Endpoint Platform Evaluation Checklist
The questions worth asking every vendor in this category — written so the answers are hard to give evasively.
Feature matrices are close to useless in this category, because every vendor can answer yes to almost every row. The questions below are written to be difficult to answer evasively, and to surface architecture rather than intent. Ask the same list of everyone, including us.
Architecture
Does the agent connect outbound only, or does it listen on a port? If there is an on-premises relay or appliance, what does it expose, where must it sit, and who is responsible for patching it?
Is the agent a compiled binary or does it require a runtime? If it requires one, whose vulnerability stream and update cadence am I inheriting?
Which architectures have native builds? Specifically, is the macOS Apple Silicon build native or an Intel build under translation?
What happens to the agent when the platform is unreachable for a day? Does it queue, does it retry, and does it recover without manual intervention?
Scope of control
Enumerate exactly what an operator can cause to happen on an endpoint. If arbitrary code execution is included, what stands between a compromised console session and code running on a production server?
Is every remote session attributable to a named individual? Is that attribution recorded somewhere the operator cannot alter?
Can I scope an operator to specific clients, and does that scoping apply to reporting and exports as well as to the console?
Data and retention
How long is health history, patch history and audit log data retained? Does retention differ by data type?
What happens to an endpoint's history when the machine is removed from management?
Can I export my data in a usable form if I leave, and what exactly is included?
Is an asset a distinct record from an endpoint, so that rebuilding a machine does not restart its history?
Are discovered devices held separately from managed ones, or can the two end up in the same count?
The gaps
What is on your roadmap that a prospect might reasonably assume already exists? — This is the highest-yield question on the list. A vendor who answers it specifically is one you can plan against. A vendor who deflects has told you something too.
Which capabilities are beta, and what specifically is unfinished about each?
Does the API expose the same surface the console uses, or a reduced subset? Can I drive operations through it or only read data?
Identity and access
Does operator authentication integrate with my identity provider? If not, what is my leaver process, and what will an access review look like?
Is multi-factor authentication available, and can it be required rather than merely offered?
What can the vendor see or do inside my tenant, and is that access logged where I can read it?
Commercial
What is the unit of pricing, and what happens when the estate shrinks rather than grows?
What is in the base price and what is separately licensed? Ask specifically about reporting, API access and any AI features.
What is the contract term, the notice period, and the price-change mechanism at renewal?
How to run the evaluation
Insist on a trial in your own environment, and deliberately choose your most awkward site rather than your cleanest. Run it for at least a month. Give it to the technicians who will actually use it daily, not only to the person making the decision — the people who will live inside a console notice things in week three that no demonstration reveals.
And ask the same vendor the gaps question twice, several weeks apart, to different people. Consistency there tells you more about how a company operates than any answer to a feature question.