> ## Documentation Index
> Fetch the complete documentation index at: https://docs.myrmex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent & Endpoint Security

> The Myrmex software agent: one program, two roles — Endpoint on a host, Collector for your integrations — installed from the console and driven by the AI agents.

This section is about the **software agent**: the program you install on a machine so Myrmex can see it and act on it. It is a different thing from the **AI agents** — Perseus, Centurion, Brontes and the rest — which decide *what* to collect and *what* to do. The software agent carries those decisions out.

<Note>
  Keep the two apart as you read. "Install the agent" always means the program on
  the host. "The agent decided" always means an
  [AI agent](/documentation/ai-agents/overview).
</Note>

## One Program, Two Roles

You install the same binary either way. What changes is the **role** it plays, and you can switch a device between them from its detail view.

<CardGroup cols={2}>
  <Card title="Endpoint" icon="laptop" href="/documentation/agent-endpoint-security/endpoint-mode">
    Runs **on the host you want to watch** — a workstation or a server. It
    collects the machine's telemetry and carries out response actions there.
  </Card>

  <Card title="Collector" icon="tower-broadcast" href="/documentation/agent-endpoint-security/collector-mode">
    Runs as a **bridge to your integrations**, reaching systems that cannot run
    the agent themselves — a firewall, a SIEM, a cloud account.
  </Card>
</CardGroup>

## What It Does

The agent follows one model: **collect → enrich → respond**. It gathers telemetry from the operating system, normalises it, and executes actions when an AI agent asks it to.

<CardGroup cols={2}>
  <Card title="Agent Capabilities" icon="list-check" href="/documentation/agent-endpoint-security/features">
    The telemetry it collects and the actions it can take on a host.
  </Card>

  <Card title="Agent Architecture" icon="sitemap" href="/documentation/agent-endpoint-security/architecture">
    How the collect, enrich and respond stages fit together on the machine.
  </Card>
</CardGroup>

## Where to Start

Install it from **Download Agent** in the console. You pick the operating system, choose between the installer and a script, and the page hands you an installation token to paste during setup.

<Frame>
  <img src="https://mintcdn.com/ainext-d322f0b7/cob3Pis6P28X3MqY/images/agent-install.png?fit=max&auto=format&n=cob3Pis6P28X3MqY&q=85&s=d9d36a7a806dec5f82b53a8869cd5dd4" alt="The Install Agent screen, with the operating system chosen and the installation token ready to copy" className="rounded-xl" width="1176" height="1021" data-path="images/agent-install.png" />
</Frame>

A new device registers as **unauthorised** and waits for you to approve it — nothing is collected until you do.

## Where to Go Next

<CardGroup cols={2}>
  <Card title="Deploying the Agent" icon="download" href="/documentation/agent-endpoint-security/installation">
    The full install walkthrough for Windows, Linux and macOS.
  </Card>

  <Card title="Endpoints & Device Inventory" icon="server" href="/documentation/agent-endpoint-security/endpoints-view">
    Browse everything registered, grouped into folders and ranked by severity.
  </Card>

  <Card title="Device Details & Actions" icon="magnifying-glass" href="/documentation/agent-endpoint-security/device-details">
    Open one machine to authorise it, switch its role, set rules and audit it.
  </Card>

  <Card title="Patch & Update Management" icon="arrows-rotate" href="/documentation/agent-endpoint-security/patch-management">
    Review pending operating-system updates and approve the proposed schedules.
  </Card>

  <Card title="Agent Communication & Security" icon="lock" href="/documentation/agent-endpoint-security/communication">
    How the agent enrolls, proves its identity and talks to the platform.
  </Card>
</CardGroup>
