"Everything on the network is visible. Almost nothing on the network is yours to manage."
The set trap
Your private network hands you a tidy list of devices, and the tempting shortcut is to call that list the fleet. It isn't. The set of things you can see is much larger than the set of things you manage, and quietly treating them as equal is how a control plane starts reaching for machines that were never its business.
What else is on the wire
Alongside the managed Macs sit a NAS, a couple of phones, a tablet, maybe a family member's laptop. Every one of them is reachable. None of them being reachable makes them fleet members. Reachable is a fact about the network; managed is a decision about authority.
Classification, not enrollment
So discovery doesn't enroll — it classifies. Each device it finds gets an explicit label: managed_mac, candidate_mac, auxiliary_device (the NAS), mom_device, unknown, or ignored. A candidate is a proposal, not a member. Only an explicit enroll operation — never the mere fact of answering a probe — grants management authority.
Some doors are locked by default
The strongest form of the rule: a family member's Mac is excluded by default and cannot enter through the generic Add-Mac flow at all. Bringing it under management would require a deliberate, operation-specific authorization — a door you unlock on purpose. That exclusion isn't a missing feature; it's the boundary working exactly as designed.