DocsMac agent with Jamf Pro

Prism DLP macOS agent: Jamf Pro rollout

The agent is a small menu-bar app. It checks pastes into desktop AI apps (once allowed, see below), records files copied to USB drives and cloud-sync folders (iCloud Drive, Google Drive, OneDrive, Dropbox, Box), and reports which AI desktop apps (ChatGPT, Claude, Cursor) and AI command-line tools (Claude Code, Codex, Gemini CLI and others) each person uses, and for how long per day. It never collects what anyone typed or what was on screen.

One permission, from each person: paste protection needs Prism DLP turned on in System Settings → Privacy & Security → Device Control and Data Access (called Accessibility before macOS 27). Apple doesn’t let an MDM grant this silently on macOS 27. The agent opens a setup window on first run with an Open Settings button; until it’s allowed, the Mac only reports AI tool use. The Prism console shows each Mac’s state under AI tools → Macs.

Status: the package (PrismDLP-<version>.pkg, from 0.2.0) is signed by Stabilise Ltd (Developer ID, Team ID K4DC35T488) and notarised by Apple. We send it to you directly for now; try it on a test Mac before a wider rollout.

1. Package

Upload PrismDLP-<version>.pkg to Jamf (Settings → Computer management → Packages) and add it to a policy scoped to your Macs. It installs /Applications/Prism DLP.app and a LaunchAgent that starts the agent for every user at login and restarts it if it quits.

2. Settings profile

Computers → Configuration Profiles → New, level Computer Level:

Application & Custom Settings → Upload, preference domain com.stabilise.prism.agent, with this plist (replace SENSOR_KEY):

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>apiUrl</key><string>https://api.prism-dlp.com</string>
  <key>apiKey</key><string>SENSOR_KEY</string>
  <key>email</key><string>$EMAIL</string>
  <key>name</key><string>$FULLNAME</string>
</dict>
</plist>

The agent needs an email to attribute usage. Jamf fills $EMAIL from the user assigned to the Mac (Inventory → User and Location); on a Mac with no assigned user the agent stays idle and shows “not configured” in its menu.

3. Permissions you can grant silently

Add a Privacy Preferences Policy Control payload to the same profile, for bundle ID com.stabilise.prism.agent, identifier type Bundle ID, with this code requirement (the signed app’s own; copy it exactly):

identifier "com.stabilise.prism.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = K4DC35T488

Then allow Removable Volumes (SystemPolicyRemovableVolumes), so the agent can check files copied to USB drives without asking. Paste protection’s permission can’t be granted this way (see above).

4. Keep it on

Add a Managed Login Items payload to the same profile: rule type Team Identifier, value K4DC35T488 (Stabilise Ltd’s Team ID), so users can’t switch the agent off in System Settings → General → Login Items.

5. Check it

On a test Mac, the Prism mark appears in the menu bar and its menu says Prism DLP is on. Use ChatGPT or Claude for a few minutes; within 15 minutes the tool appears under AI tools in the Prism console.

Updated 9 October 2026