Ideas for how macOS administration could work, built out far enough to actually run — a scripting library, an on-device AI menu bar companion, a native Jamf Pro console, an on-device AI change manager, an MDM-driven dialog and workflow engine, a Jamf lifecycle simulator, on-device Mac diagnostics, read-only Jamf Pro backups, an AI-agent policy merger, an MDM-managed MCP server for Jira, Confluence and Jamf Pro, a local-first company AI, and a security review for Jamf Pro content. None of them route your data through a server I run. Where an app uses AI, it runs on the Mac first; an external AI service is used only where it adds real value, and only one that your IT team configures and controls through MDM. The patterns they share are written down as Runes.
A concept for a reusable Bash helper library for macOS administrators — core helpers, install helpers for about 150 Mac apps, Jamf extension-attribute helpers and a security audit module, under one naming convention. Public on GitHub, still a work in progress.
A concept for an enterprise macOS menu bar companion — MDM-configurable IT actions, on-device AI, and meeting transcription. AI and transcription run on-device by default; an external IT chatbot only if IT configures one.
A concept for a native macOS console that manages multiple Jamf Pro instances — YAML playbooks for declarative automation, OAuth 2.0 credentials, no backend of mine. Your Jamf consoles, unified.
A concept for running your ITIL change-management process end to end on a local LLM — evaluate a draft change plan against your own policy, fill the gaps through a guided interview, and generate audience-ready communications.
A concept for showing MDM-driven dialogs, forms and reminders to macOS users — DDM-style workflows that keep following up until the goal is reached, triggered by scripts or configuration profiles. No telemetry, no cloud.
A concept for simulating the lifecycle of a Jamf-managed Mac — from PreStage enrollment to decommissioning — on an editable timeline that shows which policy fires when, and why. Reads Jamf Pro live or offline from Gimle backups — read-only either way — with a local AI assistant.
A concept for on-device Mac diagnostics — a rule engine checks memory, CPU, heat, battery, disk, network and MDM health, and a bundled AI model explains the findings in plain words — and answers from your own IT documentation. No telemetry; an external AI server only if IT configures one.
A concept for read-only, deduplicated Jamf Pro backups — devices, profiles, scripts, policies, groups and packages including binaries, in a documented format that Janus and Jarl can read offline, optionally encrypted with your organisation key, with a built-in explorer and PDF reports.
A concept for enforcing one AI-agent policy across teams — MDM profile fragments are merged on the Mac, strictest rule wins, into the managed files that Claude Code, Codex, opencode and Claude Desktop read. A signed vendor catalog, encrypted secrets, and discovery of unmanaged agent tools.
A concept for a local MCP server that MDM controls completely — which connectors (Jira DC, Confluence DC, Jamf Pro), which tools, which servers and credentials, switched at runtime. Connectors come from a signed public catalog, secrets are encrypted with your organisation key, and write tools stay off until allowed.
A concept for a local-first company AI — answers on the Mac's own model whenever it can, and only escalates to your OpenAI-compatible service (Azure OpenAI, OpenAI, or a gateway) when the local model can't handle it, as your policy allows.
A concept for a security review of Jamf Pro content — scripts, extension attributes, policies, profiles and package scripts, read live (read-only) or from Gimle backups. A local AI reviews first, 39 rules verify, and the results come as executive, security and engineer reports.
Several of these tools solve the same problems the same way: policy through MDM when macOS won't merge it, secrets that never sit in a profile in clear text, data shared between tools without sharing code, and a preview before anything changes. Runes writes those ideas down as reusable patterns — problem, solution, consequences and where each is used. Concepts, not code or a standard.
Each policy request is its own small profile; the client merges whatever MDM delivers into one effective configuration.
Mimir, Ratatoskr 🐉Secrets enter profiles only as envelopes sealed to an organisation key, so plaintext never shows in the MDM console.
Mimir, Gimle, Jarl, Janus, Lynceus 🌈MDM pushes the servers a tool connects to, shown read-only next to the user's own — with a switch to hide the latter.
Gimle, Jarl, Lynceus ᚱA JSON schema for every preference domain, so admins fill in a generated form instead of hand-writing plists.
Gimle, Mimir, Ratatoskr 🪣A tool's on-disk output as a documented, versioned contract, so other tools can read it offline without its code.
Gimle, Janus, Jarl, Lynceus 🔮Show what a tool would do — with the same logic as the real run — before it does it.
Gimle, Mimir, Janus, Ratatoskr