Haat × Samsung Knox
Team Brief v1 · Edition 3.1
Product + Operations + Engineering starter

Samsung Knox for Haat Partner +

A short, factual map of how Haat can register Samsung tablets, install Haat Partner +, control releases and updates, operate the fleet, and later automate restaurant activation.

Keep this mental model: KME enrolls the Samsung tablet → Knox Manage manages the tablet and app → Haat Partner + remains Haat's application.

ReleaseCan we control who gets a version?Yes. Assign apps to Pilot / Production groups in Knox Manage.
UpdatesCan apps update without restaurant action?Yes, for managed apps with automatic update policy. High priority is available.
EnrollmentDoes KME registration mean managed?No. Registration/profile assignment comes before successful Knox Manage enrollment.
RecoveryCan we rollback a bad Android build?Not as a normal lower-version downgrade. Normally ship a fixed higher versionCode.
Starting doubtHow do we control a release?Use Knox Manage app assignment and Pilot / Production groups.
Starting doubtHow do we give updates?Publish a newer build and use managed automatic update policy.
Starting doubtWhich dashboard do we operate?Mostly Knox Manage; KME is for enrollment and Knox Admin Portal is the account/service hub.
Documented = Samsung / Google factHaat design = recommended operating choicePilot = must prove on our exact tablet/app
01 · Basics first

Three systems are enough to understand the Haat use case.

Knox Suite contains more products, but these are the pieces that matter for the first restaurant tablet.

KME

Knox Mobile Enrollment

Job: add/approve Samsung devices, assign an enrollment profile, and send them into the chosen management system during setup.

Knox Manage

Daily device + app management

Job: manage enrolled devices, app assignment, update settings, profiles/policies, kiosk, status and device actions.

Managed Google Play

Android app delivery channel

Job: distribute public/private managed apps to Android Enterprise devices and apply managed update behavior.

Haat Partner +●
H+

Register Haat

Israel HQ creates Haat's Samsung Knox business account and opens the Knox Admin Portal.

Account ready
Illustration only — not the real Haat app or Samsung console.
Documented: Samsung describes KME as out-of-box enrollment and Knox Manage as its UEM/device-management solution. Samsung's Knox Suite leaflet separately lists app management, kiosk, OS management, remote support and other capabilities.
02 · Device registration & enrollment

Registered in KME is not the same as managed in Knox Manage.

This distinction matters when Operations asks “is this tablet ready?”

1

Create the Haat Knox organisation

Israel HQ registers Haat with Samsung account for Business / Knox, then uses Knox Admin Portal for services, administrators, licences and Customer ID.

Where to register: SamsungKnox.com → Sign in / business registration.
After this step: Haat has its Knox organisation and can start configuring Knox Manage and KME.
3

Register the tablet in KME and assign the Knox Manage profile

For fleet procurement, a Samsung-approved reseller can upload devices to Haat using Haat's Customer ID. Haat approves the upload and assigns the enrollment profile. For small/manual cases, Samsung also documents QR enrollment.

After this step: an eligible new/factory-reset tablet can enter the configured enrollment flow. It is still not fully managed until enrollment completes.
Pending upload

Reseller uploaded the device, but Haat has not approved it yet.

Registered + profile assigned

KME knows the device and which enrollment profile it should use.

Profile assigned, not yet enrolled

KME can show this state. The restaurant tablet has not completed EMM/UEM enrollment yet.

Enrolled in Knox Manage

Now Haat has normal day-to-day management of the tablet.

Not registered in KME? The tablet does not get KME's reseller/OOBE automatic assignment. That does not make management impossible: Samsung documents QR enrollment for both reseller-uploaded and non-reseller-uploaded devices when configured appropriately.
Official device states: KME device status · OOBE and QR enrollment
03 · Haat Partner + delivery

Add Haat Partner + once the tablet is managed.

There are two relevant paths. Keep them separate because update behavior and operations differ.

Alternative

Knox Manage in-house APK

Upload the APK to Knox Manage, then assign/push it to managed devices. Samsung documents manual upload of newer APK versions for updates.

Managed Google Play answer: yes — on managed devices, Knox Manage can assign an app as Auto-installed and set automatic update behavior. That means Haat Partner + can install and update without restaurant action when the policy and device conditions are satisfied.
Auto-installInstall automatically to assigned groups/devices.
Reinstall if removedKnox Manage exposes an auto-installed mode that reinstalls an assigned app if removed.
App update policyChoose default/Wi-Fi behavior, High priority, or postpone options depending on the management path.
Schedule installKnox Manage can schedule the installation start time for auto-installed apps.
Managed configurationPass configuration fields that the app developer has exposed.
Auto-run optionKnox Manage documents run-after-install / run-after-update options for supported assignments.
04 · Release management

Control releases with groups, not with manual APK sharing.

A simple Haat operating model is Pilot first, Production second.

1 · BuildEngineering creates v3.2 with the same application ID and same signing key, with a higher versionCode.
2 · PublishPublish to Managed Google Play or upload the newer in-house APK.
3 · PilotAssign/update a small Haat pilot group first.
4 · VerifyConfirm installed app version, login, restaurant mapping and a test order.
5 · ProductionExpand assignment/update to production restaurant groups.
What Haat controls: which groups receive the app, installation type, update preference, timing, and whether to move from Pilot to Production. Knox Manage also exposes device/app details so Operations can check assigned apps, installed apps and versions.
Haat design, not a Knox requirement: use Pilot → verify → Production because an ordering app is operationally critical. Knox gives you assignment controls; Haat decides the release gate.
05 · Updates, urgent fixes & rollback

Automatic updates: yes. Guaranteed instant updates: no.

This is the area where wording matters most.

Managed Google Play High priority: Google documents that a high-priority app update is applied as soon as possible and the normal idle/charging/unmetered-network constraints do not apply. However, Google also notes that updates for apps with larger deployments can take up to 24 hours. So this is automatic and user-free, but not guaranteed instant.
NormalRoutine release

Publish → Pilot → verify → Production. Let the configured automatic app update policy handle devices.

UrgentImmediate fix push

Publish a fixed higher version and use High priority for Managed Google Play. For in-house APK, upload the newer APK and reassign/push to target devices.

OfflineTablet has no network

No cloud management system can deliver the new app while the tablet is unreachable. It receives the update after connectivity returns and policy processing continues.

Faulty release / rollback: Android prevents normal downgrade to an APK with a lower versionCode than the installed version. So if v3.2 is faulty, the normal recovery is a forward-fix: take the last-known-good/fixed code, build v3.2.1/v3.3 with a higher versionCode, and push that version. Uninstalling to install an older build is not a normal production rollback because uninstalling removes app data and breaks continuity.
06 · Dashboards & operational controls

For daily operations, most work happens in Knox Manage.

KME and Knox Admin Portal solve different jobs.

Hub

Knox Admin Portal

Account, services, licenses, admins, Customer ID and access to Knox services.

Open it for: organisation/service/admin tasks.
Enrollment

Knox Mobile Enrollment

Register / assign tablets, profiles and enrollment state.

Open it for: a new tablet or enrollment problem.
Daily work

Knox Manage

Devices, apps, releases, policies, kiosk, device/app status and supported actions.

Open it for: Haat Partner + rollout and daily fleet operations.
What Haat can controlApp assignment, auto-install, app update policy, group targeting, profiles and kiosk configuration.
What Haat can observeDevice status, Last seen, installed app version, assigned apps and installation status/details.
Device actionsOn supported fully managed devices: lock, reboot, factory reset/unenroll and other commands documented by Knox Manage.
New tablet?KME / enrollment
New Haat release?Knox Manage → Library > Apps
Did Restaurant A receive version X?Knox Manage → device details → installed / assigned apps
Tablet not checking in?Knox Manage → device status / Last seen, then troubleshoot connectivity
Account, licence or admin issue?Knox Admin Portal
07 · Restaurant activation & real scenarios

Manual login today. Secure auto-activation is a separate future integration.

Knox can carry configuration to the app; Haat still owns restaurant authentication.

TODAY

Existing manual login

Tablet enrolls → Haat Partner + auto-installs → restaurant signs in → verify Business A → test order → Restaurant is ready.

No Haat app change is assumed.
FUTURE

Automatic restaurant activation

Tablet assigned to Business A
↓
Knox Manage sends managed configuration / activation input
↓
Haat Partner + reads the managed configuration
↓
Haat backend validates the device / activation securely
↓
Haat creates the authenticated Business A session
Knox does not create the Haat login session. Knox alone cannot log an arbitrary app in. Requires Haat Partner + and backend work.
Question / incident
What actually happens
Where Haat acts
Tablet registered but app missing
Registration/profile assignment alone is not enough. Confirm Knox Manage enrollment, app assignment and connectivity.
KME status → Knox Manage device/app state
Tablet not registered in KME
No reseller/OOBE KME assignment. QR/manual supported enrollment paths may still be used depending on setup.
KME / enrollment process
New version is ready
Publish/upload → Pilot → verify version/login/test order → Production.
Knox Manage + app distribution channel
Faulty release reached restaurants
Stop further rollout if possible, create a fixed build with higher versionCode, then push it with appropriate urgency.
Engineering + Knox Manage / Managed Google Play
Restaurant does nothing
With auto-install and automatic update policy, app install/update does not require restaurant action. Delivery still needs the managed device to be reachable.
Knox Manage assignment/update policy
Wrong restaurant appears
That is primarily Haat identity/session/mapping logic, not proof that Knox enrollment failed.
Haat Partner + / backend
Tablet is lost
Revoke Haat access/session as needed and use the supported Knox Manage device response such as lock / wipe according to policy.
Haat backend + Knox Manage
Team model: Israel HQ / Operations owns the production Knox organisation, device procurement and restaurant fleet. The India mobile team can have admin/test access in the same Knox environment for releases, testing and technical troubleshooting.