First Recon AI is available as two products, Endpoint Security and the Secure Enterprise AI Workspace. The workspace app can run in the browser or on the desktop. Deployment is determined by the product you select and does not require a separate infrastructure decision. Your First Recon AI team remains available to support you throughout the process.
The product map below shows where both First Recon AI deployables sit within the technology categories already present in your environment. It also shows how a single governed path spans both products.
Fig 11 · The product map: where things run, what you add.Gallery
Fig 12 · Two products, and the ways your people access Secure Enterprise AI Workspace.Gallery
Two entry points, one account
Start on a trial or start direct. Both land in the same tenant, so policy tuning, evidence, and credit carry into the paid account. Trial mechanics, scope, and fit: Trial.
Choose your path
Secure Enterprise AI Workspace
TIME →
Starttrial or direct onboarding
Connect identitySSO through your IdP
Policies livecoverage by region, industry, frameworks
Pilot team works governedreal chats and agent workflows
Tune and expandby department, team, or role
Fig 14a · Deployment path: Secure Enterprise AI Workspace.Gallery
Trial: a limited onboarding into the browser workspace, enough to run real work against your own policy. Direct: full workspace setup including company knowledge connectors. Either path carries the same account into paid.
Endpoint Security
TIME →
Starttrial or direct onboarding
Enroll pilot devicesmacOS and Windows via your MDM
Policies enforcesame coverage, at the endpoint
See what surfacesAI tools you do not own or host
Tune and roll fleet-wideallowlist, block, warn, monitor
Fig 14b · Deployment path: the Endpoint Security.Gallery
Trial enrolls a pilot device group; direct onboarding goes fleet-wide from the start. Visibility includes AI tools the enterprise does not own or host.
Both together
TIME →
Start onceone account, both products
Identity + pilot devicestogether or App first
One policy set liveapplies to workspace and device
Most organizations bring the Secure Enterprise AI Workspace online first and add the Endpoint Security once the workspace is in daily use, but the order is not fixed.
Live on day one
18pre-built detection templates
233detection patterns across them
22industry presets
300+one-click policy templates
Control catalogs ready to enable: SOC 2 Type IIISO 27001GDPRHIPAAPCI-DSSNIST CSFCCPA
Policy coverage mapped to your region, industry, and frameworks, not a blank slate. Full catalogs: Data protection.
The posture ladder
Fig 15 · The posture ladder: enforcement climbs as the rollout widens.Gallery
Horizon
Posture
The moves
Short term
Visibility → first enforcement
Connect IdP · accept day-one coverage · real usage on the governed path
Medium term
Tuned enforcement
Redact-vs-block per team · SIEM and deeper IdP · more teams and device groups
Long term
Full-path governance
Agents under the same policy · advanced controls as the program matures
Plan your rollout
A rollout plan follows your region, industry, existing stack, and the products you deploy. Your First Recon team builds it with you; the contact link below reaches them directly.