Foremanhost and interface authority
Puppetfacts and environment context
Roomsphysical grouping and seats
Relaysactual support vantage point
Evidencereason, action, result, blocker
Remote support path

Launchability is tested from the path that will actually carry the session.

A workstation can be reachable from the application and still unreachable from the relay. FreeSCIM keeps those boundaries explicit.

01 / AUTHORITY

Select the workstation

Room, seat, inventory, ownership, current health, and allowed actions are resolved first.

02 / RELAY

Choose the correct jump

The support path is evaluated from the relay and guacd vantage point, not from an unrelated host.

03 / ENDPOINT

Probe SSH or VNC

Current reachability and service readiness determine whether a session can launch safely.

04 / EVIDENCE

Record the outcome

Selected relay, launch token, blocker, operator context, action, and result remain correlated.

Why the fleet stays trustworthy

Automation enriches workstation truth without silently replacing it.

Inventory imports are designed to preserve provenance: reviewed source data can enrich the estate while conflicts and stale observations remain visible.

Dry-run import

Foreman and Puppet enrichment can be previewed before applying changes to workstation records.

Field provenance

Host identity, interfaces, MAC addresses, room context, and facts retain their source.

Per-seat before bulk

Precise workstation actions can remain available without enabling broad room-wide control.

On-demand VNC

VNC activation and jump-spoke creation occur only when needed instead of exposing a permanent fleet-wide listener.

Identity reaches the physical workstation

From a user and a room to a bounded support action.

FreeSCIM shows which workstation is involved, what the infrastructure authorities know, whether the relay can reach it, which remote path is valid, and what evidence proves the result.