A percentage over an unknown denominator
Compliance is reported against the machines the tool knows about. The ones it does not know about are not counted as failures — they are not counted at all, which is the more serious problem.
Platform expertise / HCL BigFix
BigFix can reach further into an estate than almost anything else and assess it continuously. What it cannot do is decide what "patched" means, who owns an exception, or which of your machines should have been in scope last month. Aevis works on those first, then configures BigFix to enforce them.
HCL BigFix is third-party software selected and licensed by the client from HCLSoftware. Aevis provides advisory, deployment, content-authoring and operational services around the client’s deployment.
Endpoint control layer
Discovered · assessed · remediated · evidencedPlatform fit
Most BigFix conversations start with a number somebody has stopped believing. Ninety-four per cent compliant, against a denominator assembled from an asset register that has not been reconciled in two years.
Compliance is reported against the machines the tool knows about. The ones it does not know about are not counted as failures — they are not counted at all, which is the more serious problem.
A machine was excluded for a good reason in 2023 and the reason left with the person who gave it. The exclusion list grows and nobody can say which entries are still justified.
Years of hand-written fixlets and relevance built by different people, undocumented, running against machines they were never tested on. Change stopped because the blast radius is unknown.
Our role is to make the deployment accurate, owned and defensible in your environment — not to sell an Aevis software product.
Product landscape
We shape the engagement around the modules and entitlements your organisation has licensed. Scope, capability and platform support always depend on your licensing and version.
Patching, software distribution, OS deployment and the day-to-day operation of the endpoint estate.
Continuous configuration assessment against benchmarks, with drift visible per machine rather than per report.
Software discovery and licence position — usually the first place the estate’s real shape becomes visible.
Reporting across deployments and the data layer other tools can read the endpoint position from.
The join between a scanner’s findings and the endpoint action that closes them — where most estates lose the thread.
Fixlets, tasks, analyses and relevance written for your estate — and documented, which is the part usually missing.
Aevis capabilities
Engage us for a focused intervention or an end-to-end programme. We work within your licensing, change-control and data-protection constraints.
What the deployment actually covers, what it misses, and how far the reported figure is from the defensible one.
Who decides what is in scope, who approves an exception and when it expires, and who is accountable for the number.
New deployments, version upgrades, relay redesign, and migration from a tool that reached less far than it claimed.
Custom fixlets, tasks and baselines written for your estate — and the retirement of the ones that no longer apply.
Remediation that produces a change record rather than an email, and findings that arrive already mapped to an owner.
Running the patch cycle, the exception queue and the reporting, or standing behind a team that does.
AI and automation in endpoint management
BigFix is an automation platform before it is anything else, and the honest description of AI here is narrow. Most of the value is deterministic — relevance, rings and rollback — and the assistive parts are stated below with their limit rather than oversold.
Ranking outstanding findings by exposure, exploitability and business context so the queue is worked in a defensible order.
Drafting relevance and fixlet logic faster, then testing it against a representative sample before it reaches anything.
Surfacing agents that have gone quiet, relays that are degrading and success rates that have moved, for somebody to interpret.
What stays human — without exception
No AI decides what is deployed to an endpoint. Scope, approval, ring progression and the decision to grant or expire an exception are human judgements made under your change control, and remain the accountable decision of the person who made them. Generated content is tested against a representative sample before it reaches production, because a fixlet with wrong relevance is a change applied to the wrong machines.
How value is measured
Entitlement and data
Which AI and analytics capabilities are available depends on the client’s BigFix modules, version and licensing, and on what HCLSoftware ships in that release. Endpoint data is processed for the agreed operational purpose only, under the client’s data-protection terms.
Connected architecture
BigFix sees more of the endpoint than most systems that claim to own it, which makes it tempting to treat as the asset register. That is a decision worth taking deliberately rather than by accident.
The single agent, its relevance evaluation, and the machines that are off the network more than on it.
Root server, relays, WebUI and the bandwidth path to every site, including the ones nobody sized.
Fixlets, baselines, analyses, custom relevance and the exception register that governs all of it.
Service management, CMDB, vulnerability scanners, SIEM and the reporting layer the board sees.
Architecture boundarySupported operating systems, module capability, API availability and integration options depend on the client’s BigFix version and licensing. We validate platform support and entitlement before committing to a design.
Delivery model
The order matters. Reporting a compliance figure before coverage is understood produces a number that has to be withdrawn later, which costs more credibility than the delay would have.
Establish the real estate, current agent coverage, deployment health and how far the reported figure is from a defensible one.
Coverage baseline and gap listSettle scope, exemption policy, expiry, ring model and who is accountable for each decision.
Written policy and ownership modelDeployment or remediation work: relay topology, agent rollout, baselines and the custom content the estate actually needs.
Working deployment with documented contentRun the full cycle on a representative ring, including the rollback path, before anything is applied at scale.
Proven cycle with a tested way backRun the patch cycle, the exception queue and the reporting, with the position reviewed rather than assumed.
Governed operating cycleRetire custom content the platform now covers, close standing exceptions and widen scope where coverage allows.
Reduced custom estate and narrower exception listUse cases
Each of these is a normal starting point rather than a programme. We map the adjacent dependencies so a local fix does not create a hidden failure elsewhere.
A figure was challenged and could not be evidenced per machine. The work is usually to fix the denominator before the numerator.
Discovery finds an estate materially larger than the register. The value is in reconciling the two rather than in the count itself.
A tool that reached less far than claimed, replaced with parallel running until coverage is proven rather than asserted.
The scanner reports and the endpoint team remediates, but nothing reconciles the two, so the same findings recur.
Long-lived and vendor-locked endpoints treated as a documented, owned exposure with compensating controls rather than as a permanent blank.
Undocumented relevance built over years, rationalised against what the platform now does natively.
Engagement shapes
Which one fits is usually a question about where accountability should sit rather than about budget.
Best forA figure you have stopped believing
A bounded assessment of coverage, deployment health and the exception register, ending in a gap list with an owner and a cost against each item.
Best forA new deployment or a tool replacement
Architecture, rollout, content and handover as a defined project with acceptance criteria, including the documentation that makes it operable afterwards.
Best forNo standing internal capability
Aevis operates the patch cycle, exception queue and reporting to an agreed calendar, with the accountability boundary set out in the service agreement.
Best forA team that should own this
We operate alongside your team and hand over deliberately, with content documented and train-the-trainer where the capability should stay with you.
Designed outcomes
Baselines and targets are agreed per engagement. We do not import a vendor benchmark into your estate and call it a business case.
Managed machines as a share of an independently assembled estate view.
Time from vendor release to ring-complete, by ring and by platform.
Deployments succeeding without manual intervention, and why the rest did not.
Open exceptions, how many are past expiry, and the trend in both.
No provider can guarantee a compliance outcome or immunity from a vulnerability. What is contracted is the operation, the evidence and the improvement practice within an agreed scope; the organisation retains its risk decisions and its regulatory interpretation.
Governance
Endpoint tooling degrades quietly. These are the standing controls that make the degradation visible while it is still small.
The estate view is reconciled against an independent source on a cadence, so the figure is always a share of something agreed.
Every exclusion carries an owner, a justification and an expiry date, and expiry means a review rather than an automatic renewal.
Deployment to production endpoints runs through your change process, with ring progression as the gate rather than a formality.
The record is produced by the deployment as work happens, at machine granularity, so an audit is a query rather than a reconstruction.
Why Aevis
We approach BigFix as a system somebody has to administer after we leave. The work is designed to survive handover, a version upgrade and a change of administrator.
A compliance percentage is only as good as the estate view underneath it. We would rather report a lower, defensible figure than a higher one that gets withdrawn under challenge.
Every hand-written fixlet is regression effort at the next upgrade. The design says what will not be built, and the backlog includes retiring what the platform now covers natively.
The people configuring your rings also carry a pager somewhere. Maintenance windows, rollback paths and the cost of a failed deployment are argued about from experience rather than from a template.
Licences are contracted directly between you and HCLSoftware. We hold no margin in your endpoint count, which is worth checking for in any competing proposal.
Relationship clarityAevis does not claim ownership of HCL BigFix products and this page does not state or imply a certified partnership. Product names and trademarks belong to their respective owners.
Testimonials
Each testimonial is tied to the service it refers to, so service pages can draw the relevant one automatically.
The change we noticed first was not technical. It was that there was finally one person to call, and that person already knew the history of the problem.
They rebuilt the service catalogue around how our teams actually work rather than how the platform was shipped. Adoption stopped being an argument.
We had the security tooling before Aevis arrived. What we did not have was anybody turning what it produced into decisions.
Frequently asked questions
The useful answers depend on your estate and licensing. These are the principles we use before an assessment establishes the exact scope.
This page makes no partnership claim. Aevis provides advisory, deployment, content and operational services around a deployment the client licenses directly from HCLSoftware. Where a formal partner relationship is relevant to a procurement, ask us and we will answer it precisely rather than by implication.
Not necessarily, and the overlap is worth deciding deliberately rather than tolerating. Many estates run BigFix for servers and cross-platform reach alongside Intune for the corporate workplace. What matters is that each machine has exactly one system authoritative for its state, and that the split is documented — two tools patching the same endpoint is a change-control problem waiting to happen.
Because a compliance percentage is a fraction, and the denominator is the part most often wrong. Machines the deployment does not know about are not counted as non-compliant — they are not counted at all. Reporting a figure before that is understood produces a number that has to be withdrawn under challenge, which is more expensive than the delay.
They become a documented, owned exposure with compensating controls and a review date, rather than a silent gap or a permanent exclusion. Segmentation, access restriction and monitoring usually do more for those machines than a patching mandate the business will correctly refuse.
Where the estate genuinely needs them, and documented so the next administrator can change them. We will also argue for writing fewer: every piece of custom relevance is regression effort at the next upgrade, and a good deal of what we are shown duplicates something the platform now does natively.
That is the co-managed shape, and we would rather you asked for it than not. Content is documented as it is written, the operating model is yours, and train-the-trainer is available through the Corporate Training practice. A supplier whose model depends on you not holding this capability is the wrong supplier for it.
HCL BigFix enquiry
Tell us what is reported today, what it is a percentage of, and what happened the last time somebody challenged it. We will be precise about what a review would and would not tell you.