macOS Agent
A lightweight agent that checks a Mac's security posture every hour: disk encryption, Gatekeeper, firewall, and more. Only pass/fail results leave the device, scored in your Monitoring Hub as Healthy, At Risk, or Critical.
Posture checks on the device
The agent evaluates a baseline security-posture pack locally (osquery-based) about once an hour and posts only the results — no file contents or browsing data leave the machine.
Scoped device key
Runs on a Device Monitor key that can only submit device posture scans — it cannot run other tools or read any account data. Revoke the key and the agent stops.
Central visibility
Every scan appears in the Monitoring Hub with a Healthy / At Risk / Critical verdict and a full device report — filter by the Device monitor type to see your fleet.
What it checks today
The current baseline posture pack for macOS. A failed check's severity drives the report verdict: any high or critical failure marks the device Critical; lower-severity failures mark it At Risk; all passing marks it Healthy.Info checks are inventories and facts rather than pass/fail controls — they are reported for context and never count as failures.
- Disk encryption (FileVault) enabledcritical
- System Integrity Protection enabledhigh
- Gatekeeper app assessment enabledhigh
- Remote access and sharing services disabledhigh
- Automatic login disabledhigh
- Known EDR/AV agent runninghigh
- Firewall enabledmedium
- Automatic software update checks not disabledmedium
- Third-party root certificates in system trust storemedium
- Unsigned or ad-hoc-signed launch daemons/agentsmedium
- Guest login disabledmedium
- Firewall stealth mode enabledlow
- Third-party kernel extensions loadedlow
- Time Machine backup destination configuredinfo
- Time Machine backup completed within 7 daysinfo
- macOS software updates pendinginfo
- Device managed by MDMinfo
- Local administrator accounts (inventory)info
- Third-party launch daemons/agents (inventory)info
- Remote-access and tunneling tools installed (inventory)info
Set up in four steps
- 1
Create a Device Monitor key
In the Monitoring Hub, create a new monitor with the type Device Monitor and set its seat assignment to the seated member who uses this Mac. Copy the key when it's shown — it appears only once.
- 2
Download the installer
Use the download button above to get the signed and notarized .pkg installer. You can verify the download against the SHA-256 checksum shown next to the button.
- 3
Install and enroll with the key
Run the installer on the Mac, then enroll the agent from Terminal. It prompts for your macOS password (for sudo) and then the device key from step 1:
$ sudo bldeviceagentctl enroll Password: Device key (apk_bls_...):
Paste the key at the prompt (input is hidden). The key is the agent's only credential and is used solely to submit posture reports.
- 4
Watch the reports come in
The agent scans about once an hour. Each report shows up in the Monitoring Hub under the Device monitor type, with the hostname as the target and a click-through to the full device posture report.
Seats and billing
Device monitoring is seat-only. Assign the monitor to a seated member of your organization. See pricing.