Work profile
A work profile is created on the employee's phone, and the system touches nothing else. The personal half of the device is out of its reach. The phone states plainly that the profile is managed by the organisation, and that cannot be hidden.
Applications
You upload an application file to the panel and push it to the devices you choose. No app store and no Google services are involved. Applications can be configured in advance, and installing anything else into the work profile can be blocked.
Policies
Moving work data into the personal half is closed off. The clipboard shared between the work and personal halves is turned on or off from the management panel. Policies are enforced continuously and cannot be removed on the phone itself.
Visibility
Model, system version, patch level and bootloader state for every device. You see the fact that USB debugging is on, a SIM change, failed unlocks and the network calls applications make.
Vulnerabilities
The server matches the patch level of every device against the Android vulnerability catalogue. The catalogue refreshes itself automatically.
Alerts
You define the rules: failed unlock attempts, a device that stopped reporting, vulnerabilities above a severity you pick, an entry in the security log. An alert clears itself once its cause is gone.
Lost phone
From the panel the work profile is locked, and wiped if the device is not coming back. If the phone is offline, it gets the command the moment it comes back online.
Finding a device
Coordinates are collected only after the phone's owner grants explicit permission. That permission can be withdrawn.
Updates
The server is updated by installing a newer Debian package over the old one. It picks up the latest version of the mobile application itself and distributes it to the devices.