OWL + KESTREL SUPPORT TOOLS

HATCH · EARLY ALPHA

A small way
to get a hand.

Give authorized O+K operators access to this computer.
You decide when the door is open.

Download preview · remote support pending

This build lets you open and inspect the local controls. Enrollment and remote commands are not activated on this endpoint yet. Allow requests remain refused while that integration is pending.

Hatch for Mac

Apple silicon · macOS 11 or later
Signed, notarized, and bundled with its runtime.

Download Hatch

Download. Open. Inspect.

Unzip the download, move Hatch to Applications, and open it. Hatch starts paused. The local controls are available for preview. Once the support service is activated, a separate Allow O+K access action will be required to enroll this computer.

The menu-bar controls let you pause access or pause and quit. No administrator installation or automatic remote enrollment occurs in this preview.

What you are allowing

Authorized O+K operators may inspect this host, run commands, and transfer files with your current user's permissions. Pause blocks new Hatch work and cancels tracked running work. It does not undo earlier changes, remove installed software, or disable independent access tools.

This first alpha does not install a privileged service or start automatically at login. Windows and Linux release acceptance, unattended mode, self-update and full system-service management are still in development.

For operators

Use the bundled command-line client with an owner-private, Hatch-scoped O+K operator credential. The command interfaces are implemented and fixture-tested; the hosted command service remains disabled pending canonical credential activation.

hatch nodes
hatch send NODE host.inspect input.json --id REQUEST_ID
hatch result REQUEST_ID

Input for host.inspect is an empty JSON object. The operator credential must carry both the correct Hatch audience/scope and current O+K administration authority. Possessing this download grants no operator access.