Fleet Deployment: SignPath signing + Smart App Control section SAC blocks unsigned/low-reputation binaries with no allow rule or file-hash exception — the previous "file-hash rule permits an unsigned binary" advice does not apply to it. Rework the section as a SmartScreen / WDAC+AppLocker / Smart App Control table and describe the SignPath Foundation signing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx
Document the diagnostic log (Configuration + Fleet Deployment) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx
Document battery inventory + health (not graded) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx
Fleet Deployment: note the Tiny Tool Town listing as a provenance reference Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx
Fleet Deployment / Methodology: note the auto-sweep of stale scratch files Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx
Add a Fleet Deployment page Running loadbearer unattended across a managed Windows estate (PDQ / Intune / GPO): the recommended `run --no-gpu --plain --target-dir --output` command line and why each flag, exit codes, the scratch-file cleanup step, the unsigned-binary / WDAC hash-rule situation, what not to put in a package (net-server, soak, --net-target), and collecting the result JSON into a corpus for compare / baseline / score. Linked from Home and the sidebar. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SNrEbxEc3Q8FWSU9T5PdCx