Skip to content

About

Why this site exists

An independent, non-commercial resource on a subject with surprisingly little written about it.

The gap

Enterprise tooling, an entirely personal problem

Apple's device management framework is mature, well documented, and used every day to configure Macs in schools and corporations. It is also almost entirely absent from the conversation about digital accountability, where the available options are consumer apps that any determined user can uninstall in a minute.

Search for how to apply configuration profiles, supervision, and content filtering to a household or a small ministry and you find vendor marketing, enterprise documentation written for people with an IT department, and very little in between. The technical answers exist; nobody has written them down for this audience.

That is what this site is: a set of written guides explaining how the framework works, what it can genuinely do, where it falls short, and how to think about the consent questions that come with it.

About Trevor Pope

Trevor Pope is a software engineer. Alongside this site he holds a technical leadership role on a Christian mobile platform being built to connect churches with the ministries around them.

This resource started from that same world. Helping a ministry sort out its devices made the gap obvious: the filtering tools marketed to churches and families were designed to be easy to install, not hard to remove, while the serious device management tooling assumed an IT department nobody in the room had. The research done to answer that ended up being worth writing down.

The guides are the whole of it. If something here is unclear, questions are welcome — see the contact page, and I'll get back to you as soon as I can.

Position

Six things every guide here assumes

These are not neutral technical documents. They take a position on how this technology should be used, and it is fairer to state it up front than to let it leak through the recommendations.

01

Consent before configuration

Management belongs only on a device whose user knows about it and agreed to it. Where the user is a minor, a parent authorizes it and the child is still told what is applied, in terms they can understand. Every guide here is written from that assumption.

02

Write it down first

Before installing anything, write down what it will do, what it collects, and who can see it. This is as true configuring your own Mac as it is for a congregation. It surfaces decisions you were making without noticing.

03

Minimum necessary data

Collect the least that accomplishes the goal. Apple's MDM framework provides no keystroke logging, screen recording, or camera access, and the guides here do not point anyone toward tools that add them.

04

Visible management

macOS discloses management by design, and that is a feature. Any configuration that tries to hide its own presence is a signal about intent rather than a technical achievement.

05

A clean way out

Every setup should have a documented path to unenrollment, designed in from the start. A configuration that is hard to undo is a trap rather than a safeguard.

06

State the limits

No filter is absolute. Categorization is imperfect, an unmanaged phone defeats a perfectly managed Mac, and technical controls support a commitment rather than replacing it. Guidance that will not say this is not worth trusting.

Accuracy

How to treat what you read here

These guides describe behavior that Apple documents, but Apple changes its platforms every year. Specifics that are accurate today may drift, and no third-party write-up — this one included — should be your final authority on a detail that matters.

Where a setting is load-bearing for your situation, verify it against Apple's current platform deployment documentation and test it on the actual device before relying on it.

What the guides cover

  • Apple MDM protocol and configuration profile payloads
  • Device supervision and what it takes to get it
  • The four macOS content filtering mechanisms compared
  • Apple Business Manager and Automated Device Enrollment
  • Planning, verifying, and reviewing a deployment
  • Consent and disclosure conversations