1. Choose your path
Start with the deployment model that matches your review and operating needs.
For the full comparison, see Hosting Options.
2. Run a small open-source pilot
If you are starting local-first, pilot Beacon on a small group before broad deployment. The fleet story differs by platform, so read the one you are rolling out to first: macOS ships MDM assets for Jamf, Fleet, and Rippling; Windows ships an MSI for Intune or SCCM; Linux ships.deb and .rpm packages that install and start the endpoint
themselves.
Decide three things up front:
- which agent harnesses are in scope
- whether events should stay local at first or forward into a security workflow
- which MDM group will receive the first system-mode package rollout
3. Deploy and validate
4. Expand or centralize
If the pilot is healthy, expand through MDM and add forwarding only where it matches your security workflow. Beacon preserves local JSONL even when you forward events downstream. Use Log Forwarding for Wazuh, Splunk HEC, Falcon LogScale HEC, Elastic, Datadog, Sumo Logic, Rapid7 InsightIDR, Microsoft Sentinel, object storage, local JSONL, and customer-managed pipelines. Usebeacon scan and beacon rules when you want local threat-detection checks over endpoint telemetry before or alongside downstream forwarding.
Move to Asymptote Managed when you need centralized retention, search, detections, fleet-wide visibility, governance, investigations, SSO/RBAC, audit trails, or rollout support. Once your organization is provisioned, endpoints join it one at a time: a developer runs beacon endpoint connect (or picks Asymptote Managed during the first install) and approves the device in the browser; on package or MDM installs an admin runs sudo beacon endpoint connect --system on the machine. Headless enrollment for fleets is a planned follow-up.
Contact us if you want Managed or Private Deployment guidance.
Related
MDM Deployment
Plan managed macOS rollout with the packaged system agent.
Log Forwarding
Forward Beacon events into security and observability platforms.
Security Review
Review local collection, data inventory, content handling, endpoint behavior, and disclosure policy.
Asymptote Managed
Review managed visibility, policy controls, investigations, and rollout support.

