Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
133 changes: 133 additions & 0 deletions docs/employee-guide/employee-portal/my-card.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,133 @@
---
title: 'My Digital Card'
sidebar_label: 'My Digital Card'
description: 'Activate, edit, and share your digital business card from the ShiftControl employee portal — a live link and QR code that stay up to date.'
keywords: ['ShiftControl', 'employee portal', 'my card', 'digital business card', 'QR code', 'share contact', 'vCard', 'PIN']
---

import Admonition from '@theme/Admonition';
import ModeScreenshot from '@site/src/components/ModeScreenshot';

<p style={{fontSize: "large"}}>Share your contact details instantly — no app to install, no paper to run out of.</p>

<Admonition type="info" title="Don't see My digital card?">
Digital cards is an optional feature your IT team switches on for the whole organization. If <strong>My digital card</strong> isn't in your employee-portal sidebar, your admin hasn't turned it on — ask them if you think you should have it.
</Admonition>

## Why this exists

Paper business cards are out of date the day they're printed, and you never have one when you need it. Standalone card apps want a monthly subscription and don't know anything about you.

Your digital card solves both. It's already built from your directory profile, so your name, title, and department are right without you typing them. You get a short link and a QR code you can show on your phone, put in your email signature, or print on a lanyard — and when your title changes, the card follows.

## Activating your card

Open **My digital card** from your employee-portal sidebar. The first time, you'll see a preview of your card built from your profile, with an **Activate my card** button.

Some details in that first preview may be sample values — the page tells you which ones — because your profile doesn't have everything a card can show. You'll set the real values right after activating.

Choose **Activate my card**. That creates your card as a draft and drops you straight into the edit screen to review it.

<Admonition type="note" title="Nothing is public until you publish">
Activating creates a private draft. Your card isn't on the internet until you publish it, which is a separate step on the <strong>Manage</strong> tab.
</Admonition>

Your company may also present card activation as a step during onboarding — if you did it there, your card is already activated and you'll land straight on it.

## The four tabs

Once your card exists, the page has four tabs.

### My card

Your live card as other people see it, with everything you need to share it.

<ModeScreenshot path="EmployeePortal/My-card" alt="The My card tab showing the live card preview alongside the QR code, copy-link button, and QR download sizes" />

- **Your card link** — **Copy** puts it on your clipboard, ready for an email signature or a chat message.
- **Your QR code** — hold your phone up and someone can scan it to save you as a contact.
- **QR downloads** — four sizes, labelled for what they're good for: **256×256** for web and chat, **512×512** for an email signature, **1024×1024** print-ready, and **2048×2048** for large format. There's also **Download SVG** if whoever's doing your print work wants a vector.
- **A status badge** tells you whether the card is **Live**.

The card itself has **Save contact**, **Call**, and **Email** buttons — those are for the person you're sharing with, so they can save you to their phone in one tap.

On a narrow screen, a **Share my card** button opens a share sheet with the same QR code, copy-link, and downloads.

### Edit my card

Your photo and details.

<ModeScreenshot path="EmployeePortal/My-card-edit" alt="The Edit my card tab with photo controls and card details showing locked, synced, and customized fields beside a live preview" />

**Photo** — **Replace photo** uploads a new one, **Remove** clears it, and **Reset to profile photo** puts your directory photo back. Square works best, at least 400×400; it gets resized to fit.

**Card details** — what you can change here depends on how your admin set the card up:

- A field with a **lock** icon is controlled by your company. You can see it, but not change it.
- A field marked **Synced** comes from your directory profile. If you'd rather show something different, choose **Customize** — the field becomes yours to edit, and your directory value stays visible underneath for reference. **Re-sync** reconnects it.
- Everything else you can just type into. Fields marked *optional* are ones you can choose to leave blank.

Nothing is saved until you press **Save changes**. **Discard** throws away your edits.

<Admonition type="tip" title="Customize is how you show your preferred job title">
If your directory says "Senior Manager, Commercial Partnerships" and you introduce yourself as something shorter, choose <strong>Customize</strong> on the title and set the version you actually use. It won't be overwritten the next time your profile syncs.
</Admonition>

### My QR code

Changes what sits in the middle of your QR code.

<ModeScreenshot path="EmployeePortal/My-card-qr" alt="The My QR code tab with the centre medallion options — company logo, none, my photo, and custom image — beside a live QR preview" />

Pick **Company logo**, **None**, **My photo**, or **Custom image** and press **Save medallion**. Your company sets a default, but your choice wins.

<Admonition type="note" title="Download a fresh copy after changing your medallion">
The change applies everywhere your code appears, but a QR image you already downloaded still shows the old medallion. Grab a new download from the <strong>My card</strong> tab after saving.
</Admonition>

Sharing and downloading live on the **My card** tab — this tab only changes the code's appearance.

### Manage

Publishing and your card's PIN.

<ModeScreenshot path="EmployeePortal/My-card-manage" alt="The Manage tab showing card status with an unpublish action and the card PIN section" />

- **Card status** — whether your card is live, with a button to **publish** or **unpublish** it. Unpublishing takes the card off the internet without deleting anything, so you can publish again whenever you like. *(Your admin can turn this off, in which case they control publishing.)*
- **Card PIN** — require a code before your card shows its contents. It doesn't have to be numbers; a word or short phrase works, up to 24 characters. You can change or remove it at any time, and you can see the current value.
- **Your card link** — if your admin has allowed it, you can regenerate your link here. Most organizations keep this with admins.

## Common questions

### Who can see my card?

Anyone with the link. Your card link is long and random, so nobody can guess it or find your colleagues by changing the URL — and cards aren't listed in any public directory or indexed by search engines. But treat the link as public: anyone you give it to can pass it on.

If that's a concern, set a **PIN** on the **Manage** tab, or **unpublish** the card when you're not using it.

### Can I have more than one card?

No — one card per person.

### What happens to my card if I leave?

Your company sets that policy in advance. Depending on what they chose, your link will either show a neutral "no longer with the company" card, redirect to a company page, or stop working. Your admin may also apply a grace period first.

### My title on the card is wrong

If the field is **locked**, your admin controls it — ask them to change it. If it's **synced**, either get your directory profile corrected or use **Customize** to set the value yourself.

### Why can't I edit some fields?

Your admin locked them so that cards across the company always match the directory. It's not personal — name, title, and department are the usual ones.

### I changed my photo but the card still shows the old one

Photo changes save with the rest of the form. Make sure you pressed **Save changes** on the **Edit my card** tab.

## Related pages

- [Your Apps](/employee-guide/employee-portal/your-apps) — the applications you have access to.
- [My Devices](/employee-guide/employee-portal/my-devices) — the hardware assigned to you.
- [Org Chart](/employee-guide/employee-portal/org-chart) — who's who, and where you fit.
- [Account Security](/employee-guide/employee-portal/account-security) — your sign-in and MFA settings.
30 changes: 29 additions & 1 deletion docs/using-shiftcontrol/Devices/Device-actions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,33 @@ Removes the device from JumpCloud management.
If a device isn't checking in when you un-manage it, the agent and policies **can't be removed remotely** — someone has to uninstall the agent on the machine itself. Otherwise you've removed the record while an agent keeps running on the endpoint.
</Admonition>

#### Un-managing several devices at once

Retiring a batch of devices — a hardware refresh, a closed office, a stack of returned laptops — used to mean repeating the single-device flow once per machine. You can now do it in one pass from the [Device Inventory](/using-shiftcontrol/Devices/Viewing-devices).

Select the devices with the checkboxes on the inventory grid, then open **Bulk Actions** in the toolbar and choose **Un-manage**.

<ModeScreenshot path="Devices/Device-bulk-unmanage" modes={["jc-only", "jc-google", "google-jc"]} alt="The Device Inventory grid with several devices selected and the Bulk Actions menu open showing Un-manage" />

Un-manage is deliberately the **only** bulk device action. Lock, restart, shut down, and erase all carry too much blast radius to expose behind a single click on a multi-row selection — those stay one device at a time, on the device's own page.

**How the batch behaves:**

- **Type-to-confirm.** Like the single-device flow, you type `unmanage` to enable the confirm button. A misclick can't retire your fleet.
- **Per-device results.** When the batch settles you get a list naming which devices were un-managed and which failed, with a reason for each failure. One error doesn't abort the rest and doesn't hide what happened.
- **Throttled.** ShiftControl works through the selection a few at a time rather than firing everything at JumpCloud at once, so a large selection takes a little longer but doesn't get rate-limited.
- **Same permission as single un-manage.** Anyone who can un-manage one device can un-manage several — there's no separate bulk permission. That's worth knowing when you grant the **Destructive** tier.

Everything in [Un-manage](#un-manage) above still applies to every device in the batch: data is left intact, active devices uninstall the agent themselves, inactive devices need a manual agent removal, and re-managing means re-enrolling from scratch.

<Admonition type="warning" title="Capture recovery keys before a bulk un-manage">
Recovery keys are only retrievable for about <strong>30 days after a device is deleted from JumpCloud</strong>, and there's no bulk reveal. If you might need the FileVault or BitLocker key for any device in your selection, reveal and save it <strong>before</strong> you run the batch — afterward the clock is already running on all of them at once.
</Admonition>

<Admonition type="info" title="Available on the Device Inventory only">
Multi-select and bulk actions live on the Device Inventory grid. The <strong>Needs Attention</strong> and <strong>Device Health</strong> views are read-only triage surfaces — filter or search the inventory to build the selection you want.
</Admonition>

### Erase device

Wipes all data and returns the device toward factory state. This is the most destructive action in ShiftControl.
Expand All @@ -111,7 +138,7 @@ ShiftControl adds guardrails on top of JumpCloud:
- **Type the device name to confirm.** Erase won't proceed on a misclick — you have to type the exact device name.
- **Capture the recovery key first.** Reveal and save the FileVault/BitLocker key *before* erasing; the wipe destroys it. ShiftControl prompts you toward this, but it's on you to actually save it.
- **macOS PIN.** Erase surfaces a 6-digit PIN. On Intel Macs without a T2 chip, that PIN is required to recover the device and **cannot be recovered if lost** — record it. On Apple Silicon and T2 Macs, recovery is protected by Activation Lock instead, and the PIN may be ignored — that's expected.
- **No bulk erase.** You erase one device at a time, on purpose.
- **No bulk erase.** You erase one device at a time, on purpose — [bulk un-manage](#un-managing-several-devices-at-once) exists, bulk erase does not.
- **Warn the user.** The erase doesn't warn the person using the device — you do.

Platform behavior differs:
Expand Down Expand Up @@ -141,6 +168,7 @@ When someone leaves, do device steps in this order so you never destroy somethin
- **Everything is logged**, including recovery-key reveals, in an append-only audit trail.
- **Erase queues when offline** and runs on reconnect — treat a queued erase as already committed.
- **Un-manage ≠ erase.** Un-manage leaves data intact; erase destroys it. Choose deliberately.
- **Un-manage is the only bulk action**, and it uses the same permission as the single-device version. Every other action stays one device at a time.

## Related Features

Expand Down
10 changes: 10 additions & 0 deletions docs/using-shiftcontrol/Devices/Viewing-devices.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,16 @@ Each row shows the fields IT actually uses to make decisions:

Click any row to open the [device's detail page](/using-shiftcontrol/Devices/Device-details).

### Selecting several devices

Each row has a checkbox, and the header checkbox selects everything currently showing. With a selection made, a **Bulk Actions** menu appears in the toolbar.

The only bulk action today is **Un-manage** — the batch version of retiring a device from JumpCloud management. It's the lowest-risk, highest-volume thing admins actually need to do to many devices at once; the destructive actions like erase stay deliberately one-at-a-time. See [bulk un-manage](/using-shiftcontrol/Devices/Device-actions#un-managing-several-devices-at-once) for how the batch behaves and what to save first.

<Admonition type="tip" title="Filter first, then select">
Combine the filters and search to get exactly the devices you mean — say <em>Dormant</em> plus <em>Windows</em> for a batch of retired machines — then use the header checkbox. It's faster and safer than hunting rows by hand.
</Admonition>

### Filtering and search

Filter the list by **status** (online, offline, dormant), **platform** (macOS, Windows, Linux, iPadOS), **encryption** (encrypted / unencrypted), and **assignment** (assigned / unassigned). Combine filters to narrow quickly — for example, *unencrypted* + *macOS* — and use search to jump to a specific name, hostname, or serial.
Expand Down
67 changes: 67 additions & 0 deletions docs/using-shiftcontrol/DigitalCards/Card-domain.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
title: 'Card Domain'
sidebar_label: "Domain"
description: 'Serve your digital business cards from your own hostname instead of cards.shiftcontrol.io, with DNS verification and a permanent ShiftControl fallback.'
keywords: ['ShiftControl', 'digital business cards', 'custom domain', 'hostname', 'DNS', 'CNAME', 'branding', 'cards.shiftcontrol.io']
icon: 'globe'
---

import ModeScreenshot from '@site/src/components/ModeScreenshot';
import Admonition from '@theme/Admonition';

<p style={{fontSize: "large"}}>Put your own hostname on the links your team hands out — without invalidating anything already printed.</p>

## Overview

By default your cards are served from `cards.shiftcontrol.io`. That works, and it's what every card falls back to. But the URL is part of the card: someone scanning a code or reading an email signature sees the hostname, and `cards.yourcompany.com` reads as yours in a way that a vendor domain doesn't.

The **Domain** tab lets you add a hostname you control and serve cards from it. Find it under **Settings → Digital cards → Domain**.

<ModeScreenshot path="DigitalCards/Card-domain" alt="The Domain tab showing the always-on ShiftControl hostname marked Primary and the custom domain form" />

## How It Works

Exactly one hostname on this tab carries the cyan **Primary** badge, so "which hostname do my links use right now?" is answerable at a glance.

- **Before you add a custom domain**, `cards.shiftcontrol.io` holds the primary slot.
- **Once your custom domain is verified and serving**, it takes the primary slot and the ShiftControl hostname drops below it as a smaller, muted **Fallback** row.

The ShiftControl hostname is never turned off. Every card always works there, including while a custom domain is mid-setup and after one is live. That's the property that makes this safe to adopt at any point: **cards already printed with the ShiftControl URL keep working forever.**

### Adding your domain

Enter a subdomain you control — something like `cards.acme.com` — and choose **Add domain**. ShiftControl then gives you the DNS records to add at your DNS provider so it can verify you own the hostname and issue a certificate for it.

Once the records resolve and verification completes, the domain starts serving and takes over as primary. New links and newly generated QR codes use it.

<Admonition type="note" title="Use a subdomain, not your apex domain">
Point a dedicated subdomain such as <code>cards.acme.com</code> at ShiftControl. Don't try to serve cards from your root domain — that's where your website lives, and the two can't share the hostname.
</Admonition>

<Admonition type="info" title="DNS changes take as long as DNS takes">
Verification can't complete until your new records have propagated. If it doesn't verify immediately, that's usually propagation rather than a mistake — re-check after your provider's TTL has elapsed. Meanwhile every card keeps working on the ShiftControl hostname.
</Admonition>

## Common Scenarios

### Scenario: Moving to your own hostname after a pilot

You rolled cards out to the sales team on `cards.shiftcontrol.io` and it went well. Now you want the company hostname. You add `cards.yourcompany.com`, add the DNS records, and wait for verification. When it goes live, it becomes primary and new shares use it — and the QR codes from the pilot, printed on the ShiftControl hostname, keep resolving. Nothing gets reissued.

### Scenario: Deciding whether it's worth it

You're a ten-person company and nobody looks closely at the URL under a QR code. The ShiftControl hostname is fine and requires no DNS work — skip it. Revisit if you start printing cards at volume or your brand team asks.

## Things to Know

- **The ShiftControl hostname is permanent.** It stays a working fallback for every card, forever. Adding a custom domain never breaks an existing link.
- **One hostname is primary at a time**, and it's the one badged **Primary**.
- **Verification needs DNS access.** You'll need someone who can add records for the domain.
- **Existing QR codes don't change.** A code encodes the URL it was generated with. Regenerate a QR code from a card if you specifically want the new hostname on it.
- **View-only admins see this page read-only.** Without *Manage card settings*, the controls render disabled.

## Related Features

- [Digital cards overview](/using-shiftcontrol/DigitalCards/Digital-cards-overview) — how cards are served and why links are unguessable.
- [Card template](/using-shiftcontrol/DigitalCards/Card-template) — the rest of your card branding.
- [My digital card (Employee Guide)](/employee-guide/employee-portal/my-card) — where employees copy their link and download QR codes.
Loading