recordist
On this page

Managed settings for IT

From version 0.3.10, an organisation can set part of Recordist’s behaviour on the Macs it manages with a configuration profile from its device management (MDM). The profile writes managed preferences for the app’s bundle identifier, app.recordist.desktop. Recordist reads them on the Mac and enforces them.

There is no Recordist server, account or admin console. The profile is the whole mechanism, and Recordist sends nothing about the policy or about anyone’s meetings anywhere. Managed settings work the same on every plan, and they exist on macOS only.

The files

File What it is
recordist.mobileconfig A sample profile with a com.apple.ManagedClient.preferences payload. It sets ForceLocalModel to true and MaxRetentionDays to 30. Its UUIDs are placeholders.
recordist-policy.schema.json A custom schema for Jamf Pro. It covers every key, and each key can be left Not Configured.

Deploy the policy

Jamf Pro

  1. Go to Computers → Configuration Profiles → New → Application & Custom Settings → External Applications → Add.
  2. For the source, choose Custom Schema. Set the preference domain to app.recordist.desktop.
  3. Paste the contents of recordist-policy.schema.json, then set the keys you want. Leave the rest Not Configured.
  4. Scope the profile to the computers or users that run Recordist, and save.

Another MDM

This works the same way in Kandji, Mosyle, Intune, Workspace ONE, Addigy, Fleet and other consoles that accept a custom profile.

  1. Download recordist.mobileconfig. Replace both PayloadUUID values with fresh ones (run uuidgen twice), and replace com.example and Example Organisation with your own values.
  2. Add the other keys you want inside mcx_preference_settings, using the keys below.
  3. Check the file with plutil -lint recordist.mobileconfig.
  4. Upload it as a custom configuration profile and scope it. Most consoles sign a profile on upload.

If your MDM has a custom settings or preference domain payload, you can use that instead of the file. Set the domain to app.recordist.desktop and add the same keys.

Try it on one Mac

Double-click the profile, then approve it in System Settings → General → Device Management (on macOS 14, System Settings → Privacy & Security → Profiles). An administrator of that Mac can remove a profile that was installed by hand, so use your MDM for anything people should not be able to undo.

The keys

Every key is optional. Recordist enforces only values that macOS reports as forced, which means managed preferences delivered by a profile. A person’s own defaults write app.recordist.desktop … never becomes a policy.

ForceLocalModel (boolean)

Notes are written on the Mac. Recordist refuses the Anthropic and OpenAI-compatible providers, and it refuses Ollama at any address other than 127.0.0.1, ::1 or localhost. Notes fall back to the built-in engine, and the person is told why once per launch. API keys for cloud providers can’t be saved.

DisableCloudAIKeys (boolean)

The Anthropic and OpenAI-compatible providers can’t be used, and their API keys can’t be saved. Notes fall back to the built-in engine. Ollama is still allowed wherever it runs, so add ForceLocalModel if notes must stay on the Mac.

MaxRetentionDays (integer)

Caps both Keep audio files and Delete meetings after in Settings → Privacy. Longer choices, including Forever, become this many days, and shorter choices stay as they are. Because Delete meetings after is capped too, meetings older than the cap are deleted with their transcripts and notes, even for a person who had that setting off. 0 or a negative number means no cap.

DisableAudioExport (boolean)

The meeting view’s Show in Finder for the audio file is removed, and the app refuses it. That button is the app’s only way to take audio out, and the audio player’s right-click menu is turned off as well. Audio still plays inside Recordist.

DisableAgentRecording (boolean)

Allow agents to start recordings in Settings → Integrations is forced off. The local API, and through it the MCP gateway and agents, can’t start a recording or import audio, and it answers with a message that names your organisation. A call reported through the local API, by the Chrome extension for example, always shows the record card, even for an app on the Record without asking for list.

DisableAutoRecordApps (boolean)

Record without asking for in Settings → Detection is forced empty, so the record card always asks before a detected call is recorded.

DisableAutoExport (boolean)

Auto-export Markdown after each meeting is forced off. Exporting a meeting by hand still works.

AllowedExportFolder (string)

Exports, by hand and automatic, go to this folder or a folder inside it. The path must be absolute, and ~ means the person’s home folder. Relative paths and paths that contain .. are ignored.

OrganizationName (string)

Shown next to every managed control as “Managed by” and the name. Without it, the app says “your organisation”. On its own it enforces nothing.

Value formats

MDM consoles store values in different ways, so Recordist accepts several forms. A boolean can be <true/> or <false/>, 1 or 0, or the strings true, false, yes or no. A number can be an <integer> or a numeric string. A value of the wrong type is ignored, as if the key were not set.

What people see

Settings shows a banner at the top that says some settings on this Mac are managed by your organisation through a configuration profile. Every managed control is locked and carries a “Managed by” note. The retention controls stay usable below the cap. In the provider menu, only the refused providers are greyed out.

When a profile is removed, people get their own choices back. Recordist keeps each person’s own setting under the policy and shows or applies the managed value only while the policy is in force.

When changes apply

Recordist reads the policy at launch and then every 60 seconds. A profile that is installed, changed or removed takes effect within a minute, with no restart. The app logs the change and refreshes the Settings screen if it is open.

A new or changed MaxRetentionDays runs retention at once. Retention also runs at launch and every six hours. For limits a person sets, Recordist skips a pass that would delete more than half of the meetings on the Mac, which guards against a wrong setting or a wrong clock. A managed cap is deliberate, so that check doesn’t hold it back, and the first pass deletes every meeting older than the cap.

Check a Mac

To read what the profile delivered, run this in Terminal on the Mac:

defaults read /Library/Managed\ Preferences/app.recordist.desktop

A profile scoped to a user instead of the computer lands in /Library/Managed Preferences/<short user name>/app.recordist.desktop.plist, and you can read it the same way. If the command says the domain does not exist, the profile hasn’t reached this Mac. Check the profile’s scope in your MDM, and run sudo profiles show -type configuration.

In Recordist itself:

  • Settings shows the banner, and every managed control is locked with its note.
  • Settings → General → Export diagnostics writes a text file with a [managed policy] section that lists the keys in force, for example ForceLocalModel, MaxRetentionDays=30.
  • The log, ~/Library/Logs/app.recordist.desktop/recordist.log, has a line that starts managed policy at launch: and, after a change, a line that starts managed policy changed:.

What is not managed yet

These are the limits of the current version.

  • macOS only. Recordist has no policy on other systems.
  • No reporting back. Recordist doesn’t tell your MDM, or anyone else, whether the policy is applied, because it has no server to report to. Check compliance on the Mac, as shown above.
  • Starred meetings are kept past MaxRetentionDays. Retention never deletes a meeting the person starred, and that applies to the managed cap too. The cap still applies to a starred meeting’s audio.
  • Audio files stay in the person’s data folder. DisableAudioExport removes the in-app way to take audio out. The files in ~/Library/Application Support/app.recordist.desktop/audio/ are still readable by that macOS user, like any of their files. Use MaxRetentionDays, or Delete right after transcription, to limit how long they exist.
  • Transcripts and notes can still leave the app. Export (Markdown, text, SRT, VTT and JSON), the copy buttons and the clipboard are not managed. AllowedExportFolder controls only where export files are written.
  • Agents can still read. DisableAgentRecording stops agents from starting recordings and imports. Once the person has connected them, the local API and the MCP gateway can still list, search and read meetings, stop a running recording and add markers.
  • API keys saved before the policy stay in the keychain. They aren’t used while a policy refuses their provider, and they aren’t deleted. Remove everything and quit in Settings → Privacy deletes them.
  • OpenAI-compatible servers on the same Mac, such as LM Studio or vLLM, are refused under ForceLocalModel, because that provider is built for API keys and can point anywhere. Use the built-in engine, or Ollama on 127.0.0.1.
  • Not managed at all yet: meeting detection and its signals, the Chrome extension, manual recording (including Ask before a manual recording too), automatic stop, the speech model and its language, the update check, launch at login, hotkeys and appearance.
  • Up to 60 seconds of delay between a profile change and Recordist enforcing it.

The summary for IT, security and legal reviewers covers the rest of what a review asks: where data is stored, what the app sends over the network, retention, legal holds and consent.