Skip to main content

Apple Agentic Security Policy

Overview

The Apple Agentic Security Policy installs Swif's Agentic Security agent on managed Macs and enrolls them in Agentic Security. Use it to deploy the agent to many devices at once, instead of downloading and running the installer on each one.

Important: This policy only installs the agent. It doesn't monitor or block anything by itself. After the agent is installed, assign Agentic Security policies to choose what it does, such as the Logging Policy to record AI agent activity. Without them, the agent doesn't capture AI agent activity.

Supported platforms and requirements

Item

Details

Platform

macOS

Minimum OS

macOS 12 or later

Device ownership

Company-owned and BYOD Macs

Other requirements

The device must be enrolled in Swif and online

Despite its name, this policy applies to Macs only. iPhones and iPads aren't supported.


Settings reference

Setting

What it does

Default

Enable Agentic Security

On: downloads the Agentic Security agent and enrolls the device in Agentic Security. Off: the policy doesn't install the agent.

Off

Enable Agentic Security is required, and it's off by default. Turn it on to install the agent.


How it works

  1. You turn on the policy and add devices from the Agentic Security page. Swif sends the policy to those devices.

  2. Swif downloads the Agentic Security agent to each device and installs it.

  3. The agent enrolls the device in Agentic Security for your Swif organization.

  4. The device appears in Agentic Security, ready for Agentic Security policies.

Users don't need to sign up or create a separate account. Devices enroll in your existing Swif workspace.


Before you start

  1. Make sure the Macs are enrolled in Swif and online.

  2. Plan which Agentic Security policies to assign after the agent is installed. See the Agentic Security Policy collection.

  3. For BYOD devices, tell users what Agentic Security collects. Monitoring policies can record prompts, responses, commands, and file paths from AI agents.


Set up the policy

You set up this policy from the Agentic Security page, in the Agentic Security Deployment Policies window. There it's listed as Apple Agent Security Policy (macOS 12.0+), with its status:

Status

Meaning

Button

Not Configured

The policy hasn't been set up yet.

Configure Policy

Configured

The policy is set up. Add more devices to it at any time.

Add Devices

Configure the policy

  1. In Swif, go to Agentic Security.

  2. Click Configure Policies to open Agentic Security Deployment Policies.

  3. Find Apple Agent Security Policy and click Configure Policy.

  4. Turn on Enable Agentic Security.

  5. Save the policy.

  6. Add the Macs that should get the agent. Start with a few devices to confirm the agent installs before a wider rollout.

Add devices to the policy

Once the policy shows Configured:

  1. Go to Agentic Security and click Configure Policies.

  2. Find Apple Agent Security Policy and click Add Devices.

  3. Select the Macs to add, then save.

Find devices missing the agent

At the bottom of Agentic Security Deployment Policies, Swif shows how many devices are missing the Agentic Security agent. Click Review Devices to see which ones. Then add them to the policy.

Swif also shows a Monitoring Gap Detected banner on the Agentic Security page when it finds devices running AI tools, such as OpenClaw, that the agent isn't monitoring.

Install on a single device

To install the agent on one device by hand instead, click Install Agentic Security at the top of the Agentic Security page and download the installer.

After the agent is installed

In Swif, go to Agentic Security > Policies and assign the policies you need, for example:

Goal

Policy

Record AI agent activity

Collect activity from AI coding agents' local logs

Block destructive commands such as rm -rf


Example configuration

Engineering Macs that run Claude Code, Codex CLI, or Cursor

Step

Policy

Setting

1

Apple Agentic Security Policy

Enable Agentic Security: On

2

Swif Agentic Security Logging Policy

Logging on

3

Swif Destructive Command Guard (DCG) Policy

On

Swif installs the agent first, then the Agentic Security policies record agent activity and block destructive commands.


Verify the policy

  1. In Swif, open the device and confirm that the policy shows as applied.

  2. Go to Agentic Security and confirm that the device appears in the device list with a recent Last Heartbeat.

  3. Click Configure Policies and check that the number of devices missing the agent has gone down.

  4. After you assign a Logging Policy, open the device's Agentic Security tab and confirm that AI agent activity appears.


Troubleshooting

The agent doesn't install

  • Check that Enable Agentic Security is on and that the device was added to the policy.

  • Check that the device is enrolled in Swif and online.

  • Check the device's Commands tab for errors.

The device doesn't appear in Agentic Security

The agent may still be installing or enrolling. Wait for the device to check in with Swif, then refresh the Agentic Security device list.

The device appears, but no AI agent activity shows

This policy only installs the agent. Assign the Swif Agentic Security Logging Policy to record activity.


Related resources

Did this answer your question?