vibe coded with ❤️
Concept app · v0.2.1 · Notarized

Mimir

MDM can only deliver one policy profile per setting domain. Mimir takes many small profile fragments — one for the whole company, one per department, one for a pilot — merges them with the strictest rule winning, and writes the result into the files that Claude Code, Codex, opencode and Claude Desktop read. A root daemon keeps those files in place, and puts them back if someone edits them.

Concept app. Mimir explores how an IT team could enforce one AI-agent policy across several tools and teams without hand-maintaining a profile per tool. It's signed and notarized, but not a supported product: the merge and enforcement were tested on one Mac in a demo environment, not in production, and no AI tool has yet been confirmed to read the files in a live session. Read Where things stand before deploying it anywhere that matters.
Terminal window running mimirctl status: health ok, catalog 2026.10.03.1, four fragments with their priorities, and the managed harnesses claude-code, claude-desktop, opencode and codex with the files Mimir wrote

One policy, many agents, many teams

🧩

Profile Fragments

Each team's policy is its own configuration profile in its own preference domain (com.spectrechen.mimir.policy.<name>), scoped by MDM like any other profile. Mimir merges all the fragments that land on a Mac.

⚖️

Strictest Rule Wins

Allowlists intersect, locks stay on if any fragment sets them, and the more restrictive of two values wins — whatever the priority. Grants are unioned, denies remove entries after the merge. A department can narrow the company baseline but not widen it.

🛡️

Enforced, Not Suggested

A root LaunchDaemon owns the vendor files. It re-applies on a timer, when profiles change, and about 2 seconds after someone edits or deletes a file. The first takeover backs the existing file up, and uninstalling restores it.

🗂️

Signed Vendor Catalog

Where each tool reads its policy, and how each key merges, lives in an Ed25519-signed catalog that updates without a new app. A path allowlist compiled into the binary means even a signed catalog can't make the root daemon write somewhere new.

🔐

Encrypted Secrets

MIMIR-ENC envelopes (P-256 ECDH + AES-GCM) keep tokens and auth headers out of profiles, MDM exports and screenshots. The key sits in the System keychain, and the plaintext only appears in the vendor file. The user can read that file, so this protects the pipeline, not the endpoint.

🔍

Shadow-AI Discovery

Finds which of 18 known agent tools are installed or running — managed or not — without reading their configs or ever executing them. Feed the result to Jamf or Intune as extension attributes.

🧪

Preview Before You Push

mimirctl preview shows the exact files a combination of fragments produces; simulate runs the whole pass into a folder; DryRun reports without writing. No Mac needed.

🧊

Fail-Safe

A fragment Mimir can't read freezes the last applied configuration instead of dropping a deny. A secret that can't be decrypted holds just that tool. Health is reported as ok, degraded or error.

🧰

mimirctl

Status, discovery, preview, validate, simulate, encrypt, key-info, profile and schema generation, and catalog signing — a signed command-line tool installed at /usr/local/bin/mimirctl, plus an offline encrypt.html.

📊

Fleet Reporting

Jamf extension attributes and Intune custom attributes report health, catalog version and unmanaged tools; status.json never contains secrets.

Admin Guide & Design

Deployment order, fragment format, merge rules, the vendor files Mimir writes, every setting, encrypting secrets, reporting and uninstalling — with a worked two-department example.

📖 Read the Documentation

Where things stand

System Requirements

macOS 26 or later (tested on macOS 27 only).

An MDM that can deliver custom configuration profiles — Jamf Pro and Intune are covered by the included schemas and scripts.

Build Status

Version 0.2.1, catalog 2026.10.03.1. Signed with a Developer ID certificate and notarized by Apple.

59 unit tests pass in 9 suites.

What's Verified

Tested on one Mac (macOS 27, not enrolled in MDM) with Mimir 0.2.0, fragments placed by hand: install, daemon start, merge results, a decrypted secret, tamper revert in about 3 seconds, removal and uninstall.

Claude Desktop's setting shows as managed in macOS, but whether the app honours it after a relaunch wasn't checked.

Not Yet Verified

No AI tool — Claude Code, Codex, opencode — was run to confirm it reads Mimir's files; the paths are the vendors' documented admin locations. Also untried: a real MDM deployment, the organisation key delivered as an MDM certificate payload, the 0.2.1 package on a Mac (its two fixes are unit-tested only), and macOS 26.

Only 4 of the 18 listed tools are applied; the rest are discovery-only.

Want to try the concept?

Concept app · Free · Signed & Notarized · macOS 26+ · 2.4 MB

Download Mimir