Skip to content

Preference reference

Tobias Almén edited this page Sep 28, 2026 · 1 revision

Preference reference

Every setting the app and its helper read. Domain: com.github.macadmins.SupportCompanion.

The Owner column says which tier the key belongs to — where the value has to come from to be honoured. Configuration explains the tiers and why they exist. In short: Defaults can be deployed however you like, Profile and Helper cannot.


Elevation

Time-limited administrator rights. Profile-only, with the helper independently enforcing what matters. See Admin elevation.

Key Type Default Owner Notes
EnableElevation bool false Profile Master switch.
MaxElevationTime int 5 Profile Minutes per elevation window.
RequireResonForElevation bool true Profile Demand a typed reason. The key really is spelled that way.
ReasonMinLength int 10 Profile Minimum characters in that reason.
ElevationWebhookUrl string "" Profile Posted to when a reason is submitted. Falls back to disk if the post fails.
ElevationSeverity int 6 Profile The severity field in the webhook payload.
ShowElevateTrayCard bool true Defaults Presentation only: whether the menu bar popover carries the elevation card.
EnforceAdminAllowlist bool false Helper (device) Demote accounts the allowlist does not account for. Reconciled at helper start and every five minutes.
PermanentAdmins [string] unset Helper (device) Accounts allowed to hold admin without the helper having granted it. Unset is not the same as [] — an empty array is a coherent policy, a missing key is a half-finished one, and the helper refuses to enforce rather than demote everybody.
ElevationAllowedAdmins [string] [] Helper (device) Accounts the watchdog should not report as unexplained administrators — a management account an MDM may add while somebody is elevated.

Privileged actions

Key Type Default Owner Notes
Actions [dict] [] Profile / Defaults Custom buttons. Read from a profile if there is one, otherwise from UserDefaults — but IsPrivileged is honoured only in the profile case, and ignored with a logged error otherwise.
RequirePrivilegedActionAuthentication bool true Profile Authenticate the user before running a privileged action.

Each Actions entry:

Field Type Default Notes
Name string "Unnamed" Also how the helper looks the action up, and what SupportCompanionCLI action takes.
Command string ""
Icon string none SF Symbol name.
Description string ""
ButtonLabel string "Run"
IsPrivileged bool false Runs as root through the helper. Profile-only.

See Customization for examples.

User installs

See User installs.

Key Type Default Owner Notes
EnableUserInstalls bool false Profile + Helper Both read it. The app decides whether to stage a file at all; the helper decides whether to install it.
ShowInstallerServiceMenuItem bool follows EnableUserInstalls Profile Whether Finder's right-click offers "Install with Support Companion". Set it explicitly to keep the feature but route everyone through the in-app catalog. Applied on every launch.
RequireAuthenticationForInstalls bool true Helper (per-user) The user authenticates as themselves, not as an administrator. Turning it off means an unlocked unattended Mac is enough.
UserInstallFallback string "installer" Helper (per-user) What to offer when an installer is not allowlisted: installer, elevate, none.
AllowedInstallers [dict] [] Helper (per-user) The allowlist. Entries that cannot decide anything are dropped and logged.
SkipHelperInstall bool false Profile (device) The helper is deployed declaratively; don't let the package install one. See Deploying the helper.

Each AllowedInstallers entry:

Field Type Default Notes
Name string required
SHA256 string none 64 hex characters. Present ⇒ strict mode: pins one exact build, survives no update.
TeamID string none Required in signature mode, i.e. whenever SHA256 is absent.
PackageIdentifier string or [string] [] For a .pkg. A distribution package needs every component listed — see User installs#Packages with more than one component.
BundleIdentifier string or [string] [] For the app inside a .dmg.
AllowAnyIdentifier bool false Accept anything that team signs. A vendor allowlist, not an app allowlist.
LeafCertificateSHA256 string none Pins the signing certificate itself. Stricter than TeamID; needs updating when the vendor renews.
MinimumVersion string none Refuse older builds, so a signed-but-vulnerable version cannot be installed instead.
RequireNotarized bool true
AllowScripts bool false The most useful restriction here: a scriptless package landing in /Applications is a file copy; one with a postinstall is arbitrary root code on every future build the vendor signs.
AllowedPayloadPrefixes [string] unrestricted Absolute path prefixes this installer may write to. Some destinations need naming even when unrestricted — see User installs#Destinations that always need naming.
AllowUnrestrictedPayload bool false Lets it write anywhere, including the User installs#Destinations that always need naming. Its own key, so the most dangerous setting has to be meant.

A signature-mode entry needs a TeamID and one of PackageIdentifier, BundleIdentifier or AllowAnyIdentifier, or it is rejected as unable to match anything.

Mode and data sources

See Modes.

Key Type Default Owner Notes
Mode string auto-detected Defaults Munki, Jamf, Intune, Fleet, SystemProfiler. Detection runs only when this is empty.
LogFolders [string] set by mode Defaults What "Gather Logs" collects.
ExcludedLogFolders [string] [] Defaults
JamfLogPollHours int 36 Defaults How far back to read jamf.log.
RefreshSelfService bool true Defaults Refresh the Jamf Self Service catalog on update checks.
FleetUrl string "" Profile Overrides the Fleet server URL discovered from fleetd or orbit. Profile-only, because the device token is sent to that server.

Branding

Key Type Default Owner Notes
BrandName string "Support Companion" Defaults Also used as the heading in the desktop info window.
BrandLogo string "" Defaults Base64. Used in dark mode, and in both if BrandLogoLight is unset.
BrandLogoLight string "" Defaults Base64, light mode.
AccentColor string unset Defaults Hex. Falls back to the system accent colour.

Navigation and menus

Key Type Default Owner Notes
MenuShowIdentity bool true Defaults
MenuShowApps bool true Defaults
MenuShowSelfService bool true Defaults
MenuShowCompanyPortal bool true Defaults Needs CompanyPortalUrl.
CompanyPortalUrl string "" Defaults Supports sovereign cloud endpoints.
MenuShowKnowledgeBase bool true Defaults Needs KnowledgeBaseUrl.
KnowledgeBaseUrl string "" Defaults
SupportPageUrl string "" Defaults Backs the "Get Support" button; empty hides it.
SupportEmail string "" Defaults
SupportPhone string "" Defaults
ChangePasswordMode string "" Defaults url or SSOExtension.
ChangePasswordUrl string "" Defaults Used when the mode is url.
MarkdownFilePath string "" Defaults Adds a sidebar page rendering that file. Needs MarkdownMenuLabel, and the file must exist.
MarkdownMenuLabel string "" Defaults
MarkdownMenuIcon string "" Defaults SF Symbol name.
CustomCardPath string "" Defaults JSON cards. Watched for changes at runtime.
CustomCardsMenuLabel string "" Defaults Set it and custom cards move to their own sidebar page instead of the home grid.
CustomCardsMenuIcon string "" Defaults
ShowLogoInTrayMenu bool true Defaults
TrayMenuShowIcon bool true Defaults Whether there is a menu bar item at all.
TrayMenuBrandingIcon string "" Defaults Base64 image for the menu bar.

Hiding cards and actions

Key Type Default Owner
HiddenCards [string] [] Defaults
HiddenActions [string] [] Defaults

HiddenCards: Storage, Actions, Evergreen, DeviceInformation, DeviceManagement, ApplicationInstallProgress, Battery, PendingAppUpdates, Jamf, FleetPolicies, Fleet.

HiddenActions: ChangePassword, GatherLogs, RestartIntuneAgent, OpenManagementApp, SoftwareUpdates, GetSupport, Reboot.

Hiding SoftwareUpdates also suppresses its notifications, not just the button. Hidden cards and buttons are left out of the Dock badge count.

Notifications

Key Type Default Owner Notes
NotificationInterval int 4 Defaults Hours between repeats of the same notification type. 0 disables all notifications.
NotificationTitle string "Support Companion" Defaults
NotificationImage string "" Defaults Path to an attachment image.
SoftwareUpdateNotificationMessage string built-in Defaults
SoftwareUpdateNotificationButtonText string built-in Defaults
SoftwareUpdateNotificationCommand string opens the Software Update pane Defaults
AppUpdateNotificationMessage string built-in Defaults
AppUpdateNotificationButtonText string built-in Defaults
AppUpdateNotificationCommand string "" Defaults Set at every launch to open the management app for the detected mode. A value forced by profile still wins.
RebootReminderDays int 0 Defaults Remind after this many days of uptime. 0 is off.
FleetNotifyUpdates bool true Defaults
FleetNotifyInstallResults bool true Defaults
FleetNotifyPolicies bool true Defaults
FleetNotifySignIn bool false Defaults Fleet Desktop SSO sign-in reminders. Off by default, unlike the other three. At most one a day while signed out.

Desktop info

The information window drawn on the desktop. See Customization.

Key Type Default Owner Notes
ShowDesktopInfo bool false Defaults Read once at launch; turning it on or off needs the app restarted.
DesktopInfoWindowPosition string "LowerRight" Defaults LowerRight, LowerLeft, UpperRight, UpperLeft. Applied live.
DesktopInfoFontSize int 14 Defaults
DesktopInfoLevel int 4 Defaults Cumulative: 1 hardware, 2 + system, 3 + network, 4 + storage, 5 + support info.
DesktopInfoBackgroundOpacity double 0.001 Defaults
DesktopInfoBackgroundFrosted bool false Defaults
DesktopInfoHideItems [string] [] Defaults Category or item keys to drop. Also takes Category and Divider to strip the chrome.

Fleet

See Fleet mode.

Key Type Default Owner Notes
FleetRecommendedApps [string] unset Defaults Software keys pinned to the top of the catalog, installed or not.
FleetRecommendedTitle string unset Defaults Renames that section.
FleetButtonLabels dict unset Defaults Custom button text, keyed by title, optionally nested by action.
FleetAppOpenMessages [string] built-in Defaults Replaces the built-in "quit the app first" phrasing.
FleetIconsFromGitHub bool true Defaults Fetch app icons from the public catalog.
FleetUrl string "" Profile Listed under Mode and data sources above.

Diagnostics

Key Type Default Owner Notes
DebugLogging bool false Defaults Debug output to the unified log.
FileDebugLogging bool follows DebugLogging Defaults Also write debug logs to file. Re-read whenever defaults change.

Written by the app

State, not configuration. Listed so it is not mistaken for settings when reading a plist.

Key Notes
LastSoftwareUpdateNotificationTime Notification interval bookkeeping.
LastAppUpdateNotificationTime
LastRebootReminderNotificationTime
LastGenericNotificationTime
isDarkMode -1 system, 0 light, 1 dark. Owned by the in-app toggle.
FleetCollapsedSections Which catalog sections the user has collapsed.

Clone this wiki locally