Governed ChromeOS fleet management

Tame your ChromeOS fleet.

Chrome Coyote gives school technology teams, MSPs, and multi-entity organizations a fast, safe, and auditable way to search, segment, and act on every Chromebook they manage—without living inside the Google Admin console.

Chrome Coyote red coyote-head logo on a dark navy background
The problem

ChromeOS administration gets blunt at scale.

Native administration can mean pagination limits, weak filtering, no reusable segments, risky one-off bulk actions, and thin audit trails. That makes routine fleet work slower and destructive changes harder to govern.

The outcome

Turn every Chromebook into a governed fleet.

Search and filter across the whole fleet, reuse device collections, run bulk actions with safety rails, and keep a complete per-device history—while giving each person access only to the organizations and OUs they should manage.

Core capabilities

What Chrome Coyote helps your team do.

Start with the operating outcome, then use the specific capabilities your environment needs.

01

Fleet-wide search and views

Search more than 30 device attributes, combine filters, configure columns, sort across the full fleet, and save reusable views.

02

Reusable collections

Build dynamic collections that refresh with your filters or static collections for projects, replacement waves, and incidents.

03

Safe bulk actions

Update annotations, move OUs, change status, clear profiles, reboot, powerwash, and more with risk-based confirmation and approval gates.

04

Action sequences

Turn multi-step work into named playbooks, preview the impact, and run each step in order without keeping a browser tab open.

05

Durable job engine

Queue idempotent background jobs, see the result for every device, and retry only the failures without repeating successful work.

06

Reports and fleet analytics

Track Chrome versions, AUE exposure, battery health, device status, and annotation mismatches, then scope or export the results.

How it works

A clear path from connection to action.

01Connect each organization.Grant approved administrators access to the domains and organizational units they are responsible for.
02Find or segment the fleet.Search, filter, import a CSV, select an OU, or open a saved view or collection.
03Preview, approve, and run.Review the impact, complete any required safety confirmation, and follow per-device progress from the Jobs page.

Everyday use cases

Fleet healthStale device reviewAUE planningAnnotation cleanupOU movesReplacement wavesBulk remediationCompliance reviewMulti-client operations

Value by role

Useful across the technology leadership team.

School technology teams

Manage student and staff Chromebooks across schools, grades, and delegated organizational units with clearer fleet data and safer operations.

MSPs and multi-entity organizations

Work across many domains from one deployment while keeping tenant data, permissions, and activity strictly isolated.

Help desks and asset teams

Find devices quickly and complete approved remediation or lifecycle work without exposing broader administrative access.

Security and privacy

Designed for responsible administration.

  • Keyless domain-wide delegation through IAM Credentials signing—no downloaded service-account keys
  • OAuth secrets and signing material stored in Secret Manager; tokens and full payloads are never logged
  • Role-based access and OU scoping enforced on reads and re-checked before destructive writes
  • Typed confirmations, second-approver gates, safety tiers, and duplicate-wipe protection
  • Immutable audit history records the actor, target, and sensitivity of each governed action
  • Strict tenant isolation for organizations and managed-service clients

Google environment

Supported connections and data sources vary by product and use case.

  • Google Workspace Admin APIs
  • ChromeOS device inventory
  • BigQuery
  • Cloud Run, Cloud Tasks, and Cloud Scheduler
  • Google OAuth and Secret Manager
Read the privacy policy

Frequently asked questions

What teams ask about Chrome Coyote.

Does Chrome Coyote store our service-account keys?

No. Google access uses keyless domain-wide delegation through IAM Credentials signing. Service-account keys are never downloaded or stored.

Can I limit what help-desk or student-worker technicians can do?

Yes. Role-based access and OU scoping determine which devices and actions each person can use, and those limits are enforced again before destructive changes.

What happens if a bulk action partially fails?

Every job records a result for each device. You can review the failures and retry only those devices without redoing the successful work.

Will actions keep running if I close my browser?

Yes. Actions run as durable background jobs on the server and continue after you sign out or close the tab.

Can Chrome Coyote manage multiple domains?

Yes. It is multi-tenant by design, so one deployment can serve many organizations or clients with strict isolation between them.

Does it work with the Google Admin console?

Yes. Chrome Coyote works alongside Google Workspace, reading device data and performing approved administrative actions through Google's official Admin APIs.

Start a practical conversation

See Chrome Coyote in your environment.

Tell us what your team is trying to improve. We’ll focus the conversation on the workflows and outcomes that matter to you.

Book a demo