Guides.

The everyday jobs, screen by screen on iPhone. Then the longer ones you do sitting down. Written from what the product does today, not from what it will do.

Step by step, on iPhone

Start at the top if the app is new to you; they run in order and each one hands off to the next. Every step names the control it wants, spelled the way the screen spells it.

  1. Find your way aroundFive tabs, and each one answers a different question. Two minutes here saves you hunting for the rest.2 minutes6 steps
  2. Add an assetFour ways in, one short form, and the next tag number when you save.A minute per machine7 steps
  3. Find an asset in the registerOne search bar, a scope when you need it, and filters that answer the questions you usually have.Seconds7 steps
  4. Read a recordOne card of bands, in the register's own order, with a search field for the fields and a jump bar that stays with you.A minute8 steps
  5. Edit an assetNothing is written until you say so. Worth knowing what editing costs, and when not to do it.A minute8 steps
  6. Add a custom field and fill it inRecord something the register has no place for, like a host name or an IMEI, by hand or from a template, and keep it off the cloud if you want.A minute10 steps
  7. Mark a machine lost or stolenThe status says it's missing. Taking it off book value is a separate call, and you can undo it.A minute8 steps
  8. Verify an assetThe shortest job in the app, and the one an audit is actually about. One tap per machine, and you never leave the camera.Seconds per machine6 steps
  9. Sweep a rackOne camera that stays open while you pan across a shelf. It records what was seen, and it's careful not to call that verified.Minutes for a room6 steps
  10. Tag a machine with NFCWrite a chip two taps from the record, and tapping the phone on it opens that record again. Beats reading a worn asset number off the back of a rack.Seconds per machine6 steps

The phone screens in these guides are captures of Starkive Manifest 1.2 for iPhone, the version on the App Store, taken on the Hill Valley demo register with no Mac and no account. Every control named in a step is legible in one of them, or belongs to a guide that says it has no picture.

Where these guides stop

Adding and editing run end to end now. Both used to stop at a button, because the form and the editing state were screens nobody here had. They were captured off the app and those two guides were rewritten around them.

What has no picture is the camera: Scan and Sweep both need a lens, and a simulator has none. Those two guides quote the shipping source rather than describing a screen from imagination, and they say so where they stop. Tagging is the third, because NFC needs a radio the simulator also lacks. A guide that invents a screen does not just look bad, it makes you fail at the task and then distrust the register.

The longer jobs

Read at a desk rather than followed with a phone in your hand. These are decisions and rounds, not taps.

Your first hour

About 40 minutes

Name the organisation and answer the regulated-data questions, which is what derives your frameworks rather than you picking them off a list. Then bring assets in before anything else: an empty register teaches you nothing about whether the product fits. Import a spreadsheet or connect one source, and leave the rest for later.

  1. Answer the setup questions honestly, including the ones about regulated data. They decide which of the 12 standards apply to you.
  2. Choose where the register lives. This governs every sync afterwards and is not easy to change later.
  3. Import a spreadsheet, or connect Intune, Entra, Jamf Pro or Okta.
  4. Print QR labels for anything you will be verifying by hand.

Bringing in a spreadsheet you already have

About 15 minutes

You do not have to reshape your file first. Columns are matched by looking at the values, not just the headers, so a column called “Who” full of names is recognised as an assignee. Columns that are yours alone become typed custom fields rather than being dropped. Exports from ServiceNow, Snipe-IT, Freshservice, Jira Service Management Assets, Asset Panda and Intune map as they are. Repeated vendors and contracts in the sheet become one record each, with the assets linked to them.

  1. Point it at the file. Nothing is written until you confirm the mapping.
  2. Check the columns it could not place; those become custom fields if you want them.
  3. Confirm. The import is logged before it writes, and can be undone in the same session.

Running a verification round

Depends on the estate

Verification is the thing auditors actually test: not that a spreadsheet exists, but that somebody laid eyes on the machine. This is what the phone is for, and the step-by-step version of the phone half is above.

  1. On the Mac, or on the phone with the attention filter, pull up what hasn't been verified inside your policy window.
  2. Walk the floor with the phone. Read the tag, cross-check the serial by barcode or OCR, confirm you have seen it.
  3. Reassign custody on the spot if the machine has moved. The change records whether or not the Mac is awake.
  4. Back at the desk, the round shows in the trail with who acted and when.

Producing an audit evidence pack

Minutes

The pack is assembled from what the register already holds, so the work happens before the auditor arrives rather than during. Your inventory is mapped to 72 controls across 12 standards, and 16 evidence reports are kept ready.

  1. Open Compliance and check the coverage for the framework being tested. Expand a report to see exactly what it is missing, and fix each gap from its Fill in or Open button.
  2. Generate the Audit Evidence Pack: full inventory, audit trail, sanitization certificates and worklists.
  3. Every artifact in the pack is mapped to the control it answers, so you are handing over an index rather than a folder.

Retiring a machine so it stands up later

A few minutes per machine

Disposal is where most registers quietly fail an audit, because the evidence chain is the thing being tested and it is usually the thing nobody kept. Manifest records it as a chain rather than a status change.

  1. Record the sanitization category against NIST SP 800-88: clear, purge or destroy.
  2. Name the witness and the authoriser, and attach the wipe certificate.
  3. The record stays in the register. A machine that was disposed of still happened, and its record is the artifact an auditor asks for.

Not covered here, on purpose

  • Reconciling software licences against installs. Licences themselves have a screen: seats purchased against seats assigned, renewals, cost. What has no guide is discovery, because there is no discovery: nothing scans a machine for what is installed on it.
  • Anything needing the cloud track while you are on the local one. The workspace decision governs what syncs, and a guide that ignored it would be describing a different install.

Something missing? Write to support@depaloconsultingllc.com and say which step you got stuck on; that is how this page grows.

For the reference behind these, area by area, see the documentation. Also useful: how it works and what it costs.