AA
Asset Admin
Asset Manager
—
Active
—
—
—
—
—
Enterprise ITAM UI
UI / workflow validation build • Backend, SSO and live integrations remain deployment-phase items
0Open Workflows
0Pending Approval
0Due / Attention
0Completed
Lifecycle Control Center
Every material action creates a transaction, history and audit eventOperational Queue
Requests and lifecycle transactions| ID | Type | Asset | Requester | Current State | Next Action | Created | Action |
|---|
Asset State Machine
Controlled transitionsREQUESTED→APPROVED→PROCURED→RECEIVED→REGISTERED→IN STOCK→ASSIGNED→RETURNED / REPAIR→RETIRED→SANITIZED→DISPOSED
Identity & Access
AuthenticationLocal LoginAllow local portal authentication as a fallback.
Asset ID Prefix by Asset TypeConfigure a different prefix and independent sequence for each Asset Type.
Examples: LAP-0001, DSK-0001, MON-0001. Prefix changes apply to new assets only.
Single Sign-On (SSO) Configuration
Entra ID · OIDC · SAML 2.0SSO EnabledEnable enterprise single sign-on on the login page.
Identity ProviderChoose the protocol. Only the selected provider's settings will be displayed below.
Microsoft Entra ID ConfigurationMicrosoft Entra ID uses OAuth 2.0 / OpenID Connect with Authorization Code + PKCE for the SPA.
Microsoft Entra IDLogin Button Display NameText displayed on the login page.
Redirect URISPA redirect URI registered in Entra ID.
Post Logout Redirect URIReturn location after Entra sign-out.
Tenant IDMicrosoft Entra Directory (tenant) ID.
SPA Client IDApplication (client) ID for the ITAM SPA.
AuthorityEntra v2 authority endpoint.
API ScopeDelegated API scope requested by the SPA.
Access & ProvisioningSigning in with Microsoft Entra ID only authenticates the identity. Portal access, Department and Role come from the Users & Departments master (Users & Departments page) — a person not already provisioned there sees Access Denied even after a successful Microsoft sign-in. Use "Azure AD Group Provisioning" on that page to bulk-provision an Azure AD group's members with a Department in one step.
SSO Configuration StatusNot configured
Freshservice Integration
Service Request sourceFreshservice IntegrationEnable loading Service Requests from Freshservice into the Asset Registration dropdown.
Freshservice InstanceExample: https://yourcompany.freshservice.com
Freshservice API KeyStored in the backend (DynamoDB) only. All ticket lookups are proxied server-side by this portal's own API, so this key is never sent to any browser.
Freshservice Workspace IDOptional. Leave blank for the primary workspace.
API Proxy URL (legacy, unused)No longer needed — this portal's backend now proxies Freshservice server-side automatically. Leave blank.
Integration OwnershipFreshservice: service requests and ITSM references · ITAM: asset lifecycle and custody.
ITSM + ITAMFreshservice SettingsSaves the whole System Configuration, including Identity & Access and SSO above.
Portal Branding
Logo & identityLivegage
Recommended: transparent PNG or SVG. The selected logo is stored locally in this SPA prototype.
Example: EUC- generates EUC-0010, EUC-0011…; IT- generates IT-0010, IT-0011…. Prefix changes apply to newly generated Asset IDs only.
Scheduled Email Reports
Dashboard summary + Asset RegisterWeekly ReportEmails a dashboard KPI/compliance summary (HTML) with the full Asset Register attached as a CSV.
ScheduleFixed at deployment via an AWS EventBridge rule on the backend, not editable here.
WeeklyRecipientsComma-separated email addresses. Each must be SES-verified (or your SES account/domain must be out of sandbox) to receive the report.
Report SettingsSaves the whole System Configuration, including the sections above.
Configuration Status
Current settingsNo changes pending. Freshservice settings are managed in the Freshservice Integration section above.
Approval Queue
Separation of Duties enforced| Approval ID | Asset | Type | Requester | Reference | Approver | Status | Action |
|---|
0Portal Users
0Active Users
0Assigned Roles
0Approval Roles
Portal Users
| Username | Name | Role | Department | Status | Actions |
|---|
Role Matrix
Enterprise RBAC| Role | Register / Edit | Issue | Issue Approval | Lost/Stolen Approval | Retirement Approval | Lifecycle Actions | Audit |
|---|---|---|---|---|---|---|---|
| Administrator Backend admin — full access, can act on any approval step including self-approval | Full | Yes | Approve (any step) | Approve (any step) | Approve (any step) | Full | View |
| Asset Admin | Full | Yes | No self-approval | No self-approval | No self-approval | Full | View |
| Asset Manager | Full | Yes | Approve | Approve | Approve | Full | View |
| EUC Asset Custodian | Create / Update | Execute | No | Report | Request | Operational | View |
| Service Desk | Create / Update | Request / Execute | No | Report | Request | Operational | View |
| Department Manager | View | Request | Approve | Approve | Approve | No | View |
| IT Manager | View | Request | Approve | Approve | Approve | No | View |
| Finance Approver Approves Disposal, Write-off, Purchase Request and Purchase Order (not shown as separate columns here) | View | View | No | No | No | No | View |
| Security Approver Approves Stolen-asset declarations and Compliance Exceptions | View | View | No | Approve (Stolen only) | No | No | View |
| Auditor / Read Only | View | View | View | View | View | No | View |
ENTERPRISE ASSET GOVERNANCE
IT Asset Management Dashboard
Executive visibility into EUC inventory, endpoint security posture, lifecycle control and governance risk.
AAAsset Admin
EUC Administrator
EUC Administrator
0Authoritative inventory
0Active custody
0In stock / ready
0Requires remediation
0Expiring within 90 days
0Lifecycle completed
Security Compliance Posture
Control-level compliance across the EUC estate0%
Overall Control HealthAverage of core endpoint controls
0Fully compliant assets
0At-risk assets
0Partially compliant
Compliance Distribution
Asset-level security status0Assets
Compliant0
Non-Compliant0
Partially Compliant0
Control interpretationMirrors the Assessment on the Compliance Health page. Compliant = MDM / Intune + Encryption + EDR are all compliant. Partially Compliant = one or two of them are confirmed. Non-Compliant = none of them are confirmed (failing or not yet reported).
Assets by Type
Total, issued and in-stock position for each asset type. Click a number to list those assets.| Asset Type | Total | Issued | In Stock | Faulty in Stock | Available | Other |
|---|---|---|---|---|---|---|
| No assets yet. | ||||||
Governance Attention
Priority exceptions requiring operational action0Non-compliant devices
0Warranty due within 90 days
0Assets pending assignment
0Active managed assets
Lifecycle Portfolio
Current asset-state distributionAssigned
0
In Stock
0
In Repair
0
Lost / Stolen
0
Retired
0
All EUC Assets
Use View for complete asset details or Assignment for the complete lifecycle and custody history.
| Asset ID | User | Asset Type | Manufacturer | Model | Serial No | Hostname | Department | Location | Status | Compliance | Action |
|---|
Current Assignments
Custody overview| Asset | Assigned User | Department | Location | Status |
|---|
0Total Assignment Events
0Active Assignments
0Returned / Closed
0Reassignments
Assignment History
Custody chain| Asset | Previous User | New User | Department | Assigned | Returned | Service Request | Custodian | Status |
|---|
Selected Asset — Complete History
Select an asset from the tableSelect an Assignment History record to view the complete chronological lifecycle and assignment history.
0In Stock
0Assigned
0In Repair
0Retired
Lifecycle Register
| Asset | Purchase Date | Current State | Warranty End | Location |
|---|
0%Encryption
0%EDR
0%MDM / Intune
Security & Compliance by Asset
Endpoint-control posture, ownership and evidence status| Asset | Asset Type | User | Department | Serial No | Encryption | EDR | MDM / Intune | Assessment | Evidence |
|---|
Evidence control: When MDM / Intune is Yes, Encryption is Compliant, or EDR is Compliant, supporting evidence is required on the asset record. Use View or Edit from the Asset Register to review or update evidence.
Open EUC Exceptions
Derived from non-compliant endpoint controls| Exception | Asset | Owner | Priority | Status |
|---|
User & Department Master
Authoritative user source| User | Display Name | Department | Role | Provisioning | Action |
|---|
0Items
0Manufacturers
0Models
0Asset Types
Item Catalog
Used by PR and PO| Item Code | Item Name | Category | Asset Type | Manufacturer | Model | UOM | Serialized | Status | Action |
|---|
0Vendors
0Active
0Inactive
0Categories
Registered Vendors
Authoritative vendor source across ITAM| Vendor Code | Legal Vendor Name | Category / Type | Criticality | Status | Action |
|---|
Receiving & Stock isn't listed separately — its rows are generated from Procurement's Purchase Orders, so deleting a PO here already removes its receiving rows too. Peripherals are removed one at a time via the existing "Detach" action on an asset's Attached Peripheral screen; "Clear All" below still wipes the whole peripheral list at once if needed. Assignment History and Lifecycle are historical logs, not row-editable records, so they only offer "Clear All" (never per-row delete).
Sections
Record counts refresh each time you open this page| Section | Records | Action |
|---|
0Pending Approval
0Approved
0Rejected
0Elevated Approval
Issuance Approval Queue
DOA-controlled requests
Recommended EUC Issuance DOA
1. RequesterEmployee / Service Desk raises issuance request.
2. Asset CustodianValidates asset, stock, user and business need.
3. ApproverDepartment Manager / authorized DOA approver approves issuance.
4. HandoverService Desk records custody acceptance and issue date.
| Request ID | Asset | Requester | Business Unit | DOA Tier | Status | Action |
|---|
DOA Rules
Example policy configuration| Tier | Trigger | Required Approver | Control |
|---|---|---|---|
| Tier 1 | Standard EUC asset | Department Manager | Business need + user eligibility |
| Tier 2 | Privileged / restricted-use device | Department Head + Information Security | Security justification + additional controls |
| Exception | Outside standard entitlement | Authorized exception approver | Documented exception / risk acceptance |
0Register Assets
0Unique Serials
0Hostnames
0Duplicate Serials
Production integration point: connect this module to Intune, Jamf, AD, SCCM or another endpoint source through an API and reconcile by immutable device/serial identifier.
Recent Activity
Prototype activity log| Timestamp | Action | Record | Actor | Result |
|---|
Available Reports
Role × Page Visibility
Changes apply immediately in this browser and sync to every other user on saveEntra IDRecommended authentication
RBACRole-based access
APIBackend integration ready
AuditImmutable server log recommended
Recommended roles: EUC Administrator, EUC Asset Manager, Service Desk, Department Asset Custodian, Auditor, Read Only.
Local Account Password Reset
Use for local portal accounts only. SSO credentials remain managed by Microsoft Entra ID.Open PRs
0
Open POs
0
Ordered Units
0
Received Units
0
Pending Receipt
0
Manufacturers
0
Purchase Request Register
Business requirement before a PO is created. PR line items capture requested quantity and expected delivery.
| PR Number | Requester | Department | Required Date | Items | Qty | Priority | Status | Actions |
|---|
Purchase Order Register
PO header plus line-item quantities. Receiving records actual accepted quantities and serial numbers.
| PO Number | PR Number | Vendor | Qty Ordered | Qty Received | Pending | Status | Manufacturer | Invoice No. | Invoice Date | Warranty Start | Warranty End | Registered Assets | Actions |
|---|
0Procured Units
0Accepted / Received
0Available Stock
0Allocated
0Rejected / Quarantined
Receiving Register
One row per procured serial number| PO Number | Procurement ID | Vendor | Asset Type | Manufacturer | Model | Serial Number | Receipt Status | Condition | Stock State | Location | Received Date | Invoice No. | Invoice Date | Warranty Start | Warranty End | Asset ID | Action |
|---|
Stock Control Rules
Controlled availabilityAvailability rule: A serial becomes available for Asset Registration only after it is physically received and marked Received / Good. Rejected, Quarantined, or Pending items cannot be registered.
Allocation rule: Once a serial is registered to an Asset ID, its stock state becomes Allocated and it is removed from the available-stock pool.