Guides.

The everyday jobs, screen by screen on iPhone. Then the longer ones you do sitting down. Written from what the product does today, not from what it will do.

Step by step, on iPhone

Start at the top if the app is new to you; they run in order and each one hands off to the next. Every step names the control it wants, spelled the way the screen spells it.

  1. Find your way aroundFour tabs, and each one answers a different question. Two minutes here saves you hunting for the rest.2 minutes5 steps
  2. Add an assetThree ways in, one form, and a tag the register reserves for you before you type anything.A minute per machine5 steps
  3. Find an asset in the registerOne search field, three registers behind it, and a filter that answers the only question you usually have.Seconds5 steps
  4. Read a recordThe sheet is laid out in the order you actually check a machine: who it is, what you do, how long it has left, then the paperwork.A minute5 steps
  5. Edit an assetNothing is written until you say so. The part worth knowing is what editing costs you, and when not to do it.A minute7 steps
  6. Verify an assetThe shortest task in the app, and the one an audit is actually about. Done properly it is one tap per machine and you never leave the camera.Seconds per machine5 steps
  7. Sweep a rackOne camera that stays open while you pan across a shelf. It records what was seen, and it is careful not to call that verified.Minutes for a room6 steps
  8. Tag a machine with NFCWrite a chip from the record in one tap, and a tap of the phone opens that record again. It beats reading a worn asset number off the back of a rack.Seconds per machine6 steps

The phone screens in these guides are captures of the shipping build, taken from a standalone register of 500 assets on an iPhone with no Mac and no account. They used to be renderings and said so; that debt is paid. Every control named in a step is legible in one of them, or belongs to a guide that says it has no picture.

Where these guides stop

Adding and editing run end to end now. Both used to stop at a button, because the form and the editing state were screens nobody here had. They were captured off the shipping build and those two guides were rewritten around them.

What has no picture is the camera: Scan and Sweep both need a lens, and a simulator has none. Those two guides quote the shipping source rather than describing a screen from imagination, and they say so where they stop. Tagging is the third, because NFC needs a radio the simulator also lacks. A guide that invents a screen does not just look bad, it makes you fail at the task and then distrust the register.

The longer jobs

Read at a desk rather than followed with a phone in your hand. These are decisions and rounds, not taps.

Your first hour

About 40 minutes

Name the organisation and answer the regulated-data questions, which is what derives your frameworks rather than you picking them off a list. Then bring assets in before anything else: an empty register teaches you nothing about whether the product fits. Import a spreadsheet or connect one source, and leave the rest for later.

  1. Answer the setup questions honestly, including the ones about regulated data. They decide which of the 12 standards apply to you.
  2. Choose where the register lives. This governs every sync afterwards and is not easy to change later.
  3. Import a spreadsheet, or connect Intune, Entra, Jamf Pro or Okta.
  4. Print QR labels for anything you will be verifying by hand.

Bringing in a spreadsheet you already have

About 15 minutes

You do not have to reshape your file first. Columns are matched by looking at the values, not just the headers, so a column called “Who” full of names is recognised as an assignee. Columns that are yours alone become typed custom fields rather than being dropped. Repeated vendors and contracts in the sheet become one record each, with the assets linked to them.

  1. Point it at the file. Nothing is written until you confirm the mapping.
  2. Check the columns it could not place; those become custom fields if you want them.
  3. Confirm. The import is logged before it writes, and can be undone in the same session.

Running a verification round

Depends on the estate

Verification is the thing auditors actually test: not that a spreadsheet exists, but that somebody laid eyes on the machine. This is what the phone is for, and the step-by-step version of the phone half is above.

  1. On the Mac, filter to what has not been verified inside your policy window.
  2. Walk the floor with the phone. Read the tag, cross-check the serial by barcode or OCR, confirm you have seen it.
  3. Reassign custody on the spot if the machine has moved. The change records whether or not the Mac is awake.
  4. Back at the desk, the round shows in the trail with who acted and when.

Producing an audit evidence pack

Minutes

The pack is assembled from what the register already holds, so the work happens before the auditor arrives rather than during. Your inventory is mapped to 66 controls across 12 standards, and 15 evidence reports are kept ready.

  1. Open Compliance and check the coverage for the framework being tested.
  2. Generate the Audit Evidence Pack: full inventory, audit trail, sanitization certificates and worklists.
  3. Every artifact in the pack is mapped to the control it answers, so you are handing over an index rather than a folder.

Retiring a machine so it stands up later

A few minutes per machine

Disposal is where most registers quietly fail an audit, because the evidence chain is the thing being tested and it is usually the thing nobody kept. Manifest records it as a chain rather than a status change.

  1. Record the sanitization category against NIST SP 800-88: clear, purge or destroy.
  2. Name the witness and the authoriser, and attach the wipe certificate.
  3. The record stays in the register. A machine that was disposed of still happened, and its record is the artifact an auditor asks for.

Not covered here, on purpose

  • Reconciling software licences against installs. Licences themselves have a screen: seats purchased against seats assigned, renewals, cost. What has no guide is discovery, because there is no discovery — nothing scans a machine for what is installed on it.
  • Anything needing the cloud track while you are on the local one. The workspace decision governs what syncs, and a guide that ignored it would be describing a different install.

Something missing? Write to support@depaloconsultingllc.com and say which step you got stuck on; that is how this page grows.

For the reference behind these, area by area, see the documentation. Also useful: how it works and what it costs.