> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# IT asset discovery

> What agents, network collectors and connectors found on your network, how each device is matched to the asset register, and the review and exception lists that keep the register honest.

The **Discovery** screen shows the computers, servers, network equipment and cloud resources that
discovery has actually found, how each is matched to an asset in the register, and what is left for
somebody to decide. Open it from **Assets → Discovery**.

<Note>If you don't see this in your navigation, your administrator can switch the module on under **Administration → Modules**, or it may not be included in your plan. The module is called **IT asset discovery** there.</Note>

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=41c305d47d9c7cf894b2acfe009488b5" alt="The Discovery review list with one device opened to show why it was proposed" width="2880" height="1800" data-path="images/assets/discovery-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/IHFOffeCL8-27cYL/images/assets/discovery-dark.png?fit=max&auto=format&n=IHFOffeCL8-27cYL&q=85&s=dc253abb9eef4f930309bcf09778d078" alt="The Discovery review list with one device opened to show why it was proposed" width="2880" height="1800" data-path="images/assets/discovery-dark.png" />

The assets stay in the register; discovery is the evidence about them. Three kinds of **source**
report what they see:

| Source | What it is |
| - | - |
| **agent** | A small program on a Windows, macOS or Linux machine that reports the machine itself and its installed software |
| **collector** | A network collector at a site that sweeps the address ranges it is authorised to scan, with or without credentials (SSH, WinRM, WMI or SNMP) |
| **connector** | A link to a system that already knows about devices — a device-management (MDM) or cloud account |

Each report is a **scan**. A minute after a scan arrives, the reconciler matches every device in it
against the register, scoring the evidence — serial number, MAC address, host name, hardware UUID and
so on. A device it is sure about is linked to its asset with nobody involved. A device it is not sure
about goes to **Review**.

Sources, enrolment keys, scan authorisations, credentials, the match rules and thresholds are set up
under **Settings → IT discovery** — see [IT discovery settings](/config/discovery). The **Set up** button takes you there.

## The header

| Figure | What it means |
| - | - |
| **devices** | Every device discovery knows about |
| **in the register** | Devices linked to an asset |
| **to review** | Devices waiting for a person to decide |
| **sweep success** | How successful recent network sweeps have been at identifying the devices that answered them |
| **sources overdue** | Sources not heard from in twice the interval each is expected to report in. What they would have reported is missing from every figure on the screen |

**Match now** matches waiting scans against the register immediately, exactly as the schedule would a
minute later. It needs permission to change match rules, thresholds and automatic creation.

Banners appear when sources have **enrolled and are waiting for approval** (their scans are refused
until somebody approves them on the **Sources** tab) or when sources are **overdue**.

## Review

**Devices to decide about** lists devices the reconciler was not sure enough about.

| Column | What it shows |
| - | - |
| **Device** | The host name, the kind of device and its IP address |
| **Serial** | The serial number, if reported |
| **Proposal** | The asset it most likely is, or **new device** if nothing scored |
| **Score** | How strongly the evidence points to the proposal |
| **Last seen** | When a source last reported it |

**It is this one** accepts the proposal and links the device to the proposed asset.

Open a row to see **Why this proposal**: each piece of evidence that **agrees** (with the weight it
added) or **disagrees** — some disagreements rule a match out altogether. **Other assets that scored**
lists the runners-up. If the device would have been registered automatically and was refused, the
reason is given. Three buttons follow:

| Button | What it does |
| - | - |
| **Another asset…** | Opens **Which asset is …?** Choose the **Asset** (search by number, name or serial) and say **Why this asset?** — you are overruling the proposal, or nothing proposed it, so somebody will ask. **Link it** links it |
| **Register it** | Creates a new asset linked to the device (see below) |
| **Not ours** | Dismisses the device (see below) |

Deciding needs permission to accept, link or dismiss a discovered device.

### Registering a device as a new asset

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-register-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=c1a3cf3f430114cc7d27b9c407b46f9b" alt="The Register dialog for a discovered laptop" width="2880" height="1800" data-path="images/assets/discovery-register-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-register-dark.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=7afabb3f5e0d22896fac5bdcd8e6df2c" alt="The Register dialog for a discovered laptop" width="2880" height="1800" data-path="images/assets/discovery-register-dark.png" />

| Field | What it means | Notes |
| - | - | - |
| **Name** | The new asset's name | Required |
| **Category** | The asset category | Required. Suggested from the kind of device. Categories are [configurable](/config/assets) |
| **Site** | Where it is | Required. Suggested from the source |

The serial and anything else discovery knows are filled in on the asset. The person last signed in to
the machine is suggested as its custodian; change it on the asset if they are not the one answerable
for it.

### Dismissing a device

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/IHFOffeCL8-27cYL/images/assets/discovery-dismiss-light.png?fit=max&auto=format&n=IHFOffeCL8-27cYL&q=85&s=1a017406201acf98f95f95ea1284c3d1" alt="The not-one-of-ours dialog with its four reasons" width="2880" height="1800" data-path="images/assets/discovery-dismiss-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/IHFOffeCL8-27cYL/images/assets/discovery-dismiss-dark.png?fit=max&auto=format&n=IHFOffeCL8-27cYL&q=85&s=36459c74e1bdd3693f51d940953a34bf" alt="The not-one-of-ours dialog with its four reasons" width="2880" height="1800" data-path="images/assets/discovery-dismiss-dark.png" />

| Field | What it means | Notes |
| - | - | - |
| **Because** | Why it is not an asset | Required. **It belongs to somebody else**, **It is somebody's own device**, **It is not something we register**, or **It should not be on this network** |
| **Note** | Anything more | Optional |

A dismissed device stays dismissed however often it is seen again. One dismissed as **It should not
be on this network** raises an **Unauthorised** exception each time it is seen again.

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-link-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=04241e5082ee67dd59f0d3b7b5d351c3" alt="The Which asset is it dialog for linking a device to another asset" width="2880" height="1800" data-path="images/assets/discovery-link-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-link-dark.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=b9f065539e560a2239ec445678483283" alt="The Which asset is it dialog for linking a device to another asset" width="2880" height="1800" data-path="images/assets/discovery-link-dark.png" />

## Exceptions

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-exceptions-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=fb983ad3485255d8992d9587f5f5e6be" alt="The Exceptions tab listing orphaned, unauthorised, unknown and unmanaged devices" width="2880" height="1800" data-path="images/assets/discovery-exceptions-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-exceptions-dark.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=508f828eebf7600c72a3c747ced027fc" alt="The Exceptions tab listing orphaned, unauthorised, unknown and unmanaged devices" width="2880" height="1800" data-path="images/assets/discovery-exceptions-dark.png" />

An hourly sweep raises what somebody has to answer for and routes each to the person answerable for
the asset — or to the IT asset team when nobody is.

| Kind | What it means |
| - | - |
| **Unknown** | Discovered, and nobody has decided whether it is one of ours |
| **Duplicate** | One machine is being counted twice, or two as one — the serial numbers disagree |
| **Stale** | Not seen by any source for longer than the organisation allows |
| **Unmanaged** | On the network, and no agent or MDM has ever reported it |
| **Unauthorised** | Dismissed as not permitted, and seen again since |
| **Orphaned** | Nobody is answerable for it: no custodian and no department |
| Blocked software | A device has a product installed that is blocked in the [software catalogue](/assets/software) |

| Column | What it shows |
| - | - |
| **Kind** | The kind, with its explanation |
| **About** | The asset or device it concerns |
| **Answers for it** | Who it is routed to |
| **Raised** | When |

**I'm on it** marks it as in hand (needs permission to acknowledge and reassign discovery exceptions).
**Resolve** asks **What was done about it?** and closes it (needs permission to resolve discovery
exceptions). If the condition still holds at the next hourly sweep, a new exception is raised — so
resolve it once the cause is dealt with, not to clear the list.

## Devices

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/IHFOffeCL8-27cYL/images/assets/discovery-devices-light.png?fit=max&auto=format&n=IHFOffeCL8-27cYL&q=85&s=ac1b5aa565f0fb81d167bc491d34987d" alt="The Devices tab listing every discovered device with its status and asset" width="3200" height="1800" data-path="images/assets/discovery-devices-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/IHFOffeCL8-27cYL/images/assets/discovery-devices-dark.png?fit=max&auto=format&n=IHFOffeCL8-27cYL&q=85&s=568ef3302170c3d5a84fd16bec8f3bcc" alt="The Devices tab listing every discovered device with its status and asset" width="3200" height="1800" data-path="images/assets/discovery-devices-dark.png" />

The register of evidence: every device discovery knows about. Choose **All**, **In the register**,
**Unreviewed** or **Dismissed** to narrow it.

| Column | What it shows |
| - | - |
| **Host name** | The device's host name, with its make and model underneath |
| **IP address** | Its last known address |
| **MAC address** | Its network card's address |
| **Operating system** | As reported. *(guessed)* means it was inferred from how the device answered without a credential; a credential replaces the guess with what the device reports |
| **Status** | **linked**, **unreviewed** or **dismissed** |
| **Asset** | The linked asset |
| **Managed** | Whether an agent or MDM reports it |
| **Last seen** | When, and by which source |

Row buttons depend on the status: **Unlink** (asks **Why was the link wrong?**; the link stays in the
device's history and the device goes back to review), **Review again** for a dismissed device, and
**Not ours** for an unreviewed one. Opening a row shows what recognised it and the **Software installed
now** — reported only by an agent or MDM, never by a network sweep.

## Sources

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-sources-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=30d66ea129f5f73ff983773a0bd14d67" alt="The Sources tab with two agents and a network collector" width="2880" height="1800" data-path="images/assets/discovery-sources-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-sources-dark.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=8d4e55d57445f0dd7c2b0be03d583eb8" alt="The Sources tab with two agents and a network collector" width="2880" height="1800" data-path="images/assets/discovery-sources-dark.png" />

| Column | What it shows |
| - | - |
| **Source** | Its name and identifier |
| **What it is** | **agent**, **collector** or **connector**, and its platform |
| **Status** | Active, waiting for approval, suspended or retired |
| **Last reported** | When it last sent a scan, or **never** |
| **Version** | The agent's version |

| Button | What it does |
| - | - |
| **Approve** | Lets an enrolled source's scans in |
| **Suspend** | Asks **Why?** Its scans are refused until restored; its key keeps working, so restoring needs no visit to the machine |
| **Restore** | Undoes a suspension |
| **Retire** | Asks **Why?** Final: every key the source holds is revoked, and the machine cannot enrol again under the same identity. What it reported stays |

These need permission to approve, suspend and retire discovery sources.

## Scans

<img className="block dark:hidden" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-scans-light.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=77938c52479407bafe9d02a460a0f881" alt="The Scans log" width="2880" height="1800" data-path="images/assets/discovery-scans-light.png" />

<img className="hidden dark:block" src="https://mintcdn.com/assetinfinity/qDhRWv9pocguWn7E/images/assets/discovery-scans-dark.png?fit=max&auto=format&n=qDhRWv9pocguWn7E&q=85&s=e4cd2ad3d20ef5fd6e29b7a08821f41f" alt="The Scans log" width="2880" height="1800" data-path="images/assets/discovery-scans-dark.png" />

The log, for when somebody asks why a sweep found less than it should have.

| Column | What it shows |
| - | - |
| **Received** | When the scan arrived |
| **Source** | Which source sent it |
| **Kind** | **sweep**, **partial** or **full** |
| **Found** | Devices found — for a sweep, out of how many addresses answered and how many were tried |
| **Not kept** | What was discarded: devices outside what was authorised, attributes dropped, and how many devices refused the credentials |
| **Status** | Whether the scan has been matched against the register |

## Who can do what

| To | You need permission to |
| - | - |
| See devices and scans | View scans, discovered devices and the software found on them |
| See the review | View discovered devices waiting for review |
| Decide about a device | Accept, link or dismiss a discovered device |
| Work exceptions | Acknowledge and reassign, or resolve, discovery exceptions |
| Approve, suspend or retire sources | Approve, suspend and retire discovery sources |
| Match now | Change match rules, thresholds and automatic creation |
| Set discovery up | Create enrolments, collectors and connectors, and issue their keys |

See also [software](/assets/software) for what is installed on these devices and
[network topology](/assets/topology) for how they are connected.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.