Case study / Internal tooling, own build
Fleet answers Jamf's own console can't give you
Managing a Mac fleet through Jamf means the questions you actually have are often the ones the console will not answer. MacWrangler is the agentic layer that gets them, safely.
Working build, device-verified- RAG over live inventory
- Agentic auditor
- Custom read-only MCP

The engagement
Challenge
The answers you need, the console won't give, and AI must be safe
Jamf's console cannot answer the cross-cutting fleet questions an admin actually has. But any AI that can act on a real fleet is dangerous by default, so it has to be safe by construction, not by good intentions.
Action
An agentic layer with the writes locked down
A macOS app with RAG chat over live Jamf inventory plus an agentic Fleet Auditor driving a custom read-only MCP server, on a safety-gated remediation spine: write paths default off, every action passes a single choke point, and a human confirms before anything changes on a device.
Result
Read-only intelligence proven, writes gated and reviewed
The read-only intelligence is proven live against a real editorial Mac fleet. A newer privilege-escalation write path was built to spec and then put through a mandated security review, with the review's corrections applied before it touches real credentials. Writes stay off until deliberately enabled.
How it is built
AI proposes, a human confirms
Write paths are off by default and pass one audited choke point. AI proposes; a human confirms.
- 01RAG chat. Natural-language questions over live Jamf inventory, answering what the console cannot.
- 02Read-only MCP. A custom MCP server the agentic auditor drives, read-only by construction.
- 03Safety spine. A single remediation choke point with a blast-radius gate and a ledger; writes default off.
- 04Diagnostics. Rich per-device network, disk, and speed diagnostics over SSH, GUI-confirmed live.
- 05Security review. The escalation write path passed a mandated top-model security review; findings were corrected before any real-credential use.
What it proves
AI that touches a fleet has to be safe by construction: it proposes, a human confirms, and the writes default off.
See the rest of the work →Deployed against a real editorial Mac fleet; the client and device identifiers are anonymized here.