Simulates the lifecycle of a Jamf-managed Mac — from PreStage enrollment to decommissioning — on an editable timeline. See which policy fires when, which smart group the Mac lands in, which profile follows, and why. Reads a live Jamf Pro org, or Gimle's offline backups.
Swimlanes or a list with a causal graph. Arrows always point from cause to effect, and the inspector shows what changed on the Mac vs. in Jamf, the full “why” chain, and what each step causes.
Enable a policy, change its frequency, triggers or scope, edit smart group criteria — the timeline recalculates immediately. Changes stay in the scenario and never reach Jamf.
Check-ins, logins, custom triggers, Self Service clicks, EA edits, app installs, re-enrollment, unmanage, wipe — or mark a step as failed and see what depends on it.
Every step is known, inferred or assumed. Assumptions surface as findings, alongside loops, script EAs nothing explains, and custom triggers nobody listens to.
Teach Janus what a package or script does, e.g. “Install Rosetta runs → EA Rosetta Installed = Yes”. Exact heuristic matches are auto-confirmed; the rest are pre-sorted for bulk review.
Qwen3 4B runs locally via MLX, bundled in the app. It explains steps and proposes missing links — proposals are only simulated after you confirm them. Larger local models are optional downloads.
Each sync — or each Gimle backup you load — becomes a new snapshot: policies, groups, EAs, profiles, PreStages, packages, scripts, apps, patch titles and blueprints. Any two can be compared.
Read a Gimle backup folder instead of calling the API — no API client on the Mac running Janus. The newest backup loads at launch, older ones open as their own snapshots, and encrypted backups open with the organisation key.
Janus only sends GET requests to Jamf Pro. A read-only API role is all it needs; credentials live in the Keychain. With Gimle backups it reads files and needs no API client at all.
A fictional org, Kestrel Labs, opens on first launch with three scenarios: a new engineering MacBook, retiring a sales Mac, and a what-if that creates a policy loop.
How to connect Jamf Pro with a read-only API role or read Gimle backups, build scenarios, read and change the timeline — plus every Jamf behavior the engine models.
📖 Read the DocumentationmacOS 27 or later.
Apple Silicon only.
A Jamf Pro API client with a read-only role, or Gimle backups (optional — the demo org works without either).
Version 1.3.0 (build 4). Signed with a Developer ID certificate and notarized by Apple.
The installer is about 2.1 GB, including the bundled Qwen3 4B model.
The simulation engine is covered by unit tests (55 across the engine, importer and assistant packages pass), including a determinism test, and the demo timelines are reproducible byte for byte.
The live Jamf Pro importer is tested against fixtures only — it has not yet run against a real org. The Gimle path is tested with fixture backups and with backups written by Gimle's demo tool (loose, packed and encrypted), but not yet through an MDM-delivered key profile inside the sandbox. The Apple on-device and Private Cloud Compute assistant options haven't been tested live; the bundled Qwen3 model has.
Policy order within one trigger is assumed alphabetical; user and network limitations are assumed satisfied; policy history of existing Macs isn't imported. Each of these shows up as a finding. Gimle backups don't contain App Installer title names or patch definitions, so Janus uses the deployment name and the patch policy's target version instead; backups in a newer format are refused.
Concept app · Free · Signed & Notarized · macOS 27+ · Apple Silicon · 2.1 GB
Download Janus