Desk-Ops Agent
The small dot in your Windows tray that shows whether this machine's Desk-Ops service is healthy, and whether Desk-Ops is working on it right now.
What it is#
Desk-Ops Agent is a small program your IT or Desk-Ops installed on this PC. It only reads; the one thing it writes is the log zip you ask for, into a local folder. It puts one dot in the Windows tray and one panel behind it, so anyone at the desk can see whether the machine's Desk-Ops service is up and whether Desk-Ops is working on the machine at this moment.
IT questions live in Footprint and ceiling below.
Five colors, one glance#
Match the tile in your tray to a row. The panel word and line are the exact words you will see.
ActivegreenOn an Azure-plane machine the line is shorter: "Listener up, reading fresh."
Activeblue · pulsesCheckingStaleamber"Reading is stale — no fresh check in the last 90 seconds."
Checking in the first minute on an Arc machine is normal. If amber stays, see When to act.DownredStart listener: that asks the machine's own Desk-Ops setup to start it. The agent never starts the service itself. Still red? Collect logs and tell Desk-Ops.SetupgrayA stale reading always wins over a confident one: a stale Down is not red and a stale Active is not blue.
The panel, top to bottom#
Left-click the tray icon and the panel opens at the bottom right of your primary screen. It is one view: a status word, one line under it, two or three vitals, a run card when Desk-Ops is running something, and a footer. Every word on it comes from the agent's latest check.
- Header dot The same color as the tray icon dot: gray while not provisioned, red when the listener is down, amber when a reading is stale or unconfirmed, green when healthy, blue and pulsing during an active session.
- Pin Keeps the panel on top of other windows. It lights by itself for the whole of an active session.
- Close Hides the panel to the tray. The agent keeps running.
- Status word Active, Down, Stale, Checking or Setup, decided by the same rule as the dot color. The small dot beside it repeats the health color and is left out in the blue active-session state.
- Status line One plain sentence about the evidence the agent has right now, shown word for word from the latest check.
- Listener vital Whether the machine's Desk-Ops service is answering: Healthy, Not responding, Stale, Checking or a dash, with the age of the last check.
- Azure Arc vital The management plane's view: Connected, Disconnected, Not installed or Unknown, with the age of its last read. The row is left out on Azure-native machines.
- Listener version The service build the agent currently sees, sub-line "service build".
- Disclosure line The EU AI Act Article 50 disclosure. It reads "Runs on this machine are operated by AI." while idle and "This machine is being operated by AI." during a session.
- EU Disclosure A hover target whose tooltip carries the full disclosure sentence.
Controls and behavior
- Left-click the tray icon to open the panel; left-click again to hide it. Right-click opens the menu:
Start listener,Collect logsandOpen Desk-Ops folder.Start listeneris enabled only when setup has finished and the service is down; it asks the machine's own Desk-Ops setup to start the service, and confirms "Start requested" in the panel. - The panel hides when you click elsewhere, unless you pinned it, the dot is blue, or a run is on. In those three cases it also stays on top of other windows.
- The pin button reads
Keep this window on top; once pinned it readsPinned — click to release; while a session holds it up (blue) it readsOn top automatically during this session. ×hides the panel to the tray. There is no Quit item: the agent is meant to stay running, and IT stops it by uninstalling.- Starting the agent a second time does not start a second copy; it shows the panel.
- Hover the tray icon and the tooltip shows the current status line. On a fresh install the icon may sit behind the tray's overflow chevron.
When to act#
The strip above covers the glance. Two situations need more than a glance: support asking for logs, and a dot that stays amber or gray.
Support asked for logs? Right-click the tray icon, one menu item; the agent zips its diagnostics into a local folder, and the zip stays on this PC. Steps below.
- Dot still green A failed collect is not a health change. The dot, the status word and the vitals keep reporting the service.
- Notice line Shown only after a failed Collect logs. It reads: "Couldn't save the log bundle to the Desk-Ops folder on this PC — <Windows error>. Try again, or read this line to support." It names the folder and the Windows error, nothing else, and clears on the next successful collect or after 10 minutes.
Amber or gray that stays
Stale, Checking, Setup: what each means.Disconnected or Not installed and stays that way, tell Desk-Ops.IT admin: what runs on the machine, and what never does, is in Footprint and ceiling below.
Your first green dot#
You do not install the agent yourself. IT or Desk-Ops puts it on the machine over a managed channel, and the dot appears at your next sign-in.
What a session looks like#
Every 30 seconds the agent runs the same short check and paints the dot from the result. Below is one Desk-Ops session as the panel tells it, from idle to a collected bundle.
- Header dot Blue and pulsing: an operator session is connected to this machine.
- Pin Lit automatically for the whole session; its tooltip reads "On top automatically during this session". The panel stays on top and does not hide when you click elsewhere.
- Status line "This machine is being operated by Desk-Ops." The status card goes compact and the vitals collapse to one line.
- Run card header CURRENT RUN with the chip Executing. The chip reads Starting until the first step moves, then Executing, then the verdict word once the run completes.
- Goal The ordered change in the client's own words.
- Evidence line Ticket, run id and host, joined by dots.
- Meter Steps done over the total, here 3 of 5. After verification it becomes checks passed of checks total. The percentage is floored, never rounded up, so 5 of 6 reads 83%, not 100%.
- Active step The step happening now, highlighted, with the operator's one-line narration under it. Gray ticks above it are performed but not yet verified; the hollow circle below is pending.
- Disclosure line "This machine is being operated by AI." for as long as the session lasts.
Rail dot: green is automatic, coral is a person acting. Small pip: the tray color at that moment.
Green, idle
The service is up, Arc has confirmed the machine, nobody is connected. The agent checks every 30 seconds and nothing changes.
A Desk-Ops operator connects
The agent sees the new session at its next check, so blue can arrive up to 30 seconds after the session opens. The dot goes blue and, if the panel is open, it moves on top and stays put; it does not open by itself. The footer switches to "This machine is being operated by AI."
The run card appears
A run begins. The card shows CURRENT RUN with the chip Starting, then Executing; steps tick ○ ▶ ✓; the meter counts N of M. The card can trail the start of the run by up to 30 seconds.
The run completes
The chip shows the verdict, word for word: PASS, FAIL, or whatever the run reported. The card label reads RUN COMPLETE. If a run stops updating instead, the card says "Run status unknown — last update HH:MM UTC".
The operator disconnects, green follows
The agent keeps blue for a few seconds so a short gap does not flicker, then turns green on the next check. The panel drops back to normal. The card reads RUN COMPLETE for the run just finished; an older run shows LAST RUN.
Support asks for logs
You right-click the tray icon and choose Collect logs (the recipe is in When to act, above). The zip lands in the Desk-Ops folder, which opens, and nothing leaves the PC unless your Desk-Ops setup has switched the receipt note on.
Desk readers can stop here; the sections below are for IT admins and support staff.
Footprint and ceiling#
The agent is meant to be found. What it installs is visible with the tools already on the box.
You can see it yourself: the Startup entry and the Apps entry both read Desk-Ops Agent, the program lives in its own folder under Program Files, and the agent listens on no port.
What it does
- shows five dot states
- reads the local health state the service publishes
- checks that the machine's Desk-Ops service is answering
- confirms the machine is still enrolled with your management plane
- zips logs locally and opens the folder
- discloses AI operation in its footer
What it never does
- restarts or supervises the service
- uploads bundles or log text
- holds credentials or tokens
- records the screen, keystrokes, or video
- acts as a remote control or off switch
- updates itself (each release is a new installer)
- hides its process or its Apps entry
- listens on any port
The tray agent records nothing. A Desk-Ops operator run is screen-recorded as evidence and delivered with the run receipt.
Builds reach a machine only through your IT's managed channel, never a public download. Signed builds name Think Tank Consulting, LLC, the legal entity behind Desk-Ops. Never disable SmartScreen or Defender for an install — nothing from Desk-Ops will ever ask you to.
Working with support#
Support cases start and end with the log zip. Here is the short version.
The short version
Four things to know.Collect logs. Read the zip's file name to support, or attach it yourself; the agent never uploads it for you.From Beta 1 to 1.0.0#
None of this has a date. GA adds no features; it is the point where the beta has proven everything out.
Full observation surface
Five dot states, the panel, the run card, Collect logs. Delivered by IT over a managed channel.
Only if checks find something
Patches only if the beta turns something up. A clean beta means no patch at all.
Broader machine coverage
More machine classes get the full managed view.
Same features, proven
Promoted when the beta record is clean on both machine classes. Updates stay a new installer per release.