Mimir 0.2.1 — distribution
============================
Merges MDM policy fragments into the managed configuration of AI agent harnesses
(Claude Code, Claude Desktop [experimental], opencode, OpenAI Codex CLI) and keeps it enforced.
Signed (Developer ID, team 23VFRTF5KC) and notarized. Requires macOS 26 or later.
Vendor catalog bundled: 2026.10.03.1 (updates itself from github.com/spectrechen/mimir-catalog).

Deployment order (Jamf Pro, Intune or any MDM; device scope)
  1. Profiles/Mimir-ManagedLoginItems.mobileconfig    required, deploy first
  2. Your org key profile                             only if fragments contain MIMIR-ENC secrets
                                                      (create it with Tools/make-org-key.sh + make-key-profile.sh)
  3. Mimir-0.2.1.pkg
  4. Optional: daemon settings profile                 Examples/profiles/Mimir-settings.mobileconfig
  5. Your policy fragments, one profile each           start from Examples/fragments/*.json

Contents
  Mimir-0.2.1.pkg          installer (daemon, CLI at /usr/local/bin/mimirctl, seed catalog)
  Mimir-0.2.1.pkg.sha256   checksum
  Profiles/                   Managed Login Items profile
  Examples/fragments/         example fragments (JSON): org baseline, security denies, department A,
                              extra vendor B access, local-MCP kill switch, LLM gateway
  Examples/profiles/          the same as ready-to-upload .mobileconfig files
  Examples/previews/          what the merged vendor files look like for four example groups of Macs
  Examples/settings/          example daemon settings
  Examples/DEMO-ONLY-key.pem  public demo key that decrypts the example secrets (never use it for real secrets)
  Jamf/                       custom schemas (fragment + settings), Extension Attributes
  Intune/                     custom attribute scripts, setup notes
  Tools/mimirctl              the CLI for your admin Mac (validate, preview, simulate, profile, encrypt, key-info)
  Tools/encrypt.html          offline browser page to encrypt secrets
  Tools/make-org-key.sh       creates the org encryption key (P-256)
  Tools/make-key-profile.sh   wraps the org key in a certificate profile
  Catalog/                    the signed vendor catalog (for an internal mirror: set CatalogURL)
  Docs/ADMIN-GUIDE.md         deployment, fragments, secrets, reporting, troubleshooting
  Docs/DESIGN.md              architecture, merge semantics, threat model
  Docs/TEST-REPORT.md         automated tests and the real-Mac test, incl. what is not verified yet
  Docs/screenshots/           CLI and encrypt page screenshots (light + dark)

Quick check on your admin Mac
  Tools/mimirctl validate Examples/fragments --catalog Catalog/catalog.json
  Tools/mimirctl preview Examples/fragments/org-baseline.json Examples/fragments/deptA-baseline.json --catalog Catalog/catalog.json
  Tools/mimirctl profile my-fragment.json --name my-fragment --output Mimir-policy-my-fragment.mobileconfig

On a managed Mac
  mimirctl status        mimirctl discover        sudo mimirctl apply

Try a policy set without a Mac to spare
  Tools/mimirctl simulate Examples/fragments --catalog Catalog/catalog.json --key Examples/DEMO-ONLY-key.pem --out /tmp/mimir-sim
  Tools/mimirctl status --file "/tmp/mimir-sim/Library/Application Support/Mimir/status.json"

Notes
  - Example secrets use a throwaway demo key and hosts use *.acme.example. Replace both before production use.
  - Don't deploy vendor profiles for com.anthropic.claudecode, com.anthropic.claudefordesktop,
    ai.opencode.managed or com.openai.codex next to Mimir: they override Mimir's files.
  - Claude Desktop support is experimental: test on a pilot group first.
Uninstall: sudo "/Library/Application Support/Mimir/uninstall.sh" [--keep-policy]
