On the computers
From the outside
In the cloud
Against threat data
The short version
How the automatic schedule works
Everything above runs on Telivy’s own servers. There is nothing to install, schedule, or maintain on your side, and nothing that depends on someone being logged in. The runs are spread out on purpose. A weekly run covers a lot of clients, so Telivy works through them in a queue instead of firing everything off together, and a single run can take hours to reach everyone. That is normal, and a client near the back of the queue is not stuck. They also recover on their own. If a scan is interrupted, it gets picked up and retried without anyone having to notice.On the computers: what the agent does
The Telivy Agent runs quietly in the background on every device where it is installed, on both Windows and Mac. It wakes up roughly once an hour. Waking up hourly is not the same as scanning hourly, and this trips people up more than anything else on this page. On each hourly wake-up, the agent:Says hello
Checks whether it should update itself
Collects any instruction waiting for it
Does any collection that is actually due
How often each type of data is refreshed
From the outside: what Telivy checks without touching a device
These checks need no agent. They run against the client’s domain, any extra domains you have added, and any IP addresses on the assessment.In the cloud: Microsoft 365 and Google Workspace
If the client has a connected Microsoft 365 or Google Workspace tenant, Telivy reads its security configuration daily. That covers user accounts, multi-factor authentication, admin roles, dormant accounts, sharing settings, and tenant policy. For Microsoft 365, sign-in and audit activity can also be collected every hour where that capability is enabled for your agency. That is what makes event-based alerts such as repeated failed logins possible. Telivy also checks every few hours that the connection itself is still healthy. Cloud connections expire or get revoked, usually when someone changes an admin password or adjusts consent. When that happens the assessment flags it so you can reconnect, instead of quietly collecting nothing. Daily cloud scanning applies to clients with Risk Monitoring switched on, and you can turn it off per client separately from endpoint scanning. Keeping daily Microsoft 365 coverage while endpoints rescan monthly is a perfectly normal setup. See Microsoft 365 Security and Google Workspace Security for what is assessed.Against threat data: why findings appear on their own
This is the part that surprises people most, so it is worth saying plainly. New findings can appear without any device being scanned again. Telivy keeps a record of what software each machine had at its last scan. Separately, it pulls in new vulnerability information every night, along with which vulnerabilities are being actively exploited in the real world and how likely each one is to be attacked. Once a week, Telivy re-compares the software it already knows about against that updated information. If a serious vulnerability was published against a version of a browser your client was already running, it appears in that weekly comparison. Nobody had to touch the machine. This also works in the other direction. A finding’s severity can rise or fall as the security community learns more about it, which is why a client’s numbers can shift slightly between rescans. Vulnerability Data Sources explains where this information comes from and how Telivy prioritizes it.What you actually control
Per client, from the assessment’s scan settings, you choose:- how often endpoints are fully rescanned: weekly, monthly, quarterly, or off
- whether Microsoft 365 monitoring is on
- whether Google Workspace monitoring is on
What a scheduled rescan actually covers
When a client’s cadence comes round, Telivy saves a snapshot of where things stand so you can see what changed, then refreshes everything: the devices, the external picture, and any connected cloud tenant. A rescan replaces the current findings rather than sitting alongside them. The history is kept separately, so you can still show a client how their position has moved over time.FAQ
My client is set to monthly. Why did something change this week?
My client is set to monthly. Why did something change this week?
I clicked rescan. Why do some devices still show old data?
I clicked rescan. Why do some devices still show old data?
Does the agent scan the computer every hour?
Does the agent scan the computer every hour?
How often is the dark web checked?
How often is the dark web checked?
How often are look-alike domains checked?
How often are look-alike domains checked?
A new vulnerability was announced for software my client runs. When will I see it?
A new vulnerability was announced for software my client runs. When will I see it?
Can I change the times these checks run?
Can I change the times these checks run?
Do scheduled rescans count against my assessment allowance?
Do scheduled rescans count against my assessment allowance?
What happens if a scan does not finish?
What happens if a scan does not finish?