WORKSTATION AGENT
Workstation Agent — Agent Lifecycle
6 of 12Understand how the Agent starts, runs, recovers, updates and retires safely on the workstation.
ResilientSelf-HealingAuto UpdateObservableSecure by DesignManaged
Agent lifecycle overview
1
Install
Agent installed on workstation.
2
Register
Machine registered in Mediloop Portal.
3
Trust Established
Identity validated and trusted.
4
Online
Healthy and ready to run connectors.
5
Degraded / Offline
Local operation continues safely.
6
Updating
Agent automates recovery and synchronization.
The Agent is designed to be resilient, self-healing and secure at every stage.
Agent state machine
Installed
Registered
Trusted
Updating
Online
Degraded / Offline
Recovering
Retired
Startup & auto-launch
Service starts with OS
Auto-login not required
Agent tray icon starts with session
Connects to Mediloop Cloud
Connectors load on demand
Service states
StoppedService not running
StartingInitializing
RunningHealthy
DegradedPartial functionality
OfflineNo connectivity
StoppingGraceful shutdown
Heartbeat & health checks
Periodic heartbeat to cloud
Validate connectivity, disk, memory and access
Auto-restart on failure
Health visible in Portal and local UI
Optional alerting via webhooks
Network loss & recovery
Continue permitted local operations
Queue events and commands
Reconnect with exponential backoff
Sync state after reconnection
No data is lost; actions are eventually delivered and acknowledged.
Sleep / wake & user switch
Handles suspend and resume
Revalidates connections and certificates
Supports user switching
Reapplies least-privilege context
Resumes sessions when safe
Session lifecycle
Session created on Mediloop sign-in
Token issued to Agent
Connectors open as requested
Session ends on logout/timeout
Resources released securely
Connector management
Connectors loaded on demand
Multiple connectors run simultaneously
Isolation between connectors
Idle connectors are paused
One connector failure does not affect others
Update management
Automatic update checks
Validate signed package
Stage download in background
Automatic rollback on failure
Release notes before installation
Certificate & key management
Identity certificate auto-renewed
Rotation without service interruption
Old certificates kept until safe to remove
Certificate lifecycle is managed by Mediloop PKI.
De-registration & uninstall
Deregister from Portal
Revoke certificates and tokens
Stop service and close connections
Remove local data and cache
Optionally wipe connector data
Complete uninstall
The Agent never stores patient data locally unless explicitly required by a connector. Any persisted data is encrypted at rest and in transit.