in V1.1 (R07)

Employee + Device Lifecycle Operations — the board, plus the two workflows

Key outcome (§17.8): track procure → ship → assign → recover → wipe → reassign. The 9-state board is unchanged from V1 (§17.14). New in V1.1: Lifecycle is framed as Employee + Device Lifecycle Operations — two workflow strips run the board: Onboarding (12 steps, ends at DAY-1 READY → C-12) and Offboarding (12 steps, ends at Reassign / Retire → C-13). Board scrolls horizontally inside the frame.

DataCLOUDMDMStatesLifecycle → Part C
console.remotedesk.io/lifecycleWireframe · Demo data

Lifecycle

Every transition is recorded as a LifecycleEvent (§17.4)
Procured
MacBook Air 13
SN ····
Procured
In transit
MacBook Pro 14
SN ····
→ Frontend Engineer · Hanoi
In transit
Assigned
MacBook Air 13
SN ····
Product Manager · Tokyo
Assigned
Active
9
managed Macs
collapsed → C-02
Recovery
MacBook Pro 14
SN ····
offboarding · checklist ↓
Recovery
Received
empty
Wiped
empty
Available
MacBook Air 13
SN ····
inventory · Tokyo office
Available
Retired
MacBook Pro 13
SN ····
2021 · battery EOL
Retired
Onboarding workflow · employee + device · 12 stepsends at Day-1 Readiness → C-12
1 Create employee 2 Approve device profile 3 Procure / from inventory 4 Assign serial 5 Ship 6 Deliver 7 Enroll · management profile 8 Install Agent 9 Apply policies 10 Required software 11 Validate health · VPN 12 DAY-1 READY ✓
Offboarding workflow · employee + device · 12 stepsrecovery detail → C-13
1 Employment ends 2 Revoke access 3 Lock device 4 Return label 5 Schedule pickup 6 In transit 7 Receive 8 Inspect condition 9 Secure wipe 10 Record condition 11 Return to inventory 12 Reassign / Retire
Offboarding checklist · MacBook Pro 14 · SN ····Recovery
Lock device & revoke corporate access MDM · audited
Return shipping scheduled CLOUD
Receive & inspect · record condition
Secure wipe (typed confirmation required) MDM · audited
Return to inventory → reassign or retire
StateLifecycle states (Part C): Procured / In transit / Assigned / Active / Recovery / Received / Wiped / Available / Retired. Only legal transitions are offered on each card (e.g. Received → Wiped, never Received → Active directly).
ConfirmWipe is the highest-risk action in the product: typed device-serial confirmation, second-role approval if policy demands, and an immutable audit entry. Lock requires standard confirmation.
DataBoard and events are CLOUD; lock/wipe execute over MDM. Shipping fields are manual/partner-fed in V1 (no warehouse automation — §17.3 defer).
FlowOffboarding flow D-6 walks Recovery → Received → Wiped → Available; per-device recovery has its own full screen in V1.1 (C-13). Onboarding’s readiness gate is C-12. Approved work/timesheet records are preserved per retention policy (§6.2).
C-11 · IT Console · Policies & audit · P1 · revised in V1.1 (R04)

Two policies that must never look like one — and the Work Intelligence switch

Key outcome (§17.8): separate device/security policy from work/privacy policy. §17.16 requires the split to be visually distinct — device policy is ink and management-flavored, work policy is volt-tinted and Agent-flavored, with separate editors and separate audit trails. New in V1.1 (R04): Work Intelligence is a workspace configuration, not a product constant — the panel below enables it, picks the work mode, and selects features; turning it off removes the entire WORK area from every employee’s Agent.

DataCLOUDMDMAGENTStatesPolicy versions · audit
console.remotedesk.io/policiesWireframe · Demo data

Policies

Separate objects · separate editors · separate audit trails (§17.16)
Device & security policy
Baseline security v3 · applies to all Macs
Apple Device Management
FileVault required · recovery key escrowed
Firewall on · stealth mode
OS updates within 14 days
Screen lock after 5 min
Wi-Fi / VPN / certificate profiles
v3 · edited Aug 6 · audit ✓
Work & privacy policy
Work capture v2 · shown to employees before it takes effect
RemoteDesk Agent
Capture: app/window/domain/file metadata only
Screenshots: off (separate permission if ever enabled)
Exclusions: employee-managed, always allowed
Private Mode: always available, immediate
Admin visibility: submitted records only
v2 · edited Jul 30 · audit ✓ · announced in Agent ✓
Work Intelligence · workspace configurationnew in V1.1 · R04
Enable Work Intelligence
◉ Automatic — no timer needed; activity becomes reviewable sessions ○ Timer — explicit start/stop with client/project/matter ○ Hybrid — timer as intent, context fills the gaps
☑ My Day ☑ Timeline ☑ Work summary ☑ Missing-time suggestions ☐ Timer ☐ Timesheet & approvals
App & window metadata
Browser domain (never full URL)
File names · paths redacted
ScreenshotsOff
Private ModeAlways available
Private Mode has no toggle — it cannot be configured away by any workspace.
Turning Enable off removes the WORK group from every employee’s Agent nav and menu bar — the group disappears entirely; nothing renders disabled (R01). Changes are versioned and announced in the Agent before they apply.
Preset A · IT-onlyWork Intelligence off
Pure device management, security and support.
Agent nav
Home · My Device · Support
Privacy · Settings
no WORK group — absent, not grayed
Preset B · Remote teamAutomatic mode
Work records for distributed employees — no billable time.
Agent nav
Home · My Device · Support
WORK My Day · Timeline
Privacy · Settings
Preset C · Professional servicesHybrid + Timer
Billable work: timer, timesheets and approvals on top of B.
Agent nav
Home · My Device · Support
WORK My Day · Timeline · Timesheet
Privacy · Settings
Quiet, not invisible
Work-policy changes are versioned, announced in the RemoteDesk Agent before they apply, and always readable by every employee in the Privacy Center (A-08). Device policy and work policy are edited by different roles and never merge into one document.
Audit logfilter by actor · action · target · immutable
TimeActorActionTarget
Aug 7 14:21IT admin · TokyoDiagnostic bundle collected · consent ✓MacBook Pro 14 · SN ····
Aug 7 13:48IT admin · TokyoPolicy edited · Baseline security v2 → v3Device & security policy
Aug 6 17:10Approver · SingaporeTimesheet approved · W32Product Designer · Osaka
Aug 5 09:30IT admin · TokyoWipe command issued · typed confirmation ✓MacBook Pro 14 · SN ···· (recovery)
PermissionsDevice policy: device-admin role. Work/privacy policy: workspace-owner role. Neither role implies the other; the UI enforces and displays the split (§17.11).
StatePolicies are versioned; a work-policy version is Pending-announce until the Agent has surfaced it to employees, then Active. Device-policy versions push profiles on activation.
AuditThe audit log is append-only and captures policy edits, sensitive commands, support sessions, approvals and lifecycle events with actor + timestamp (§5.3, §17.13).
ConfirmPublishing either policy shows a diff against the current version before confirm.
Workspace configThe Work Intelligence panel is part of the Work & privacy policy object (workspace-owner role). Enable/mode/features drive which WORK screens exist in the Agent (A-00/A-05/A-06/A-07) and whether Work Records (C-09) appears in the Console. Data-capture toggles map to the §5.5 capture list; screenshots stay a separate permission that this panel alone cannot grant.
C-12 · IT Console · Lifecycle · Day-1 Readiness · P0 · new in V1.1 (R06b)

Is this employee ready to start work Monday?

The per-employee readiness list: every new hire in the next 7 days, with the full chain — employment, Mac, shipping, enrollment, Agent, policy, software, VPN — collapsed into one answer per person. This screen carries P0 visual weight in V1.1: it is the first thing the high-fi demo shows, because it is the question a pure MDM cannot answer.

DataCLOUDMDMAGENTStatesLifecycle · MDM · Agent · Compliance → Part C
The strategic line
Jamf asks “Is this Mac compliant?” — RemoteDesk asks “Is this employee ready to start work Monday?” Compliance is one input; readiness is the product.
console.remotedesk.io/lifecycle/day-1-readinessWireframe · Demo data

Day-1 Readiness

3 new hires in the next 7 days · 2 ready · 1 at risk
Window 7 days
Alex Rivera · Software Engineer · Tokyo · starts Mon Aug 11
Employment ✓ Mac assigned · MacBook Pro 14 · SN ···· Shipping · delivered Enrolled ✓ Agent connected ✓ Security policy ✓ Required software 5/5 VPN ✓
DAY-1 READY ✓
Sarah Lee · Product Designer · Singapore · starts Mon Aug 11
Employment ✓ Mac assigned · MacBook Air 13 · SN ···· Shipping · in transit Enrollment · pending delivery Agent · pending Security policy · pending Required software · pending VPN · pending
Expected delivery: Monday 2:00 PM — after her start time. Options: expedite shipping, or prepare a loaner from Singapore inventory (2 available).
AT RISK
QA Engineer · Osaka · starts Wed Aug 13 · all 8 checks passing
DAY-1 READY ✓
DataReadiness is a CLOUD aggregation per employee: employment (People record), assignment + shipping (LifecycleEvents), enrollment (MDM), Agent heartbeat (AGENT), policy + software + VPN (CLOUD evaluation). Each check links to the screen that fixes it (C-05, C-08, C-13, C-03).
StateAn employee is DAY-1 READY only when all checks pass before their start date; any pending check within 72 h of start flips the card to AT RISK with the blocking reason and the recovery options. States come from the Part C matrices — readiness adds no new chip vocabulary.
PriorityP0 in V1.1. C-01’s “New hires” tile deep-links here; this screen and C-13 are the two the high-fi demo must nail — 30 seconds to show a customer this is not another MDM.
EmptyNo upcoming hires: calm empty state with “Create a new hire” (People → New Hires), never a bare table.
C-13 · IT Console · Lifecycle · Device Recovery Detail · P1 · new in V1.1 (R07b)

One recovery, walked to the end

The full recovery timeline for one offboarding device: access revoked → locked → return label → pickup → in transit → received → inspect → secure wipe → inventory. Every step is timestamped and audited; the current step always names the next action. The post-receipt inspection and the wipe’s terminal choice (reassign or retire) are shown as mini-frames below.

DataCLOUDMDMStatesLifecycle · Device → Part C
console.remotedesk.io/lifecycle/recovery/mbp14-····Wireframe · Demo data
Lifecycle / Recovery / MacBook Pro 14 · SN ····
MacBook Pro 14 SN ····
Previously: Backend Engineer · Manila · employment ended Aug 3
RecoveryIn transit
Recovery timelineall steps audited
Access revoked · corporate accounts + certificates Aug 4 09:12 · audit ✓
Device locked · management lock command Aug 4 09:15 · audit ✓
Return label created · SF Express · sent to employee Aug 4 10:02
Pickup completed Aug 5 16:40
In transit — current step expected Tokyo office Fri Aug 8
Received · confirm at intake
Inspect & record condition mini-frame ↓
Secure wipe (typed confirmation required) audited
Return to inventory → reassign, or retire
Shipping · SF ExpressIn transit
TrackingSF ···· ···· 8841
FromManila
ToTokyo office
ExpectedFri Aug 8 · before 18:00
Device condition
Pending
Recorded at inspection, after receipt.
Next action
Confirm receipt when the package arrives — that unlocks inspection.
enabled on arrival scan or manual check-in
Variant · after receipt — InspectionReceived
◉ Good · ○ Fair · ○ Damaged — needs repair
Battery health91% Keyboard · trackpadOK Charger returnedYes
Opens the typed-confirmation dialog: type the device serial to confirm. Second-role approval if policy requires. Immutable audit entry.
Variant · after wipe — terminal choiceWiped
Wipe verified Aug 9 11:20 · audit ✓. The device leaves Recovery by exactly one of two doors:
Inventory → Available (reassignable, D-1). Retire → terminal state with disposal note. Approved work/timesheet records and audit history survive the wipe per retention policy (§6.2.8).
StateThe timeline is the Lifecycle machine walked linearly: Recovery → Received → Wiped → Available / Retired. Steps can only complete in order; skipping is impossible in the UI, not just discouraged.
ConfirmSecure wipe keeps the V1 rule: typed device-serial confirmation, optional second-role approval, immutable audit. Lock and revoke were confirmed at offboarding start (C-10).
DataTimeline and shipping are CLOUD (partner-fed tracking, manual in V1 — no warehouse automation, §17.3); lock and wipe execute over MDM. Serial and tracking numbers render masked in demo data.
OverdueA return not received by the expected date + 3 days flips the recovery to overdue: C-01’s Recovery card counts it, and this screen shows an escalation banner (contact employee · re-issue label · report lost → lock stays on).
A-00 · RemoteDesk Agent · Home · P0 · new in V1.1 (R02) · the default screen

The first screen answers: is my work Mac ready?

Home is what opens when the employee opens RemoteDesk — and it is an IT screen, not a work screen. Hierarchy on the page: Device → Attention → Support → Work. Three status dots give the one-glance answer; the WORK section sits last, carries an Optional tag, and disappears entirely when the workspace runs IT-only (C-11 preset A).

DataMDMAGENTCLOUDStatesMDM · Agent · Compliance → Part C
RemoteDesk — HomeWireframe · Demo data
Good afternoon, David.
Your Mac is ready for work.
Protected Managed by Demo Company RemoteDesk connected
Device statusMy Device →
FileVault encryptionOn
FirewallOn
macOS15.6 available
Required software4 of 5 installed
Needs your attention · 1
macOS 15.6 update
Company policy asks for updates within 14 days — 5 days left. Installing takes about 30 minutes.
IT support
Something not working? IT can collect a read-only diagnostic snapshot — you approve first, and IT never sees your screen or files.
last diagnostic Aug 6 · you accepted · read-only
Work OptionalMy Day →
Today’s work 6.2h · 2 need review
Only what you submit is ever shared.
Variant · IT-only workspace (C-11 preset A)Work Intelligence off
RemoteDesk
Home My Device Support Privacy Settings
The WORK group is completely absent — no grayed items, no teaser. Home drops the Work card; the grid becomes Device / Attention / Support. The product is complete without it.
DefaultHome is the window’s default screen (R02). The three dots map to CLOUD compliance verdict (Protected), MDM enrollment (Managed by {Company} — links to A-03), and Agent connection (RemoteDesk connected). Any dot degrading flips the headline (“Your Mac needs one thing before it’s ready”) and promotes the fix into Needs your attention.
HierarchySection order is fixed: Device → Attention → Support → Work. The Work card renders last, dashed, tagged Optional — and only when Work Intelligence is enabled for the workspace (C-11). It shows totals and review counts only; no timer is rendered on Home.
AttentionAttention items are actionable requirements only (update due, software failed, permission missing) with the policy reason and a scheduling choice — never alarms. Empty attention section collapses to a single “Nothing needs your attention” line.
Support“Get help” opens A-04 pre-focused on the request form — acceptance criterion 5: one click from Home.
A-01 · RemoteDesk Agent · Menu bar · P0 · rebuilt in V1.1 (R05)

Support-first by default — the Timer is conditional content, not identity

Redesigned per R05. The default menu bar answers “is my Mac okay, and where is help?” — device health and support lead. The WORK block appends only when the workspace enables Work Intelligence, and the Timer block only in timer/hybrid mode. No timer digits sit in the menu bar by default: the Timer is conditional content, not the product’s identity.

DataMDMAGENTStatesMDM · Compliance · Work capture → Part CWireframe · Demo data
1 · Default state — always present
RDRemoteDesk
Demo Company
Protected Your Mac is protected and managed.
SecurityCompliant
Get IT support
My Device Open RemoteDesk ↗
2 · Attention state — when something is due
RDRemoteDesk
1 item
macOS 15.6 update
due in 5 days · ~30 min
Get IT support
My Device Open RemoteDesk ↗
Menu-bar icon gains a small warning dot. Same calm register — a reminder, not an alarm.
3 · Conditional appendages — only if enabled
Work · appended when Work Intelligence is on
Today’s work
Platform project · 6.2h · 2 to review
Private Mode — pause capture
Timer · appended only in timer / hybrid mode
0:42:10
Client A · Platform
These blocks append below the default rows — they never replace them. Timer digits appear in the menu bar only while a timer runs in timer/hybrid workspaces.
IdentityDefault popover = device health + support (R05): Protected headline, Security row, Get IT support. Work rows and the Timer are appendages gated by C-11 workspace config — in an IT-only workspace states 1 and 2 are the entire menu bar experience.
StateThe icon reflects the highest-priority state: normal, attention dot, support-session glyph while a session is active, private/paused glyph when capture is paused, offline glyph when local-only. Work-capture states (Part C) surface only when Work Intelligence is on.
Private ModeLives in the WORK appendage (there is nothing to pause in an IT-only workspace). Toggling pauses work-context capture immediately; the block renders as Private in A-06. Scheduled privacy periods live in A-08.
Support“Get IT support” opens A-04; during an active session the dropdown pins a session row with an End control. No admin capability surfaces here; “Demo Company” links to A-03 for what management means.
A-02 · RemoteDesk Agent · Onboarding · P0

Device management and work capture — explained separately, then enroll

Prototype content (§17.6): explain device management and work capture separately; permissions; company policy; enrollment. The two halves of the product get two distinct cards so consent is informed, not bundled.

DataCLOUDMDMAGENTStatesMDM · Agent → Part C
Welcome to RemoteDeskWireframe · Demo data
1 · Device management2 · Work capture3 · Permissions4 · Company policy5 · Enroll
RD
Two things, explained separately.
Your company manages this Mac. You manage your work record. They are not the same permission.
Device management · for ITApple Device Management
Sets up Wi-Fi, VPN and security settings
Keeps FileVault, firewall and OS updates on
Installs required work apps
Can lock or erase this Mac if it’s lost or when you leave
Work capture · for youRemoteDesk Agent
Builds your day from app/window metadata
You review, edit and classify before anything is formal
Private Mode and exclusions, always available
Your company sees only what you submit
macOS permissions requested next
Accessibility · required for activity metadata Notifications · reminders & support Login items · start at login Screen Recording · never requested — remote screen viewing does not exist in this product
OrderTransparency before permission prompts (§5.11): steps 1–2 explain, step 3 requests, step 4 shows the org’s device + work policies (§5.12), step 5 enrolls (MDM profile, then Agent registration).
Permission deniedIf Accessibility is declined, the Agent still enrolls the device and runs device features; work capture stays off with a persistent, calm fix-it banner (Part E).
StateEnrollment progress mirrors C-05: this device moves Pending → Enrolling → Managed; failures show the same error code the admin sees.
Copy ruleNever bundle the two consents into one “Accept all”. Each card links to its own detail sheet.
A-03 · RemoteDesk Agent · My Device · P0 · was A-06 in V1 · moved forward (R03)

Four questions, answered without asking IT

Prototype content (§17.6): model, OS, management status, Agent status, security, updates, required software — restructured in V1.1 around the four questions an employee actually has: Is my Mac managed? Is it secure? Is anything required of me? What can my company manage? Same underlying states as C-03 — management is visible, so it never feels covert.

DataMDMAGENTStatesMDM · Agent · Compliance → Part C
RemoteDesk — My DeviceWireframe · Demo data
MAC
MacBook Pro 14 · Apple Silicon
macOS 15.5 · SN ····
1 · Is my Mac managed?
ManagementManaged by Demo Company
RemoteDeskConnected v0.9 · synced 1 min ago
2 · Is it secure?
FileVault encryptionOn
FirewallOn
Security checkUpdate needed
3 · Is anything required of me?
macOS update15.6 available
SlackInstalled
FigmaInstalling
Endpoint AVFailed
4 · What can my company manage?
Security settings, Wi-Fi, VPN and certificates
Required work apps · install and update
Lock or erase this Mac if it’s lost or when you leave
Not your files, messages, browsing or personal accounts
TransparencyStates here must equal what C-03 shows for this device — one source of truth rendered on both surfaces, in the same friendly labels (R08; no channel jargon on the employee side either).
Trust-critical“View Device Management Policy” is the trust-critical element of this screen: question 4 is answered by the actual readable policy (the A-02 step-4 document), not a marketing summary. It must always be one click away, never behind support, and always current with the policy version in C-11.
UpdatesOS updates initiated here are user-scheduled (“tonight”); if policy enforces a deadline, the deadline is shown, not sprung.
ErrorsA failed required-app install shows the same error the admin sees in C-08, with Retry and “Ask IT” (opens A-04 pre-filled).
A-04 · RemoteDesk Agent · Support · P0 · was A-07 in V1 · moved forward

Help that announces itself

Prototype content (§17.6): request support, connection status, active remote-session state, diagnostics. During a session, a banner stays pinned with the session state and an End control the employee can always reach (§17.11).

DataAGENTCLOUDStatesRemote support → Part C
RemoteDesk — SupportWireframe · Demo data
IT support session active — an IT admin is running a terminal session (never your screen).
Started 14:02 · 12:41 elapsed · session is audited
Active
Get IT support
Something isn’t working
Requested IT has been notified · you’ll get a consent prompt before anyone connects
Share diagnostics
Send system info and Agent logs to IT to speed things up. You’ll see the exact contents before sending.
Recent sessions on this Mac
Aug 7 14:02 · Diagnostic bundle · you accepted · collected
Aug 6 16:04 · Diagnostic bundle · you accepted · collected
Aug 2 11:30 · request expired · nothing collected
ConsentThe consent prompt names the admin and states exactly what will be collected (the read-only diagnostic set, shown in full). Decline ends the request as Failed on the Console side — nothing is collected, attempt still audited.
StateSession states mirror C-07 exactly; the banner persists across all Agent screens and the menu bar while Active. Ending from either side transitions to Ended for both.
PermissionsSupport sessions never request macOS Screen Recording — screen viewing does not exist in this product (ADR-0002); support permissions stay separate from work capture (§17.11).
DiagnosticsDiagnostics sharing is explicit-action with a content preview; nothing is pulled silently.
A-05 · RemoteDesk Agent · My Day · P0 · was A-03 in V1 · WORK group · Optional

My work, my numbers, my call

Prototype content (§17.6): current work, work time, sessions, missing/unclassified suggestions, daily summary, End My Day. In V1.1 this is no longer the default screen — Home (A-00) is; My Day heads the optional WORK group and exists only when the workspace enables Work Intelligence (C-11). It remains a personal work journal — deliberately nothing here resembles a monitoring dashboard (§17.16).

DataAGENTStatesWork capture · Time entry → Part C
RemoteDesk — My DayWireframe · Demo data
My Day · Thursday, August 7
You decide what becomes formal. Suggestions never auto-add.
Platform project · 0:42:10
Work time
6.2h
recorded so far
Meetings
1.0h
2 sessions
Breaks
0.8h
incl. lunch
To review
2
1 unclassified · 1 missing →
Today’s sessions
Project sessions Internal Unclassified Private · not captured
Suggestions · you confirm, nothing auto-adds
10:12–10:30 · 18 min before your first timer looks like Platform project
same document · same repo
13:44–14:31 · 47 min unclassified session
assign a project or mark break/private
Daily summary · draftDraft
Drafted from your confirmed sessions. You edit and approve — it is never sent anywhere on its own.
Anti-goalNo productivity scores, no percent-active gauges, no comparisons to teammates — the tiles are plain durations under the employee’s own control (§5.14, §17.16).
State“To review” counts exceptions only (§5.10). End My Day opens Daily Review: resolve missing time, classify sessions, approve the summary; unresolved items persist as Needs Review.
DataEverything on this screen is Agent-local plus CLOUD sync of confirmed items; raw events never leave the review pipeline (§5.5 ActivityEvent → WorkSession → summary → optional TimeEntry).
ConfirmSuggestion “Add” creates a session pending the employee’s classification — formal time entries only ever come from explicit action (§5.5 “never silently add”).
A-06 · RemoteDesk Agent · Timeline · P0 · was A-04 in V1 · WORK group · Optional

Understood sessions, with full edit control

Prototype content (§17.6): Simple/Detailed modes; edit, split, merge, classify, private, break. Simple shows understood work sessions; Detailed may expose app/file evidence — to the employee only, per privacy policy (§5.5).

DataAGENTStatesWork capture → Part C
RemoteDesk — TimelineWireframe · Demo data
Thursday, August 7
SimpleDetailed 41 events → 6 sessions
09:00
10:00
11:00
12:00
13:00
14:00
Platform project — feature work09:00–10:12
3 activity blocks merged · selected
10:12–10:30 · not recorded — see suggestion in My Day
Internal — code review10:30–11:24
Lunch break12:05–12:48
Platform project — docs12:52–13:40
Unclassified · 47 minAssign ▾
Private14:35–14:52 · nothing captured
Selected session
Platform project — feature work
09:00 – 10:12 · 1.2h
Platform project
All edits are undoable. Detailed mode shows this session’s evidence (apps · files) to you only.
Alternate state · Offline-localOffline-local
You’re offline. Activity is being stored only on this Mac and will sync when you reconnect. Nothing is lost; nothing is sent.
Banner sits above the timeline; the menu-bar icon shows the offline glyph. Queue status in A-09.
LayersAlways distinguish raw evidence → inferred WorkSession → formal TimeEntry (§5.8). Simple mode hides evidence; Detailed reveals it to the employee only.
StateBlock styles are the work-capture vocabulary (Part C): Tracking (solid), Idle/break (paper), Private/Excluded (dashed — no content exists), Unclassified (warning), Offline-local (banner).
InteractionEdit/split/merge/classify/private/break all act on the inferred layer; “Create time entry” is the only bridge into the formal layer (A-07).
PrivacyMarking private retroactively deletes captured content for that span, not just hides it; confirm dialog states exactly that.
A-07 · RemoteDesk Agent · Timesheet · P0 · was A-05 in V1 · WORK group · Optional

The formal record the employee submits

Prototype content (§17.6): weekly entries, project/matter, narrative, hours, status, conflict, export. This is the only layer that ever reaches the Console (C-09), and only when submitted.

DataAGENTCLOUDStatesTime entry → Part C
RemoteDesk — TimesheetWireframe · Demo data
Week 32 · Aug 4 – Aug 8DailyWeekly
DayProject · matterNarrativeHoursStatus
Mon 4Client A · PlatformImplemented enrollment flow error handling and…7.5Submitted
Tue 5Client A · PlatformDevice table state chips; review feedback…8.0Approved
Wed 6Internal · HiringInterview panel + debrief notes…2.0Needs Review
Wed 6Client A · PlatformOverlaps 13:00–13:30 with the entry above — adjust one of them.6.5Conflict
Thu 7Client A · PlatformDraft — from today’s sessions…6.2Draft
Week total 30.2h · 1 conflict blocks submission
StateMachine (§5.9): Draft → Needs Review → Approved → Submitted → Exported; Conflict is a blocking flag raised by overlap detection and must be resolved before submit.
VisibilityOnly Submitted (and later) states sync to C-09. Draft and Needs Review are employee-side; the admin cannot see or edit them.
ExportCSV, Excel, PDF, copy-as-text (§5.9); optional payroll/billing hand-off is a CLOUD integration, out of the Agent’s UI scope beyond the submit action.
BulkMulti-select supports bulk classify/approve/submit; destructive bulk actions confirm with a count.
A-08 · RemoteDesk Agent · Privacy Center · P0

The contract, readable any time

Prototype content (§17.6): what is captured / not captured, exclusions, Private Mode, visibility rules. This screen is the standing answer to “what does my company see?” — current org policy included, in plain words.

DataAGENTCLOUDStatesWork capture → Part C
Principles rendered on this screen
Managed does not mean monitored — device management rights (A-03) grant no work-content visibility. Quiet, not invisible — capture state is always visible (menu bar), and this page always reflects the current policy version.
RemoteDesk — Privacy CenterWireframe · Demo data
Captured · metadata only
Application name and window title
Browser domain (never the full URL)
File name, with path redaction
Time and foreground / idle state
Current Timer / project context
Never captured
No keystroke or password capture
No email/chat message-body capture
No clipboard capture
No camera or microphone capture for Work Intelligence
Screenshots off by default and not required for the core product
No remote screen viewing — support cannot see your screen. The capability does not exist in this product (ADR-0002).
Exclusions
Personal browser profileExcluded
Banking sitesExcluded
~/Personal folderExcluded
Private Mode
Pause capture now
Scheduled privacy
daily 18:30 – 09:00
Takes effect immediately. Private time shows as a dashed block — content is never captured.
Who can see what
IT admin · device & security state only
Approver · timesheets you submit
No one · your raw timeline, private time, excluded activity
Org policy: Work capture v2 · view full policy →
Your data. View, export or delete your personal work data (deletion honors org/legal retention where it applies — the screen says which).
SourceCaptured / never-captured lists are the §17.11 and §5.5 defaults verbatim; if the org enables anything beyond defaults (it cannot enable screenshots without a separate permission), this page shows it before it applies.
StateExclusion and Private states are Part C work-capture states; the menu bar reflects them instantly.
Data controlsView/export/delete per §5.11; delete requests that hit retention rules explain the rule instead of failing silently.
A-09 · RemoteDesk Agent · Settings · P0

Reliability, in one compact page

Prototype content (§17.6): sync, launch at login, shortcuts, offline queue, updates, diagnostics. Nothing clever — the settings a distributed employee actually needs when the network is bad.

DataAGENTStatesAgent → Part C
RemoteDesk — SettingsWireframe · Demo data
Connection
StatusSynced · 1 min ago
Offline queue0 pending · 0 failed
Behavior
Launch at login
Shortcut · Start/stop timer⌥⌘T
Shortcut · Private Mode⌥⌘P
Agent updatesAutomatic · v0.9
Data & diagnostics
Local data retentionPer company policy · 90 days
Diagnostics
OfflineQueue shows pending/failed counts (§5.13); failures list per-item errors and retry. Offline-local capture state is announced in A-06 and the menu bar, not buried here.
Repair“Repair agent” reinstalls Agent components without touching MDM enrollment; it warns what it will and won’t change.
PolicyRetention is read-only when set by org policy, with a link to the policy text in A-08.
Part C · State reference sheet · design-system extension (§17.17)

The badge vocabulary — all eight state matrices from §17.14

These chips are the design-system extension developers implement once and reuse everywhere: MDM/Agent/compliance badges, support-session states, work-session blocks and lifecycle states. Colors are the semantic set — volt never encodes status.

Color language healthy / positive transitional / attention failed / violation not yet / inactive formal / submitted dormant / terminal private / excluded — content does not exist
Deviceoverall device record · shown beside the serial · C-02, C-03, C-10
UnenrolledEnrollingManagedOfflineNon-compliantRecoveryWipedInventoryRetired
MDMApple MDM channel · never merged with Agent state · C-02, C-03, C-05, A-03
Not enrolledPendingEnrolledFailedHealthy
AgentRemoteDesk Agent channel · heartbeat-driven · C-02, C-03, C-08, A-03
Not installedInstallingOnlineOfflineUpdate requiredError
Compliancecomputed verdict · always with reasons · C-01, C-02, C-04, C-06, A-03
CompliantNeeds attentionNon-compliantUnknown ·Offline > 7 days degrades the verdict to Unknown
Remote supportsession lifecycle · every transition timestamped & audited · C-07, A-04
IdleRequestedConnectingActiveEnded/Failed
Work captureemployee-side only — never rendered in the Console · A-01, A-05, A-06, A-08
TrackingIdlePrivateExcludedOffline-localNeeds review
Time entrythe formal layer · §5.9 state machine · A-07, C-09
DraftNeeds ReviewApprovedSubmittedExported+Conflict ·Draft & Needs Review are employee-side; the Console sees Submitted onward (plus entries routed for approval)
Lifecycledevice asset journey · board columns in C-10 · readiness checks in C-12 · recovery timeline in C-13
ProcuredIn transitAssignedActiveRecoveryReceivedWipedAvailableRetired
ImplementationOne chip component, seven visual variants (ok / warn / bad / mute / ink / out / private-dashed). State names are the API strings; do not rename in the UI.
RuleMDM, Agent and Compliance are three independent chips on any device row — a device can be MDM-Healthy and Agent-Offline at once (C-02 shows this on purpose).
Volt disciplineVolt marks selection, primary CTAs and brand accents (active tab underline, selected card outline). If a chip is volt, it’s a bug.
Part D · End-to-end flows (§17.15) · seventh flow added in V1.1

Seven flows the prototype must walk without dead ends

Each node names the screen that hosts it. These are the click-through paths for the Figma/coded prototype — and the demo script: new hire → Day-1 ready → daily work → support → offboarding/recovery (§17.17). Screen references use the V1.1 numbering (Part B was renumbered; each renumbered screen carries a “was A-0x” note).

D-1 · New hire

§17.15 · onboarding workflow §6.1
Create employeerecord in PeopleConsole · People
Assign / procure Macfrom inventory or partnerC-10
Enrollinvitation → MDM profileC-05 → A-02
Install Agenton the managed MacC-05 · A-02
Apply policiesdevice + work, separatelyC-11
ReadyConnected · Managed · CompliantC-03 · gate: C-12

D-2 · Daily employee

§17.15
Menu barstate check · start timerA-01
My Daycurrent work + totalsA-05
Timelineedit / classify sessionsA-06
Missing-time reviewconfirm or dismissA-05
Daily ReviewEnd My Day · exceptions onlyA-05
Timesheetoptional · submit weekA-07

D-3 · IT support

§17.15 · consent + audit throughout
Employee requests helpA-04 (or A-01)
Admin opens Device detailC-03
Consent promptemployee acceptsA-04
Collect diagnostics (read-only)C-07
End sessioneither sideC-07 · A-04
Audit recordC-11

D-4 · Software

§17.15
Mark app requiredfor a device/employee groupC-08
Deploy / updateMDM managed-app commandC-08
Device installsemployee sees progressA-03
Version reportedAgent heartbeat → inventoryC-08 · C-03

D-5 · Security

§17.15
Device becomes non-compliantrule fails on evaluationC-06 · C-01
Admin sees reasonrule + since-whenC-04
Policy / actionconfirm → MDM commandC-04 · C-11
Compliant againre-evaluated · history entryC-03

D-6 · Offboarding

§17.15 · offboarding workflow §6.2
Employment endtriggers recovery checklistPeople → C-10
Lock / recoverrevoke access · MDM lockC-10 · C-13
Returnshipping / pickup / in transitC-13
Receive → Inspectcondition recordedC-13
Wipetyped confirmation · auditedC-13 · C-10
Reassign / retireback to D-1 or end of lifeC-13 → C-05

D-7 · Day-1 readiness

new in V1.1 · R06b · the demo’s opening flow
Employee createdstart date setConsole · People · New Hires
Device sourcedinventory or procureC-10 · C-12
Shiptracked to the employeeC-12
Enrollmanagement profile installsC-05 → A-02
Agentconnects · first heartbeatA-02 · C-12
Policydevice + work appliedC-11
Softwarerequired apps installC-08
DAY-1 READY ✓all checks pass before startC-12
PrototypeEach flow must be walkable in the prototype without dead ends; error branches (Failed enrollment, Failed session, Conflict) route to the alternate states in Part E.
RetentionD-6 preserves required audit and approved work/timesheet records per retention policy even after wipe (§6.2.8).
Part E · Required prototype states (§17.16)

Non-happy paths the prototype must demonstrate

§17.16: design empty, loading, offline, permission-denied, failed-command, non-compliant and recovery states. This index says where each one is demonstrated in this document; three screens carry full alternate-state mini-frames.

Required stateDemonstrated onNotes
EmptyC-02 mini-frame · C-10 empty columnsEmpty ≠ error: always an explanation plus the next action (send invitation).
LoadingC-02 mini-frame · C-01 annotationSkeleton blocks, never spinners over stale numbers.
OfflineC-02 rows (Agent Offline) · A-06 mini-frame (Offline-local) · C-02 cached-data bannerConsole offline = cached data labeled with its age; Agent offline = local capture continues, sync later.
Permission-deniedA-02 annotation (Accessibility declined) · C-03/C-09 annotations (missing work role)Mini-frame below. Explain who can grant access; never a bare 403.
Failed commandC-05 Failed enrollment row · C-07 failed-session mini-frame · C-08 failed installKeep the raw error code, offer retry, escalate after repeats.
Non-compliantC-04 reasons panel · C-06 exceptions table · C-02 chipVerdict always travels with its failing rule and remediation.
RecoveryC-13 full screen · C-10 Recovery column + checklist · C-02 recovery rowRecovery devices are unassigned but still audited; wipe path is D-6. C-13 adds the overdue-return escalation.
Alternate state · Permission-denied (Console, Work area)example
LOCK
Work records need the work role
Device administration doesn’t include work visibility. Ask a workspace owner to grant the approver role if reviewing timesheets is part of your job.
Alternate state · Permission-denied (Agent, Accessibility off)capture off
Work capture is off. macOS Accessibility permission was declined, so nothing is being recorded. Device management still works. Open System Settings →
Calm banner in A-05/A-06; menu-bar icon shows the paused glyph. Never a blocking modal.
MandateThe three full alternate-state mini-frames live on C-02 (empty + loading/cached), C-07 (failed session) and A-06 (offline-local banner); this page adds the two permission-denied patterns.
ToneError and empty states use the same calm register as the rest of the Agent — especially on employee screens, where alarm styling would read as monitoring pressure (§17.16).
← RemoteDesk IT