Documentation Index
Fetch the complete documentation index at: https://docs.asymptotelabs.ai/llms.txt
Use this file to discover all available pages before exploring further.
For Security & IT Teams
Beacon gives security and IT teams local endpoint visibility into supported AI agent runtimes. It captures supported activity from Claude Code, Codex CLI, Cursor, and Claude Cowork, normalizes it into a stable endpoint event schema, and writes Wazuh-compatible JSONL for local inspection or customer-managed forwarding. Beacon is local-only by default. The endpoint agent does not require a Beacon-hosted account, remote policy fetch, or external network dependency during normal collection.Operational workflow
Deploy the endpoint agent
Use the signed and notarized macOS
.pkg for MDM deployment, or install the CLI directly for local evaluation. Production MDM deployments use system mode and write events to /var/log/beacon-agent/runtime.jsonl.Inventory and validate health
Track Beacon version, collector service health, runtime log freshness, configured harnesses, content retention mode, and log writability through your device-management platform.
Review retention settings
Select
full, redacted, or metadata retention based on your approved telemetry collection policy.Guides
MDM deployment
Plan managed macOS rollout with the packaged system agent.
Jamf
Deploy and inventory Beacon with Jamf Pro policies and extension attributes.
Fleet
Deploy Beacon with Fleet software, policies, queries, and scripts.
SIEM forwarding
Forward Beacon runtime JSONL to Wazuh or a customer-managed SIEM pipeline.
Endpoint event schema
Review the normalized JSONL contract used for endpoint events.
Supported surfaces
See supported runtimes, deployment modes, storage paths, and forwarding boundaries.
What to monitor
| Area | Recommended signal |
|---|---|
| Install coverage | Beacon package or binary version is present |
| Collector health | com.beacon.endpoint.collector is running |
| Event freshness | Last runtime event age is within your expected window |
| Runtime configuration | Configured harnesses match the approved deployment scope |
| Retention | Content retention mode matches policy |
| Forwarding readiness | Runtime log exists and is writable by the collector |

