Skip to main content

Application Installation Report - Organization and Global KB

Overview​

This automation reports on where a given application is installed across the tenant. For each organization it counts the devices carrying the named application and publishes a device detail table to an organization Knowledge Base article. Optionally, it also publishes a tenant-wide summary table to a global Knowledge Base article.

Inventory is not collected from the endpoint the script runs on. The script calls the NinjaOne Public API and works from the software inventory NinjaOne has already gathered, authenticating with the OAuth 2.0 client credentials grant. The credential comes from two secure custom fields — cPVAL Ninja API Client ID and cPVAL Ninja API Client Secret — populated once during setup and read at runtime, so no credential is passed in as a script parameter.

Because the report is assembled centrally, run this on a single scheduled device rather than deploying it across the fleet.

⚠️ Prerequisite: Both credential custom fields must be populated before the first run, from an API application configured as described in API Application Configuration. The script exits without producing a report if it cannot obtain an access token.

API Application Configuration​

The credential this automation uses comes from an API application registered in NinjaOne. Create it once, before the first run, under Administration → Apps → API → Client App IDs → Add.

Image5

SettingValueNotes
Application platformAPI Services (machine-to-machine)Required. Pre-fills the dialog for unattended access with no user sign-in.
NameApplication Installation ReportAny name works. Naming it after the automation makes the credential easy to identify and revoke later.
Redirect URIshttp://localhost:8080/Not used by the client credentials flow, but the field must contain a value.
ScopesMonitoring, ManagementMonitoring reads organizations, devices, and software inventory. Management writes the Knowledge Base articles. Leave Control unchecked — the automation never takes remote action on a device.
Allowed grant typesClient credentialsLeave Authorization code and Refresh token unchecked. Client credentials is the only flow the automation uses.

On Add, NinjaOne issues a Client ID and a Client Secret. Copy both into their custom fields straight away:

⚠️ The Client Secret is shown only once. If the dialog is closed before it is copied, the secret cannot be retrieved — a new one must be generated, which immediately invalidates the old one. Update the custom field at the same time, or the automation will fail to obtain an access token on its next run.

💡 Note: Granting only Monitoring and Management keeps the credential to the minimum this automation needs. If the same API application is later reused by other automations, review whether their requirements change the scopes above.

Sample Run​

Example 1​

Runs with Use Wildcard and Global Level Report both enabled.

Google Chrome is matched as a partial name, so entries such as Google Chrome and Google Chrome Beta are all counted. Every organization receives a KB article named Google Chrome - OrgName - TimeStamp in its Reports folder, listing the devices that carry a match. A single global article, Google Chrome - TimeStamp, is also written to the global Reports folder with the per-organization counts side by side.

Image1

Example 2​

Runs with Use Wildcard and Global Level Report both disabled.

Google Chrome is matched exactly, so variants like Google Chrome Beta are excluded. Organization articles are still written as above, but no global article is produced — useful when the report is for individual client review rather than an internal tenant-wide rollup.

Image2

Dependencies​

Parameters​

NameCalculated NameExampleAccepted ValuesRequiredDefaultTypeDescription
Instance URLinstanceurlus2.ninjarmm.comAny valid NinjaOne instance hostFalseus2.ninjarmm.comstring/textHost name of the NinjaOne instance the API calls are directed at. Set this to match the region your tenant is hosted in.
Application NameapplicationnameGoogle Chrome--True--string/textName of the application to report on, as it appears in NinjaOne software inventory. Matched exactly unless Use Wildcard is enabled.
Use Wildcardusewildcard--True/FalseFalseFalseCheckboxMatches any application name containing the value of Application Name rather than requiring an exact match. Enable to capture variants such as editions, channels, and version-suffixed names.
Organization KB Article NameorganizationkbarticlenameGoogle Chrome - OrgName - TimeStamp--True--string/textName of the KB article written for each organization. Supports the OrgName and TimeStamp substitution tokens.
Organization KB Folder NameorganizationkbfoldernameReports--FalseReportsstring/textKnowledge Base folder the organization article is filed under. Created if it does not exist.
Global Level Reportgloballevelreport--True/FalseFalseFalseCheckboxAlso publishes a tenant-wide summary table to a global KB article. Leave disabled to produce organization articles only.
Global KB Article NameglobalkbarticlenameGoogle Chrome - TimeStamp--False--string/textName of the global summary article. Supports the TimeStamp substitution token. Ignored when Global Level Report is disabled.
Global KB Folder NameglobalkbfoldernameReports--FalseReportsstring/textKnowledge Base folder the global article is filed under. Ignored when Global Level Report is disabled.

Article Name Substitution Tokens​

Write these as plain words in either article name field. Each is replaced with its live value when the article is created.

TokenReplaced WithExample
OrgNameName of the organization the article belongs toContoso Ltd
TimeStampDate and time the report was generated2026-09-16 14:30:30

💡 Note: OrgName only resolves on the organization article. A global article covers every organization, so the token has no single value there.

Custom Fields​

Field NameTypeMandatoryScopeDescription
cPVAL Ninja API Client IDSecureYesSystemClient ID of the client-credentials API application used to authenticate against the NinjaOne Public API. Read at runtime.
cPVAL Ninja API Client SecretSecureYesSystemClient Secret paired with the Client ID above. Read at runtime; never passed as a script parameter.

Automation Setup/Import​

Automation Configuration

Sample Output​

Organization Knowledge Base article:

Image3

Global Knowledge Base article:

Image4

Output​

  • Activity Details: Logs the authentication result, the organizations and devices processed, the match count per organization, and the Knowledge Base articles written or updated.
  • Knowledge Base: Writes a device detail article per organization, and a tenant-wide summary article when Global Level Report is enabled.

Changelog​

2026-09-16​

  • Initial version of the document