macOS Managed Deployment
Updated: October 8, 2026
Deploy the FireTail Endpoint Agent to your macOS fleet using your organization's MDM software. The agent is distributed as a .pkg and configured through the root user's com.firetail.agent defaults domain.
You will need a FireTail project token and access to your MDM's package deployment and script management features.
Deploy the package
-
Download the macOS
.pkgusing the download above. -
Verify its SHA-256 checksum against the macOS release details:
shasum -a 256 "<downloaded-file>.pkg" -
Upload the
.pkgto your MDM and assign it to the target devices. Use your MDM's package installation workflow, or run the following installation command with administrator privileges:sudo installer -pkg "./<downloaded-file>.pkg" -target /
Replace <downloaded-file>.pkg with the filename you downloaded, including its version. Installation needs permission to install software and to change the System Certificate Trust Settings so the agent's SSL certificate can be added to the trust store.
Configure the agent
After installation, use an MDM script running as root to write the project token to the com.firetail.agent defaults domain. Set FIRETAIL_PROJECT_TOKEN to your project token before running the command:
defaults write com.firetail.agent project_token "$FIRETAIL_PROJECT_TOKEN"
The configuration must belong to the root user, rather than the signed-in employee. The token prefix selects the FireTail SaaS environment.
You can also configure the proxy port, API port, and debug logging. See the configuration reference for the defaults keys, types, and examples. The macOS agent runs in proxy mode.
Restart the agent after changing its configuration. Run this command as root through your MDM:
launchctl kickstart -k system/com.firetail.agent
Verify the deployment
Check the agent's status on a target device:
launchctl print system/com.firetail.agent | grep state
Review the agent log for any issues:
tail -f -20 /var/log/firetail-agent.log
Interact with a supported AI provider and confirm the activity appears in Employee Logs.