Managed device guide

Building apps for dedicated business devices

Treat the application and device fleet as one operated business system. Define ownership, enrolment, identity, updates, recovery and retirement before scaling beyond a pilot.

The short answer

An app for dedicated business devices must be designed with the fleet that runs it. The solution needs compatible hardware, managed enrolment, device and user identity, controlled application distribution, configuration, offline and peripheral behaviour, monitoring, update rings, recovery and secure retirement.

Start with one representative workflow and device. Prove provisioning, the critical user outcome and recovery from power, network, application and hardware failure before committing to a larger estate.

01

Choose the device model from the operating context

ModelTypical contextDesign focus
Single-purpose kioskUnattended or customer-facing stationLockdown, session reset, physical recovery and readiness
Shared shift deviceWarehouse, logistics, retail or field teamFast sign-in, handover, pending work and accountability
Assigned work deviceOne employee over a longer periodUser policy, protected data, support and replacement
Specialised terminalScanner, controller, rugged or vehicle-mounted unitPeripheral protocol, environmental limits and vendor lifecycle

Write down who owns the device, who may use it, where it operates, which business outcome it serves and how long it can remain unavailable before the workflow is harmed.

02

Select hardware and platform as a supported combination

  • representative operating temperature, dust, moisture, impact and mounting;
  • battery, fixed power, charging cycles and safe shutdown;
  • screen, camera, scanner, audio and accessibility needs;
  • Wi-Fi, cellular, Ethernet, Bluetooth and USB requirements;
  • operating-system support window and vendor update commitment;
  • device-management compatibility and enrolment method;
  • regional supply, spares, repair and replacement lead times; and
  • SDK, driver and peripheral support for the intended application stack.

Android offers fully managed dedicated-device capabilities and lock task mode. Apple supports supervised device deployments through device management, including Automated Device Enrollment and an App Lock payload for Single App Mode. The correct platform depends on the exact device, workflow and ownership constraints.

03

Design the fleet lifecycle before the first rollout

Acquire and identifyEnrol and configureAssign and operateUpdate and supportWipe and retire
  1. Assign a stable asset and device identity.
  2. Enrol through the intended zero-touch or controlled setup path.
  3. Apply policy, certificates, network settings and application configuration.
  4. Verify the ready state before assignment or installation.
  5. Monitor supported versions, configuration drift and application health.
  6. Roll changes through test, pilot and production rings.
  7. Revoke access, remove business data and record final disposition.

04

Separate device trust from user authority

A managed device can be trusted as an organisational asset without granting every user access to every record or action. Use the device identity for enrolment, configuration and service attestation where appropriate. Use a person, role or shift identity for business authorisation.

Device

Managed asset

Policy, configuration, certificates, inventory and lifecycle state.

User

Business actor

Role, permitted records, actions and accountable audit events.

Session

Bounded use

Start, inactivity, handover, sign-out and temporary local data.

Service

Backend trust

Scoped machine access without embedding broad administrator credentials.

05

Design the application for interruption and shared responsibility

  • return to a known ready state after restart or update;
  • keep critical state durable outside the screen lifecycle;
  • show peripheral, network and server readiness without technical jargon;
  • prevent a second user from seeing the previous session's temporary data;
  • make pending and failed work inspectable during handover;
  • support safe configuration change without rebuilding the application;
  • capture privacy-conscious diagnostics tied to device and operation IDs; and
  • provide an authorised support mode that cannot become a general escape route.

For a one-purpose Android station, see the Android kiosk solution. For weak networks, use the unreliable-connectivity design guide.

06

Monitor readiness and business outcomes separately

Operational viewUseful evidence
FleetEnrolment, assigned location, policy, version, last contact and retirement state
ApplicationRelease, startup, crash, configuration and critical journey health
ConnectivityTransport, broker or API reachability, delivery delay and failed retries
PeripheralConnection, firmware, command state and recoverable fault
BusinessCompleted tasks, exceptions, pending age and verified outcomes

A device can be online while the application is unusable, and the application can be running while the business action fails downstream. Preserve the identifiers needed to follow one journey across those layers.

07

Prepare a dedicated-device brief

Record the device model, environment, user and sharing model, required peripherals, network options, management platform, enrolment path, identity, application distribution, configuration ownership, offline rules, data retained locally, update rings, monitoring, support access, spare strategy, remote actions and retirement process.

Prototype the highest-risk hardware or management dependency before fleet procurement. Continue with the hardware and IoT integration guide when the device controls or reads external equipment.

Sources

Primary references

Questions

Frequently asked questions

What is a dedicated business device?

A dedicated business device is a company-owned phone, tablet, kiosk or specialised terminal configured for a defined employee or customer purpose and managed through an organisational device lifecycle.

Should a dedicated device run one app or several apps?

Use one app when the device serves a narrow unattended task. Allow a controlled set when workers need several approved tools. The workflow and support model should decide, not a preference for stronger lockdown.

Do dedicated devices need mobile device management?

A production fleet normally needs a management path for enrolment, policy, application distribution, configuration, updates, inventory, remote actions and retirement. Choose a platform that fits the ownership model and device estate.

Can different employees share one dedicated device?

Yes, but define shift identity, local data separation, sign-out, pending work, handover and accountability. Device identity and employee identity should remain distinct.

How should a business choose dedicated hardware?

Choose from the task, environment, peripherals, operating-system support, ruggedness, power, connectivity, supply continuity, management compatibility and replacement path. Pilot the exact hardware before fleet purchase.

Plan the device fleet

Bring the work environment, user model, device estate, peripherals and operational owner.

LCR can define the managed application boundary and prototype the first complete device journey.