Section 05
Endpoint controls, updates, and removal
Evaluate the complete deployed image because kiosk controls span application code, install scripts, system services, compositor policy, input controls, and physical configuration.
Ask how updates are built, approved, delivered, logged, tested, rolled back, and supported. Confirm who owns patching for the operating system, client packages, certificates, optional device services, target workstations, and dealership applications.
Removal should cover the device, management identity, local state, logs, network exceptions, support access, inventory record, and physical disposition. The existing dealership workstation and applications should remain available independently.
Lifecycle requirements
Restricted interface and physical-access review
USB, input, VT, compositor, and watchdog validation
Update owner, cadence, evidence, and rollback
Support boundaries and incident escalation
Disablement, removal, local-state handling, and disposal