Deploy and lock down ClearDictate with your MDM.
Standard macOS managed preferences. Works with Jamf, Kandji, Intune, Mosyle and any MDM that can deliver a configuration profile.
1. Install with MDM
- 01Download the DMG and verify its SHA-256 against the Download page.
- 02Upload it to your MDM as an app package, installing to /Applications.
- 03Deploy the managed-settings profile (below) to the same devices.
- 04Deploy a PPPC profile for Accessibility (step 5).
- 05Scope to a pilot group first, then roll out.
2. Managed settings
Managed values override the user’s settings. In the app, a managed setting is hidden and replaced by a note that it is managed by your organisation.
| Key | Type | Effect |
|---|---|---|
| ForceOnDevice | Boolean | true allows only the on-device engine (Parakeet). The Cloud engine and Smart cleanup are hidden, and the app never contacts OpenAI. Audio and text never leave the Mac. |
| ModelMirrorURL | String (https URL) | Downloads the speech model from this mirror instead of https://huggingface.co. The mirror must serve the same paths as Hugging Face for FluidInference/parakeet-tdt-0.6b-v3-coreml. |
| HistoryRetentionDays | Integer | 0 keeps no history, and the History window shows “History Is Off”. Any other number keeps that many days. Unset keeps everything, up to 2,000 dictations. |
To test on one Mac without MDM: defaults write com.megakad.dictationapp ForceOnDevice -bool true. A user can undo this, so use a profile to enforce it.
3. Sample profile
<?xml version="1.0" encoding="UTF-8"?>
<plist version="1.0"><dict>
<key>PayloadType</key><string>Configuration</string>
<key>PayloadDisplayName</key><string>ClearDictate (managed)</string>
<key>PayloadIdentifier</key><string>com.example.cleardictate</string>
<key>PayloadScope</key><string>System</string>
<key>PayloadContent</key>
<array><dict>
<key>PayloadType</key><string>com.megakad.dictationapp</string>
<key>PayloadDisplayName</key><string>ClearDictate settings</string>
<key>ForceOnDevice</key><true/>
<key>ModelMirrorURL</key>
<string>https://models.example.internal</string>
<key>HistoryRetentionDays</key><integer>30</integer>
</dict></array>
</dict></plist> UUIDs and version keys are omitted for readability; the downloadable file is complete, and Copy copies the whole file. Remove any key you don’t want to enforce, and replace the PayloadUUIDs with your own (uuidgen).
4. Model mirror
On first run each Mac downloads the speech model (about 470 MB) from Hugging Face. To keep this inside your network, or to avoid repeated downloads:
- aMirror the Hugging Face repository FluidInference/parakeet-tdt-0.6b-v3-coreml to an internal HTTPS host, keeping the same paths.
- bSet ModelMirrorURL to that host, for example https://models.example.internal.
- cOptionally block huggingface.co at your proxy to confirm no Mac falls back.
5. Permissions (PPPC)
Deploy a Privacy Preferences Policy Control payload for bundle ID com.megakad.dictationapp and the app’s code requirement (from codesign -dr - /Applications/ClearDictate.app). macOS limits what MDM can pre-approve:
| Permission | PPPC service | What MDM can do |
|---|---|---|
| Accessibility | Accessibility | Allow silently |
| Input Monitoring | ListenEvent | Let standard users approve. Only needed for the Fn key; users can pick a custom shortcut instead. |
| Microphone | Microphone | User approves on first use |
Replace its CodeRequirement placeholder with the output of the codesign command above before deploying.