One-time authority certification and registry entry. Per end-point.
Ongoing SecureBoot and TPM drift monitoring.
API, dashboard, compliance reporting.