COBO is the strictest way to run a company device. The organization owns the hardware, manages every inch of it, and locks it to one thing: work. No personal apps. No personal account. Just the job.
It sits at the far end of the ownership spectrum, opposite BYOD. If BYOD is your employee's phone with a bit of work on it, COBO is the company's phone with nothing but work on it. Here is when that trade makes sense, and when it does not.
What COBO actually means
COBO stands for Corporate-Owned, Business-Only. The company buys the device, enrolls it as fully managed, and restricts it to a defined set of business apps. There is no personal profile, no browsing the app store for fun, often no more than a handful of apps on the screen. The device belongs to a task, not a person.
That is the line that separates it from the other models. COPE (Corporate-Owned, Personally Enabled) is also company-owned, but it carves out a private space for the employee. COBO does not. It is company hardware, company use, full stop.
COBO next to COPE, BYOD and CYOD
Four letters keep getting mixed up, so here is the quick placement. BYOD is the employee's own device. CYOD lets the employee pick from an approved list, then the company manages it. COPE is company-owned with a personal side. COBO is company-owned with no personal side at all.
Ranked by control, COBO is the tightest and BYOD the loosest. If you want the full decision framework, our guide on BYOD vs COPE vs CYOD vs COBO lays out each model side by side, and the COPE breakdown covers the middle ground.
When COBO is the right call
COBO shines when the device serves a function, not an individual. Think of a warehouse scanner, a delivery handheld, a retail checkout tablet, a nurse's shared phone, a kiosk at the entrance. Nobody wants a personal Instagram on the barcode scanner, and nobody should.
It also fits anywhere personal use is a real liability: regulated environments, shared devices that pass between shifts, or fleets where a single distracted tap can cost money or safety. When the job needs the same locked setup on 500 identical units, COBO is the model that keeps them identical.
How COBO works in practice
On Android, COBO maps to the fully managed mode of Android Enterprise, with no work profile and no personal Google account. On Apple, it maps to a supervised device enrolled through Automated Device Enrollment, with restrictions that strip out the App Store and personal iCloud.
From there you lock it down. Dedicated-device or kiosk mode pins the device to one app or a small set. Zero-touch enrollment ships the units already configured, so a box of 200 scanners powers on ready to scan. The user never sees a setup screen, and never needs to.
The trade-offs, honestly
The upside is control. Maximum security, uniform configuration, and a clean privacy story, because there is no personal data on the device to worry about. For compliance teams, that last point removes a whole category of headaches.
The downside is rigidity. COBO gives the user nothing to personalize, which is fine for a scanner and wrong for a sales director. It also means the company foots the hardware bill for every device. And acceptance depends entirely on context: a frontline team expects a locked work tool, while an office worker handed a business-only phone will push back within a day.
The security case for COBO
A business-only device is a smaller target by design. No personal email means no personal phishing. No app store browsing means no sideloaded game quietly asking for contacts. The attack surface shrinks to the apps you chose and nothing else, which is a large part of why regulated industries lean on the model.
Auditors like it too. When a device holds zero personal data, the questions about consent and data separation simply do not arise. You can wipe, inspect and reconfigure a COBO device without stepping on anyone's personal photos, because there are none. That clean line makes compliance reviews faster, and it shortens the argument with works councils in Europe, where personal data on managed devices is a sensitive topic.
COBO across industries
Retail runs on it. Checkout tablets, inventory scanners and click-and-collect handhelds are business-only by nature, and they pass between staff without anyone claiming them. Lock them to the point-of-sale app and the stock app, and a new hire is productive in minutes.
Logistics and field service are the same story with rougher hardware. A delivery driver's rugged handheld needs the routing app, the proof-of-delivery app, and nothing that drains the battery on a break. Healthcare adds a compliance layer: a shared nursing phone under COBO carries the clinical apps and none of the risk that comes with a personal account on a device that touches patient data.
Manufacturing and warehousing round it out, where dedicated terminals sit on the line and never leave the building. In each case the device is furniture with a screen, and COBO keeps it that way.
Rolling out COBO without friction
The rollout makes or breaks adoption. Start by mapping the exact apps each role touches, because COBO forces that clarity: if an app is not on the list, it is not on the device. Build one locked configuration per role instead of a pile of exceptions, and keep it lean.
Then lean on zero-touch. Ordering devices that enroll themselves out of the box turns a 200-unit deployment from a week of manual setup into an afternoon of unboxing. Pilot on a single site first, watch how the locked config holds up against real shift patterns, and only then push it fleet-wide. The teams that struggle with COBO are almost always the ones that skipped the pilot and found a missing app on day two, across every device at once.
How Appaloosa runs COBO fleets
Appaloosa manages business-only devices as fully managed Android and supervised iOS, with dedicated-device lockdown and zero-touch provisioning built in. It is the model behind our frontline and shared device setups, where a device belongs to a shift or a station rather than a name.
If your devices exist to do a job and nothing else, COBO is probably your model. Map the apps each role needs, lock the rest away, and let zero-touch do the rollout. Start with a small pilot on one site, then scale the same config across the fleet.