You can deploy the software on endpoints in incremental phases to reduce the performance impact.
Phase 1 (Pilot phase)
A pilot phase must not include more than 200 endpoints. Create a basic policy to establish a baseline for your enterprise. Perform day to day tasks on these endpoints. Endpoints in security operations are normally a good place to start as any adverse activities are observed. During this time, run the standard cycle of 2 weeks in observe mode and evaluate the total number of policy discovery events to make sure legitimate software has been added to a policy. New events must not exceed more than 2 per day before enabling. TACC events must not exceed more than 200 events per day to make sure minimal performance impact.
Phase 2 (Group 1)
Group 1 must only be deployed when the pilot group is stable. Depending on the target systems, this group must not contain more than 1000 systems if they are low risk endpoints, or 100 systems if assets are considered critical to your environment. You must monitor policy discovery and TACC events daily. Make sure numbers do not exceed 200 events per day and all policy discovery events are reconciled before enabling.
Phase 3 (and beyond)
After deploying group 1 successfully, continue deploying as needed. Further groups must not exceed more than 10,000 as more than 10,000 endpoints in observe mode can cause significant performance degradation to ePO - SaaS.