Managed settings (MDM)

A configuration profile can set where MimicScribe’s text AI runs and lock that choice. Audio is captured, transcribed and diarized on the Mac in every configuration; the profile decides where the transcript text may go.

The profile uses Apple’s standard managed-preferences payload for the app.mimicscribe domain, so it works with any MDM: Jamf, Kandji, Intune, Mosyle and others. A setting the profile manages wins over anything the user picks. In the app, the matching controls are greyed out and read “Managed by your organization.”

MimicScribe has no admin console or audit dashboard. The profile locks settings on each Mac; it does not report back.

Local-only profile

Download the local-only profile. It turns off every AI provider. With it installed:

  • Every new meeting and imported file is offline, and the Offline switch can’t be turned off. Offline meetings never go to webhooks, cloud search answers, or connected AI tools.
  • Typed and spoken questions about any meeting, including ones recorded before the profile was installed, aren’t sent to an AI provider.
  • Dictation pastes the on-device cleanup (fillers, repeats, paragraphs, spoken punctuation). Per-app dictation profiles can’t route to a provider.
  • Transform is off. Its shortcut shows “Transform is turned off by your organization.”
  • Reference documents, vocabulary hints and meeting search make no AI calls.
  • Onboarding shows a note instead of the “Where should AI run?” choices. With a profile that sets only some keys, the rest start off and the user can turn them on in Settings.

Upload it to your MDM as a custom profile, or deploy the same keys through your MDM’s custom-settings payload.

Locking your own Mac

You don’t need an MDM. Double-click the downloaded profile, then approve it in System Settings → General → Device Management. Remove it from the same pane. A profile you installed yourself can be removed by you; one your MDM installed can’t.

From Terminal or an AI agent

An agent can download the profile and open it, but macOS requires you to approve the install yourself. No script can skip that step.

curl -fsSLo ~/Downloads/mimicscribe-local-only.mobileconfig 
  https://mimicscribe.app/mimicscribe-local-only.mobileconfig
open ~/Downloads/mimicscribe-local-only.mobileconfig
# Now approve it: System Settings → General → Device Management

Then quit and reopen MimicScribe. To check it took effect:

defaults read app.mimicscribe meetingAIProvider   # prints: none

In the app, Settings → AI & Data shows each picker greyed out with “Managed by your organization.”

Without a profile, the same keys can be set with defaults write (for example defaults write app.mimicscribe meetingAIProvider none). That sets the value but doesn’t lock it: the user can change it back in Settings. Quit MimicScribe before writing.

Keys

All keys live in the app.mimicscribe domain.

KeyValuesControls
meetingAIProvidernone, gemini, onDevice, openAICompatiblePost-meeting summary, speaker names, action items
liveAssistantProvidernone, gemini, openAICompatibleIn-meeting briefings, talking points, live Q&A
dictationProvidernone, gemini, onDevice, openAICompatibleDictation cleanup
instructionProvidernone, gemini, onDevice, openAICompatibleTransform (none turns it off)
SUEnableAutomaticCheckstrue / falseDaily update check (on by default)
SUAutomaticallyUpdatetrue / falseInstall updates without asking

Values are case-sensitive. An unrecognized value is read as gemini, so after deploying, open Settings → AI & Data on one Mac and check that each locked picker shows what you set.

none is off. gemini is the built-in cloud AI through MimicScribe’s open-source proxy. onDevice is Apple Intelligence and needs a Mac that supports it. openAICompatible is the custom endpoint.

Meetings are forced offline when meetingDefaultOfflineMode is true (Offline mode: no feature can use cloud AI, and every meeting stays offline) or when both meetingAIProvider and liveAssistantProvider are none. A key the profile leaves out stays under the user’s control, so a local-only profile needs all four provider keys. (supportingProvider is no longer read: search and reference documents follow meetingAIProvider, and vocabulary extraction follows dictationProvider.) Meetings recorded before the profile was installed keep their own Offline setting.

Allowing only your company’s endpoint

Set the provider keys to openAICompatible and also manage openAICompatibleBaseURL and openAICompatibleModelName. The managed values are the ones the app uses. The endpoint fields in Settings don’t lock yet, so a user can type in them, but their edits aren’t used. If the endpoint needs a key, the user enters it in Settings; keys are stored in the Keychain, not in preferences.

What still connects

Update checks, and license validation on paid plans, still reach mimicscribe.app with a profile installed. Neither carries meeting content. Crash reports are off by default; after a crash the app asks before sending one. The full list is on the network activity page.