Machines and robots

Add machines and get their one-time machine key, assign them to workspaces, manage Robots and their settings, and create the robot accounts unattended jobs run as.

Three things work together to run a job: A machine is the Orchestrator's record of a Windows host. You create it, and it gets a one-time machine key that the Robot on that host uses to enrol. A robot is the VeloPhex Robot service running on an enrolled machine. It reports its version, runtimes (for example Workflow and Python) and a heartbeat. A robot account is the Windows user an unattended job runs as. It lives under Manage access and is assigned to workspaces. Machines have a Mode: Mode Use it for Robot (service) Production execution. Jobs run as a robot account. Development Testing and debugging. Jobs a person starts by hand can run in the session of whoever is signed in at the machine, if the Robot allows it. Triggers always use a robot account. Personal Created automatically when someone signs in to the Assistant on a machine nobody enrolled. It runs only its owner's jobs. See Use the VeloPhex Assistant. Add a machine# You need permission to manage machines (machines.edit), for example the Administrator role. In the sidebar, switch to Tenant and select Machines. Select New machine. Enter a Name, such as FIN-BOT-03. Choose the Mode: Robot (service) — production execution or Development — testing and debugging. Select Create machine. For a Robot (service) machine, the Machine created page shows the Machine key (it starts with vpx_ek_) and a ready-made Enrol the Robot command. Copy the key now: it is shown once and works once. Then select Done. Treat the machine key like a passwordAnyone who has an unused key can connect a machine to your tenant. Do not paste it into tickets, chats or documents. If it may have leaked, regenerate it (below); the old key stops working. Enrol the Robot on the Windows host with the key, from the Assistant or the command line. See Enrol a Robot. Assign the machine to the workspaces whose jobs it should run. See Assign machines to a workspace. Development machinesThe web app shows a machine key only for Robot (service) machines. To enrol a Development machine, issue a key for it with the API: POST /api/v1/tenants/{tenantId}/machines/{machineId}/enrollment-keys. Check the fleet# Tenant ▸ Machines lists every machine with its Mode, Status (Connected or Disconnected), Robot Version, Runtimes, number of Robots and Last seen. The summary line shows how many machines are online and offline and how many robots are busy, and warns about machines that have no robot yet. Select Personal to list personal machines instead. A robot that has not sent a heartbeat for 90 seconds (the default) is shown as offline. The list updates live. Change a machine's settings# Go to Tenant ▸ Machines and select the machine. It opens on the Overview tab. Under Settings, change the Name, Max concurrent jobs (1 to 64), Description, or Bind to a single host, then select Save changes. Under Robot settings, override the tenant's Robot defaults for this machine (log level, RDP sessions, screen resolution, colour depth, heartbeat, maximum concurrent jobs). Leave a field empty to inherit the tenant default. See Robots settings. Bind to a single host ties the machine to the first host that enrols with its key. Another host cannot then use a key for this machine. After a hardware replacement or reimage, turn the binding off before you enrol the new host. Regenerate the machine key# Open the machine (Tenant ▸ Machines ▸ the machine) on the Overview tab. In the Enrolment card, select Regenerate key and confirm. Copy the New machine key. It is shown once. Robots already enrolled keep working. Enrol a robot in the same card shows the enrol command again. See a machine's robots and health# The Robots tab lists the robot on the machine with its status, runtimes, last heartbeat and current job. The Health tab shows status, version, sessions, current jobs, recent failures and support bundles, with these actions: Action What it does Drain Stops new work from reaching the machine. Turn on Stop running jobs to end the running ones too. Resume undoes it. Collect diagnostics Asks the Robot for a support bundle, which you can download from the same tab. Revoke Its robots stop at once and can only return with a new machine key. Archive Revokes and hides the machine. Its job history stays. To delete a machine, select Delete machine at the top of its page. Robots using its key no longer connect, and this cannot be undone. Manage robots# Tenant ▸ Robots lists every robot in the tenant. Filter with All, Online, Offline, Disabled and Revoked, or search by name. To rename a robot: Select ⋮ on its row ▸ Edit. Change the Name and select Save changes. ⋮ ▸ View details shows the robot's machine, runtimes, sessions, the account it runs as, and when it registered. Create a robot account# Unattended jobs never run as the Robot service. They run as a robot account: a Windows user whose password the Orchestrator keeps encrypted and releases to the Robot just before a job starts. Go to Tenant ▸ Manage access ▸ Robot accounts. Select New robot account. Enter a Name (a label, for example svc-finbot03) and the Windows account in Domain\Username (for a local account, MACHINE\user). Enter the Password and Confirm password. Choose the Session: Console, or RDP. Keep One job at a time ticked unless the account may run several jobs at once. Optional: open Advanced to take the password from another Credential store instead of the built-in one, or tick Use an existing credential asset. See Credentials and assets. Select Create robot account. Then assign it to every workspace whose unattended jobs it should run: Tenant ▸ Workspaces ▸ the workspace ▸ Assign ▸ Type Robot account. See Give people, groups and robot accounts access. From a robot account's ⋮ menu you can also: Verify on machine: ask an online machine that serves one of its workspaces to test the Windows sign-in. The result says, for example, Signed in, Wrong user name or password or Account is locked. Change password: store a new password after you change it in Windows. Edit or Delete the account. What the Windows account itself needs (log on locally, a loadable profile, a console session for desktop automation) is described in Attended and unattended Robots. Run jobs as the signed-in user on a Development machine# On a Development machine, a job started by hand (Start job or the API) can run in the session of whoever is signed in at the machine, with no robot account. The Robot must allow it; run this once from an elevated prompt on that machine: PowerShellCopy& "$env:ProgramFiles\VeloPhex\Robot\VeloPhex.Robot.Service.exe" configure --allow-signed-in-user-jobs true Jobs started by triggers always need a robot account. When a job cannot start# Message Cause Fix 409 no_run_as_account No robot account is assigned to the workspace (or a parent workspace), and no Development machine may run the job as its signed-in user. Assign a robot account to the workspace, or allow signed-in user jobs on a Development machine. 409 no_capable_runner No robot serving the workspace has the runtime or capability the package needs. Assign a machine whose Robot has that runtime, or update the Robot. Job stays Pending The machine is offline, drained or busy, or every robot account with One job at a time is busy. Check Machines and the job's details for the reason. More causes: Common issues. Next steps# Enrol a Robot Attended and unattended Robots Jobs

Add a machine

Check the fleet

Change a machine's settings

Regenerate the machine key

See a machine's robots and health

Manage robots

Create a robot account

Run jobs as the signed-in user on a Development machine

When a job cannot start

Next steps