What Wyrd can do
Rules and visibility
Answers the question What can you set for the fleet, and what can you only see?
The system owns the work profile, not the device: inside the profile it sets the rules, outside it only observes.
What can be set
- Applications in the work profile. You hand out the ones you need, and installation by the employee can be allowed or forbidden.
- The shared clipboard between the work and personal halves. It can be switched on or off; with it off, work text cannot be copied into a personal messenger.
Rules are kept in force and cannot be lifted on the handset itself.
What is visible but not controlled
- Whether USB debugging is enabled.
- A change of SIM card.
- The make-up of the device: model, system version, patch level, time last seen.
These cannot be forbidden from the dashboard. The personal half of the phone is not the system's. They show a deviation in how a handset behaves, so the conversation with the employee happens before an incident does.
Restraint
Excessive restrictions produce the opposite result: employees carry a second phone and the protection loses its purpose. Restrict what your threat model calls for.