OpalSpan documentation
OpalSpan lets technicians direct and authorize device work. OpalSpan Mech is the built-in AI technician: use it in your browser, with no local Agent CLI installation. Alternatively, the AI assistant you already use can operate OpalSpan Agent CLI on your workstation. Both routes use the same workspace and device permissions; they do not share Mech conversations or private files.
These guides describe the released Windows and Linux products, not future features.
Start here
- Getting started: sign in, select a workspace and connect.
- Use Mech in your browser, or set up the optional Agent CLI on Windows or Linux for your own AI assistant.
- Access and enrollment: persistent devices, shared enrollment links, commands, transfers and history.
- Portable Rescue: attended temporary access and optional promotion to persistent access.
- Diagnostics: request only the evidence you need.
- Customers: companies, contacts and device relationships.
- Cases and drafts: record work, correct notes and review customer-facing text.
- Mech: built-in AI technician in the browser.
For external-agent automation, use the CLI reference and the curated HTTP API reference. For failures, start with troubleshooting.
What runs where
| Product | Purpose |
|---|---|
| OpalSpan Mech | Built-in AI technician in the browser. Requires no local Agent CLI installation. |
OpalSpan Agent CLI (forge) |
Optional tool for an external AI assistant on a technician's Windows or Linux workstation. The compatible executable remains forge during the name transition. |
| Bridge | The website and API that own workspaces, authorization, device presence, customer context and history. |
| OpalSpan Daemon | Persistent elevated service on an enrolled Windows or Linux device; reconnects after reboot. Its installed service identity remains Forge during the transition. |
| Portable Rescue | Attended, temporary elevated access, without installing the persistent service unless explicitly promoted. |
| Diagnostics | A verified, one-shot collector run only after an explicit request. |
Connections use the native outbound HTTPS relay and public-key SSH/SFTP. The customer device needs no inbound LAN listener, support account, VPN client or Windows OpenSSH server. The agent workstation needs OpenSSH client tools.
Workspaces and responsibility
In the current public service, human Admins and Technicians have ordinary workspace-wide device, history, customer and case access. Workspace settings, accounts, roles and invitations remain Admin-only. Switching workspaces never grants membership, and customer links or case assignments never grant access.
One technician identity controls a device at a time; that identity may open several channels and work on several devices. Access is elevated. Agree the customer's scope before running commands or changing a machine.
Mech is generally admitted under normal workspace authorization, entitlement and credits. Ordinary Work/Cases and access through your own local agents remain available. OpalSpan does not send customer email, provide a full CRM/PSA or guarantee recovery of every machine. See release applicability for the current boundary.