AI operations

Seventy Windows machines, managed by a sentence

Instead of a console, an instruction in plain words. The agent proposes a plan, waits for approval, and only then acts — with signed updates and rollback.

Client
retail chain with dozens of stores
Status
Production · 2026
Outcome
  • A fleet of roughly seventy Windows 10 and 11 machines is managed without driving to the stores.
  • Every agent update is signed and rolls back to the previous version on failure.
  • Every bulk operation has an approval step and a verified per-machine result.
Stack
GoPowerShellWindows ServiceHTTPS and internal CAcosignGitHub ReleasesPython

The problem

Dozens of stores, several machines in each, and the only way to change anything on them was a car journey or a remote desktop session one machine at a time. A routine task such as reconfiguring a scheduled task on every till meant a full day of clicking, and at the end nobody could say with certainty whether it had worked everywhere.

Conventional fleet management tools solve this, but they bring their own infrastructure, licensing, and an administrator to operate them. For a company of this size that is disproportionate.

What was built

Each machine runs a small agent written in Go, installed as a Windows service. It communicates over HTTPS against an internal certificate authority, updates itself, and every update package is signed. If a new version fails to start, the agent falls back to the previous one.

Above that there is no console. There is a language model with a precisely bounded set of tools and a disciplined procedure. The operator writes what they need, the model assembles a plan, shows it, and waits.

Installing a package across a group of stores
operatorAll the tills in stores 12 to 18 need the new print driver installed.
agentFound 24 machines in group stores-12-18, of which 22 are online and 2 unreachable (POS-1404, POS-1712).
agentPlan: download package, verify signature, stop print spooler, install, start spooler, verify driver version.
approvalRun on 22 machines? The two unreachable machines will be queued.
operatoryes
result22/22 succeeded. Driver version verified on all. 2 machines waiting to reconnect.

The approval step is the entire point of this design. The model may propose anything, but nothing executes until a human confirms it — and what is confirmed is a specific list of machines, not an abstract command.

What this is not

This is not a replacement for a large endpoint management product. It has no central console with a real-time view and it is not built for thousands of workstations. It is built for tens to low hundreds of machines in an environment where deploying a large solution makes no economic sense. Within that range it is faster and cheaper; beyond it, it stops being the right choice.

Result

The solution is deployed across the whole fleet. Configuration changes, scheduled task repairs, shortcut distribution and diagnostics are done from one place, with a verifiable per-machine result.