Security playbook · AI Employee: Sig

Endpoint Compliance Drift

Compliance drift < 3% workspace-wide

The problem

Endpoint compliance decays. New employee's laptop meets baseline; three months later they've disabled the screensaver-lock "just for this presentation" and never re-enabled it, installed unapproved software, granted admin rights to some contractor, opted out of updates. MDM shows green-across-the-board because it's checking against a policy the user quietly worked around. Every quarter someone runs a manual audit, finds 40 machines drifted, and the loop starts again.

At a glance
Trigger
Cron (daily)
Approvals
None for auto-remediate; owner ticket otherwise
What it does
Writes to your systems
Systems
Jamf · Intune · CrowdStrike
How it feels in production

An hour-by-hour walkthrough.

Every 4 hours, Sig runs a compliance drift scan across the fleet. For every device it compares: - Screensaver-lock timeout (should be 10 minutes; user set to 4 hours) - FileVault / BitLocker enabled - OS version within N months of latest supported - Firewall enabled with default-deny - Approved-only software installed (against sanctioned software list) - No local admin accounts beyond the sanctioned one - EDR agent running + reporting - Backup encryption + last-backup date - USB port policy applied - Password / passcode policy met Priya's MacBook has drifted: screensaver-lock is 4 hours (was 10 min), and she has installed a screen-recording app that isn't on the approved list. Sig DMs Priya: "Your laptop has drifted from compliance on 2 items: screensaver-lock is set to 4 hours (policy: 10 min), and 'CleanShot X' isn't on the approved software list. Options: (1) reset lock to 10 min (I can do this — approve), (2) request approval to keep CleanShot X (link to approval form). Please respond within 48 hours." For high-severity drift (encryption disabled, EDR agent uninstalled, extra local admins), Sig doesn't wait for user response — it re-enables the setting immediately per policy and files an incident for security review. Weekly security digest: drift by category, top-offending users (repeat patterns), sanctioned-software gaps (many people installing the same unapproved tool = maybe add it), compliance score trend.
How it works

Step by step.

  1. 01

    Scan the fleet on 4-hour cadence

    Full compliance check across every managed device: policy vs. actual state per compliance dimension. Read from MDM + EDR + agent-reported inventory.

    Jamf · Intune · Kandji · CrowdStrike · SentinelOne · Fleet
  2. 02

    Detect + classify drift by severity

    Low: user-fixable, non-critical (screensaver timeout). Medium: security-relevant, user-influenced (unapproved software). High: security-critical, auto-remediate (encryption off, EDR uninstalled, admin escalation).

    Compliance policy · Severity matrix
  3. 03

    Route to user for low/medium; auto-remediate high

    Low/medium: user DM with specific drift + one-click remediation or exemption-request. High: auto-remediate immediately + file incident for security review.

    Slack · Teams · MDM policy push · Incident tracker
  4. 04

    Nudge + escalate on non-response

    User has 48 hours to respond or Sig auto-remediates + notifies user. Repeat drift patterns (same user, same setting, 3+ times) escalate to manager as coaching moment.

    Slack · Manager escalation · Coaching queue
  5. 05

    Weekly security digest + policy tuning

    Drift-by-category trend, top-offending users, common exemption requests (informs policy updates), compliance-score fleet health. Sanctioned-software list updated from common exemption asks.

    Analytics · Slack digest · Policy tuning
Systems and wiring

What you connect to make this run.

Jamf · Intune · Kandji · Workspace ONE

read+write

MDM as source of policy + fleet state. Write policy re-enforcement, remediation profiles. Read: compliance status per device per policy dimension.

CrowdStrike · SentinelOne · EDR

read+write

EDR agent health + tamper detection. Missing EDR heartbeat is a high-severity drift; user cannot uninstall or disable.

Sanctioned-software list · App catalog

read+write

Approved software list. Common exemption requests feed additions or investigations; a widely-used unapproved tool may be a policy gap rather than a violation.

Slack · Teams · Manager registry

read+write

User DM for low/medium drift. Manager escalation for repeat patterns. Never surprises users — always the specific drift + specific fix.

What changes

Before and after, honestly.

Endpoint compliance rate at any time
Before
50-75% (drift accumulates)
After
95%+ (4-hour detection + user-initiated fix)
Time from drift to remediation
Before
30-90 days (quarterly audit)
After
Under 48 hours (auto or user)
High-severity drift events left un-remediated
Before
8-25 per quarter
After
Zero (auto-remediate)
Security team hours per week on endpoint compliance
Before
8-20 hours (chasing quarterly audit findings)
After
1-3 hours (policy tuning + exemption reviews)
Frequently asked

Answers about this playbook.

What if a user needs to install unapproved software for a specific task?

Exemption request flow. User justifies the need; Sig routes to security for one-time approval or catalog addition. Approved: exemption logged with expiry (usually 30 days for one-off, permanent for catalog add).

How does it handle BYOD or contractor devices?

BYOD compliance limited to what MDM policy covers. Corporate data isolation checks (email, VPN, doc apps) rather than full-device compliance. Different severity thresholds per device class.

What about developers who need local admin for their work?

Local admin allowed per role (engineering, IT ops), tracked with justification. Only extra-local-admin accounts flag; sanctioned admin roles pass compliance.

How does it handle offline devices (long air travel, remote area)?

Devices without check-in for 7+ days flag as "unknown compliance state" — not compliant, not violating. On next check-in, scan runs and any drift addressed.

Can we exempt specific device populations (lab, kiosks)?

Yes — device-class tags with class-specific compliance policies. Lab devices may skip screensaver-lock (shared use); kiosks have their own strict policy. Enterprise class always follows full policy.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.