Before you can get value from Nexthink, you need to understand how it's built: what runs on each device, what data it collects and how often, where that data goes, and how the cloud platform turns raw telemetry into decisions and actions. This page covers the full architecture end to end.
The Full Picture
Nexthink Infinity is organized into four logical zones: the endpoint layer where the Collector agent runs, the encrypted data transport to the cloud, the Infinity cloud platform where data is processed and acted on, and the integration layer that connects to the rest of your IT environment.
Zone 1: Endpoint Layer
The Collector is the foundation of everything Nexthink does. It is a lightweight agent installed on each managed device that continuously gathers telemetry and enables two-way communication between the endpoint and the Infinity cloud. Without it, there is no data: and without data, there is no DEX program.
The Collector is built around a kernel driver and a set of accompanying user-space modules. The kernel driver gives it privileged access to system-level events, process executions, network connections, file operations,that are not visible to user-space agents. This is what allows Nexthink to capture complete, accurate telemetry rather than approximations. Each module is independent: device performance, network monitoring, user session tracking, software inventory, campaign delivery, and remote action execution all run as separate components managed by a central coordination module.
The Collector runs on Windows (10 and 11), macOS (recent releases), and Linux (Ubuntu, Red Hat Enterprise Linux, and other major distributions). In VDI environments, it supports Microsoft Azure Virtual Desktop, Windows 365, Citrix Virtual Apps and Desktops, and VMware Horizon: with session-awareness so it correctly attributes metrics to individual users in shared environments. The Nexthink Browser Extension extends visibility into web application performance in Chrome, Edge, and Firefox, capturing metrics that the OS-level agent cannot see.
The Collector deploys silently with no visible interface: end users are generally unaware it is present. It distributes through standard enterprise software deployment tools: Microsoft Endpoint Configuration Manager (SCCM), Microsoft Intune, Jamf (for Mac), or any other MDM/UEM platform that can deploy MSI or PKG packages. A central Collector Configuration tool in the Infinity portal controls which modules are active, what data is collected, and how the agent connects to its regional cloud instance. Updates happen automatically from the cloud.
The Collector is designed to be always-on without impacting the devices it monitors: a critical requirement since a monitoring agent that degrades performance would defeat its own purpose. Nexthink engineered the agent with efficiency as a primary constraint, and it consistently runs with negligible CPU and memory overhead. The data collection process uses sampling and local aggregation: rather than streaming every raw data point to the cloud, the Collector samples metrics at 20–30 second intervals and sends aggregated 5-minute or 15-minute summaries, significantly reducing bandwidth consumption.
Zone 2: What Gets Collected
Nexthink distinguishes between two fundamental categories of data: objects (things that exist and rarely change) and events (things that happen at a specific moment in time). Events are further divided into punctual events, discrete occurrences like a crash or login,and sampled events, where dynamic metrics like CPU usage are captured at regular intervals and aggregated.
| Data Category | What It Captures | Frequency / Method | Retention |
|---|---|---|---|
| Device Inventory | Hardware specs, OS version, CPU model, RAM, disk, battery, manufacturer | On change; refreshed at startup | Current state always available |
| Software Inventory | Installed applications, versions, publishers, install dates | On change; full scan at startup | Current state + 30 days history |
| User & Session Data | Login/logoff times, session duration, logon performance, RDP/VDI sessions | Punctual: exact event timestamps | 30 days |
| Device Performance | CPU usage, memory consumption, disk I/O, GPU/NPU load, boot time | Sampled every 20–30s; aggregated to 5-min slices | 30 days operational · 13 months trends |
| Application Performance | Process CPU/memory, crashes, hangs, load times, foreground usage, network traffic | Sampled every 20–30s; aggregated to 15-min slices | 30 days operational · 90 days app module |
| Network Connectivity | Latency (RTT), packet loss, DNS response, connection quality, Wi-Fi signal | Sampled continuously; per-session aggregates | 30 days |
| Web Experience | Page load times, web errors, SaaS app performance (via Browser Extension) | Per page load / per error event | 30 days |
| Crashes & Errors | Application crashes, blue screens, hung processes, web errors | Punctual: captured at event time | 30 days |
| Employee Sentiment | Campaign responses, survey answers, satisfaction ratings, free-text feedback | On response submission | 30 days + per-campaign summary |
| Remote Action Output | Results returned by automated scripts: diagnostics, remediation confirmations | On execution completion | 30 days operational · 13 months summary |
| DEX Score | Composite digital experience score per user and device, broken down by device, application, and connectivity dimensions | Computed daily from the prior 7 days of data | 13 months |
Zone 3: The Infinity Cloud
Nexthink Infinity is a multi-tenant SaaS platform hosted on Amazon Web Services, deployed regionally so that customer data stays within the customer's geographic AWS region. The platform is built on more than 300 microservices running in Amazon EKS, using Apache Kafka for data ingestion and Apache Flink for real-time stream processing. Below are the major functional modules available to IT teams.
Zone 4: AI Layer
The scale of data Nexthink collects has always been its greatest strength, and before AI, its greatest challenge. A large enterprise deployment generates millions of telemetry events per day across tens of thousands of endpoints. Human analysts could never process that volume systematically. They sampled, they reacted to alerts that surfaced, they handled what users reported. The vast majority of signals went unread. AI changes that equation. Machine learning correlates signals across the entire fleet simultaneously, surfaces anomalies no individual analyst would catch, and enables systems to act autonomously before a user is impacted. What was previously a tidal wave of data becomes a strategic asset.
Nexthink describes itself as an AI-native platform: meaning AI is not a feature added to an existing product but a design principle built into the foundation. These four modules represent the current AI capability surface.
Spark is a fully autonomous AI agent that resolves IT issues for employees without creating tickets. It runs in Microsoft Teams or Copilot, reads real-time endpoint telemetry to understand exactly what's wrong on a specific device, and executes IT-approved remediation autonomously: in under two minutes on average. Achieves 77% first-contact resolution, compared to an industry average of roughly 15%. IT teams retain full control: Spark only executes actions that have been explicitly pre-approved through the Infinity workflow system.
Workspace is Nexthink's AI-native environment for IT teams: combining natural language investigations, AI-surfaced insights, and guided actions in one interface. Analysts ask questions in plain English ("Which devices had the most crashes this week?") and Workspace constructs NQL, runs the investigation, and returns results with context. It also surfaces proactive diagnostics automatically, shifting the analyst's role from detection to triage. Nexthink reports a 30% accuracy improvement and 80% reduction in token usage from fine-tuning the AI specifically on the Nexthink data model and NQL syntax. Workspace runs entirely on AWS, keeping data within the customer's regional tenancy.
As enterprises deploy AI productivity tools, Microsoft Copilot, Google Gemini, ChatGPT, and others,AI Drive provides the observability layer to measure whether employees are actually using them, how deeply, and what the experience quality is. This closes a critical gap: most organizations are spending significant money on AI tool licenses but have limited visibility into adoption rates or the correlation between AI tool usage and employee productivity outcomes.
Zone 5: Integrations
Nexthink Infinity is designed to sit at the center of a broader IT environment, both ingesting context from external systems and pushing enriched data back to them. The integration model is bidirectional: Nexthink receives identity and organizational data from Active Directory or HR systems, and sends device telemetry, DEX scores, and remediation results to ITSM platforms, BI tools, and CMDBs.
Amplify is Nexthink's primary ITSM integration product, with ServiceNow as the lead integration. When a service desk agent opens a ticket in ServiceNow, Amplify surfaces a side panel showing the employee's device telemetry, DEX score, recent application crashes, network quality, and any active monitors: without the agent having to leave ServiceNow. Amplify also enables ticket-triggered remote actions and campaigns: when a ticket closes, Nexthink can automatically send a satisfaction campaign to the employee.
Nexthink exposes a RESTful API for custom integrations and supports a growing library of pre-built connectors for Active Directory and Entra ID (for device and user context), Microsoft 365 and Teams (for Spark delivery and application monitoring), HR systems including Workday (for organizational hierarchy and onboarding workflows), and CMDB platforms for asset data correlation. Campaign responses and remote action results are also accessible via API, enabling BI tools and data lakes to incorporate Nexthink data into broader analytics.
Security & Data Governance
Nexthink handles sensitive endpoint and employee data at scale, which makes security architecture a significant consideration for enterprise procurement and deployment. The platform is built with multi-tenant isolation, regional data residency, and a clear data minimization model.
All data in transit between the Collector and the Infinity cloud is encrypted via HTTPS/TLS. Data at rest within the platform is encrypted using AWS-managed encryption. The connection from Collector to cloud uses the customer's regional Infinity instance, so data never transits outside the designated geographic boundary.
Each customer's Nexthink instance is logically isolated within the shared AWS infrastructure. Data from one tenant is never accessible to another, and the microservice architecture enforces strict tenant boundaries at both the data layer and the application layer.
Trend and aggregated data, the long-term storage tier retained for up to 13 months,does not contain personally identifiable information. Operational event data (30-day retention) is associated with device and user identifiers. Nexthink's data model is designed so that the analytics value does not require storing sensitive personal content. Campaign responses are associated with the responding user only to the degree the campaign is configured to capture identity.
Nexthink maintains security and compliance certifications including SOC 2 Type II, ISO 27001, and GDPR compliance for European customers, as well as FedRAMP In Process authorization for U.S. federal customers. Verify current certification status directly with Nexthink for procurement purposes, as certification scope and status can change.
What's Next
With the architecture understood, you're ready to explore the functional areas of the platform in detail. The most impactful capabilities for most organizations to tackle first are Spark (if you have the deployment maturity) and Engage plus Flow (the fastest path to operational ROI from employee feedback and automated remediation).
Statistics and technical details on this page are sourced from Nexthink official documentation, press releases, and independent industry research. View full references →