vibe coded with ❤️
Concept app · v1.3.0 · Notarized

Janus

Simulates the lifecycle of a Jamf-managed Mac — from PreStage enrollment to decommissioning — on an editable timeline. See which policy fires when, which smart group the Mac lands in, which profile follows, and why. Reads a live Jamf Pro org, or Gimle's offline backups.

Concept app. Janus explores whether a Jamf Pro setup can be understood by simulating it instead of testing it on real Macs. The engine is deterministic and documented, but it's a prototype, not a supported product — the live Jamf Pro importer hasn't been run against a real org yet, and the simulation relies on stated assumptions. Treat its timelines as a guide, not a guarantee. It has been tested in a demo environment only, not in production.
Janus timeline for a new engineering MacBook: swimlanes for lifecycle, triggers, policies, inventory, groups, profiles, apps, extension attributes and DDM, with an inspector explaining why the Mac joined the Engineering Ready smart group

Every step, and why it happened

🕰️

Editable Timeline

Swimlanes or a list with a causal graph. Arrows always point from cause to effect, and the inspector shows what changed on the Mac vs. in Jamf, the full “why” chain, and what each step causes.

🔀

What-If Changes

Enable a policy, change its frequency, triggers or scope, edit smart group criteria — the timeline recalculates immediately. Changes stay in the scenario and never reach Jamf.

➕

Insert Events

Check-ins, logins, custom triggers, Self Service clicks, EA edits, app installs, re-enrollment, unmanage, wipe — or mark a step as failed and see what depends on it.

🎯

Honest Confidence

Every step is known, inferred or assumed. Assumptions surface as findings, alongside loops, script EAs nothing explains, and custom triggers nobody listens to.

🧩

Effect Rules

Teach Janus what a package or script does, e.g. “Install Rosetta runs → EA Rosetta Installed = Yes”. Exact heuristic matches are auto-confirmed; the rest are pre-sorted for bulk review.

🤖

Local AI Assistant

Qwen3 4B runs locally via MLX, bundled in the app. It explains steps and proposes missing links — proposals are only simulated after you confirm them. Larger local models are optional downloads.

📸

Versioned Snapshots

Each sync — or each Gimle backup you load — becomes a new snapshot: policies, groups, EAs, profiles, PreStages, packages, scripts, apps, patch titles and blueprints. Any two can be compared.

🏛️

Gimle Backups

Read a Gimle backup folder instead of calling the API — no API client on the Mac running Janus. The newest backup loads at launch, older ones open as their own snapshots, and encrypted backups open with the organisation key.

👁️

Read-Only

Janus only sends GET requests to Jamf Pro. A read-only API role is all it needs; credentials live in the Keychain. With Gimle backups it reads files and needs no API client at all.

🧪

Demo Organization

A fictional org, Kestrel Labs, opens on first launch with three scenarios: a new engineering MacBook, retiring a sales Mac, and a what-if that creates a policy loop.

User Guide & Simulation Model

How to connect Jamf Pro with a read-only API role or read Gimle backups, build scenarios, read and change the timeline — plus every Jamf behavior the engine models.

📖 Read the Documentation

Where things stand

System Requirements

macOS 27 or later.

Apple Silicon only.

A Jamf Pro API client with a read-only role, or Gimle backups (optional — the demo org works without either).

Build Status

Version 1.3.0 (build 4). Signed with a Developer ID certificate and notarized by Apple.

The installer is about 2.1 GB, including the bundled Qwen3 4B model.

What's Verified

The simulation engine is covered by unit tests (55 across the engine, importer and assistant packages pass), including a determinism test, and the demo timelines are reproducible byte for byte.

The live Jamf Pro importer is tested against fixtures only — it has not yet run against a real org. The Gimle path is tested with fixture backups and with backups written by Gimle's demo tool (loose, packed and encrypted), but not yet through an MDM-delivered key profile inside the sandbox. The Apple on-device and Private Cloud Compute assistant options haven't been tested live; the bundled Qwen3 model has.

Known Limits

Policy order within one trigger is assumed alphabetical; user and network limitations are assumed satisfied; policy history of existing Macs isn't imported. Each of these shows up as a finding. Gimle backups don't contain App Installer title names or patch definitions, so Janus uses the deployment name and the patch policy's target version instead; backups in a newer format are refused.

Want to try the concept?

Concept app · Free · Signed & Notarized · macOS 27+ · Apple Silicon · 2.1 GB

Download Janus