Integration

How do I roll out GenZAgents to 200 engineers?

For 200 engineers: push @genzagentsio/setup via your MDM (JAMF / Intune / Workspace ONE). Use the org install token (install-only-scoped) so even if leaked it can't do damage. Total deployment time: ~1 day including testing.

Step 1 — generate the org install token

/admin/install-tokens → Generate. The token is install_only-scoped — it can ONLY call /v1/install/* endpoints. Even if leaked from a laptop /etc/genzagents.env, it can't read receipts, can't register agents, can't do anything except configure tools on the user's laptop. Minimal blast radius.

Step 2 — pick your MDM template

/integrations/mdm shows ready-to-deploy templates. JAMF policy XML. Intune PowerShell script. Workspace ONE configuration profile. Each template installs @genzagentsio/setup via npm + writes /etc/genzagents.env with the install token + runs the setup CLI.

Step 3 — pilot with 5 engineers

Deploy to a smart group of 5 trusted engineers first. Verify: GenZAgents shows up in Claude Desktop / Cursor / Cline (or whichever AI tools they use). Verify: receipts flowing on /dashboard. Verify: no breakage of existing MCP servers or other workflows. Standard pilot validation.

Step 4 — full rollout

Once pilot validates: extend to the full smart group. Monitor /admin/install-fleet for completion — should show 200 laptops registered within 24-48 hours (limited by MDM sync cadence, not our side). Standard MDM rollout pace.

Step 5 — ongoing operations

Token rotation: update MDM secret quarterly, re-push. Install fleet audit: /admin/install-fleet weekly for laptops not reporting (decommissioned / out of sync / error states). Tier upgrades: handled per-org-token (the token tier determines the org's available features).

Engineer experience

Engineers see GenZAgents configured the morning after the MDM push. They don't need to enter anything; the agent DID + API key were configured by the install token flow. They open their normal AI tool; receipts start flowing. Zero friction by design.

Related

Get the trust layer for your AI work

GenZAgents is the verified work-history layer above every AI provider your team uses. Sign cryptographic receipts, hand off conversations across Claude / ChatGPT / Cursor / Gemini, keep institutional AI knowledge when employees leave.

Last reviewed · 2 min read· Open spec· Changelog