# Devices and revoking access

**Diagnostics** lists every machine enrolled in your organization: who it belongs to,
when it registered, and when the Gateway last saw it.

## Revoking a device

**Revoke access** on a row kills that machine's gateway tokens. The AI tools on it lose
access within seconds — no need to reach the laptop, and it works whether or not the
machine is online.

Use it for a lost or stolen laptop, or a machine that shouldn't have been enrolled.
For a person who has left, use **Offboard** on Users & Teams instead — it covers every
device plus their passkeys in one action.

Revoking is reversible: the same row offers **Restore access** afterwards.

## Device identity

Each machine holds a hardware-backed key in the OS keychain (Keychain on macOS, Credential
Manager on Windows). The private key never leaves the device, and it is what ties a
request in **Activity** to a person and a machine rather than to a shared token.

<!-- shot:diagnostics-devices -->
![Diagnostics — enrolled machines, when each was last seen, and per-device revocation.](https://docs.sentilai.com/uploads/images/gallery/2026-08/hcIdiagnostics-devices.png)
*Diagnostics — enrolled machines, when each was last seen, and per-device revocation.*