Work and teams

Control phone and PC transfers in your company

Admin-signed policies that every device enforces locally: switch features off, block file types, guard the clipboard, allow LAN only. No accounts.

Available in preview Updated Works on
  • Windows
  • Android
  • Linux

An administrator creates a private admin key with pdb team init, writes the rules in a JSON file and signs it; each PC is enrolled with the organisation name and admin key, and then applies the signed policy. Every device checks the signature and enforces the rules itself, so there are no user accounts and no cloud console to run.

At a glance

  • Policies are signed with the administrator’s private key and checked on each device.
  • Switch features off, block file types or set a maximum file size.
  • Keep resident registration and card numbers out of the clipboard.
  • Allow the local network only, with no internet connections.
  • A tamper-evident audit log can be required.

Step by step

  1. Create an admin key

    On the administrator’s PC run pdb team init. Keep the key file private.

  2. Write and sign the policy

    Describe the rules in a JSON file and sign it with pdb team sign policy.json --org "Your company", which creates team-policy.json.

  3. Enroll each PC

    On each PC open Settings › Security & organisation › Organisation › Team enrollment, enter the organisation name and the Admin key, and click Enroll.

  4. Apply the policy

    Click Apply policy file… and choose team-policy.json, or run pdb team apply team-policy.json. pdb policy shows what is in force.

  5. Check the audit log

    Open Audit log and use Verify integrity, or run pdb audit --verify, to confirm the record hasn’t been changed.

Clipboard rules

In clipboard_block use kr_rrn (resident registration numbers), card (only valid card numbers are blocked), kr_phone or email, or re: followed by a regular expression for anything else. Look-alike dashes, other digit forms, dots or tabs as separators and invisible characters are handled, and the same rules cover text and links sent to My Drop. Unknown rule names are refused when you sign.

What it isn’t

There are no user accounts, no SSO and no cloud console, by design. The audit log records what each device did in a chain of hashes, so later changes are detectable.

Questions

Do we need a server or a management console?

No. The policy is a signed file. Devices verify the signature and enforce the rules locally.

Can we stop internet connections and allow only the office network?

Yes. A policy can allow the local network only, so devices don’t connect over the internet.

Does it support SSO or user accounts?

No. The product has no accounts, so there is no SSO; trust comes from the signed policy and device pairing.

How can I see what a device is enforcing?

Run pdb policy on that device to show the policy in force.