Jamf Pro / Intune: enterprise managed policy for the Bolt desktop app

The Bolt desktop app (distinct from the browser extension, which has its own policy files in the browser-extension kit) reads MDM policy directly from the app’s own managed preference domain. No native-messaging bridge is involved, which is why this is a standard MDM “Custom Settings” payload and not a special case.

  • Preference domain (bundle id): app.sparcle.bolt.enterprise
  • Template: bolt-desktop.mobileconfig
  • Windows: same key catalogue, read from the registry instead. See the Windows guide and its ADMX/ADML template.

This profile carries app SETTINGS only. A second profile covers privacy permissions, and neither implies the other, so deploy both:

Profile What it does Without it
bolt-pppc.mobileconfig Grants the privacy (TCC) permissions Bolt needs. The macOS guide explains every entry Prompts the user cannot satisfy on a managed Mac (no admin password)
bolt-desktop.mobileconfig (this one) DLP mode, guarded sites, vault policy, sign-in target The user’s own choices apply

A third, bolt-nativemessaging.mobileconfig, matters only if your browsers restrict native messaging. The macOS guide says when.

There is no system-extension profile. The current release does not ship a network filter or any other system extension, so there is nothing to pre-approve.

Which keys exist

Bolt reads a closed catalogue of keys. A key outside this list is silently ignored, not an error you would see. These are the same key names the browser extension’s managed schema publishes, so admins have one vocabulary across both surfaces.

Key (write this) Type Merge kind Notes
dlpMode string Level off | warn | redact | block. Most-restrictive wins across sources, even over a forced value.
dlpEnabled bool Switch Forced wins outright; else off beats on. Accepts <integer>0/1</integer> too (MDM tooling habit).
inputGuardEnabled bool Switch Same switch semantics as above.
pageCaptureEnabled bool Switch Same switch semantics as above.
vaultRequirePin bool Switch Force the vault to require a PIN to unlock, instead of leaving it to the user’s own vault setting. Same switch semantics as above.
vaultRequireMasterPassword bool Switch Require a master password for Bolt’s own vault. Forced true: the vault stays shut until the user sets one (with a recovery kit), and it cannot be turned off. Gates access in the running app; stored records are not yet re-encrypted under it. Only the recovery kit resets it; no admin reset exists.
riskySites array<string> Coverage Hostnames the AI-DLP guard covers. Union: every entry ADDS coverage.
riskyAppBundleIds array<string> Coverage Native-only (no browser equivalent): other apps’ bundle ids to treat as risky AI destinations.
inputGuardHosts array<string> Coverage Extra hosts the on-type guard covers beyond riskySites.
allowedCorpDomains array<string> Exemption Intersection: every entry is a HOLE in the policy. An explicit empty array is a real value (closes every hole), not “unset”.
inputGuardExcludeHosts array<string> Exemption Same exemption semantics as above.
pageCaptureExcludeHosts array<string> Exemption Same exemption semantics as above.
boltUrl string Config The org’s Bolt deployment URL.
launchMode string Config Free-form config value (not validated by the merge); use the same values as the extension’s launchMode (native, popup, sidebar) unless the app documents otherwise.
inputGuardMode string Config Free-form config value; extension convention is ai-sites | all-sites.
vaultAutoLockMinutes string Config Force the vault auto-lock timeout. Matches the app’s own picker: 1 | 5 | 15 | 30 | 0 (Never).
vaultMasterPasswordSessionHours string Config Hours a master password unlock lasts before it is asked again; the PIN only re-unlocks within it. 4 | 12 | 24 | 0 (until Bolt restarts).
vaultPendingMaxHours string Config Hours a pending vault action (a login, password change, passkey or authenticator code not yet saved or dismissed) is kept, sealed under the user’s vault key on this device only. 1 (default) | 4 | 24 | 0 (memory only, never written to disk).
appUpdatesEnabled bool Switch May Bolt check for, download and install its own updates? <false/> unregisters the updater entirely: no request is made to the release manifest, so there is nothing for an egress proxy to see. A value of the wrong type is treated as <false/>, never as “allowed”. Omitting the key leaves updating exactly as it ships. This key is the sole authority: the app’s in-app update preference and an air-gapped build flag can only make it update less.
appUpdatePinnedVersion string Config Hold the fleet at ONE version, e.g. 0.1.159. Exact version, not a maximum: Bolt moves to that version and no other, in either direction; a re-published build of the pinned version is still accepted. A string that is not valid semver is treated as “updates off”, not as “no pin”. appUpdatesEnabled <false/> wins over this.

Known gap, not in scope here: pageCaptureAllowHosts exists on the browser-extension side but is deliberately not yet read by the desktop app, because what an empty list means there has to be settled before it can be added safely. Setting it in a profile today does nothing on the desktop app.

Only keys you set are treated as forced; anything you omit falls through to the device-default tier (/Library/Preferences/…, root-writable: e.g. a provisioning script’s sudo defaults write) and then to the app’s own built-in default. There is no per-key opt-out beyond simply not setting it.

Deploy via Jamf Pro

  1. Computers → Configuration Profiles → New.
  2. General payload: give it a name, and set Level to Computer Level (this policy is device/machine-wide, not per-user. Bolt deliberately does not read the user preference domain).
  3. Add the Custom Settings payload (this is the same payload type as PayloadType: com.apple.ManagedClient.preferences in the template).
  4. Set the Preference Domain to app.sparcle.bolt.enterprise.
  5. Either upload bolt-desktop.mobileconfig directly (“Upload File”) or paste its mcx_preference_settings <dict> into the property-list editor: both produce the same forced keys.
  6. Scope to the target smart group and deploy.

Deploy via Microsoft Intune

Intune’s macOS support for arbitrary managed-preferences domains is via a custom configuration profile (it has no first-class UI for third-party app preferences the way Jamf does):

  1. Devices → macOS → Configuration profiles → Create → Templates → Custom.
  2. Upload bolt-desktop.mobileconfig as-is (replace the placeholders first: organization name, boltUrl, and both PayloadUUID values; generate fresh UUIDs with uuidgen, one per occurrence).
  3. Assign to the target device group. Intune installs it as a standard .mobileconfig; no additional Intune-side schema/OMA-URI mapping is needed since the payload is already a complete Apple configuration profile.

Verify

  1. Install Bolt. Its bundle id is app.sparcle.bolt.enterprise.

  2. Install the profile for local testing. profiles install no longer exists: the command-line tool has been unable to install configuration profiles since macOS 11 (profiles install … answers “profiles tool no longer supports installs. Use System Settings Profiles to add configuration profiles.”; verified on macOS 26, profiles tool 8.51). Double-click the .mobileconfig and approve it in System Settings → General → Device Management.

    This works for bolt-desktop.mobileconfig, whose keys land in /Library/Managed Preferences/ either way. It does not work for bolt-pppc.mobileconfig: its privacy grants are honoured only when the profile is delivered by an MDM enrollment. A hand-installed copy is accepted by macOS and then ignored. Test that one on an enrolled Mac or not at all.

  3. Confirm it landed: sudo defaults read /Library/Managed\ Preferences/app.sparcle.bolt.enterprise.plist should show the keys you set.

  4. Launch (or restart) Bolt and confirm the pushed policy is honored: e.g. set dlpMode to block and confirm a risky paste is blocked rather than just warned, or add a host to riskySites and confirm it’s now covered. Since Bolt treats an unmanaged machine as “zero keys, no error,” an absent effect first means: check the profile actually installed (step 3) before assuming the app ignored it.

  5. Remove the profile (sudo profiles remove -identifier app.sparcle.bolt.enterprise.mdm-policy-profile) to confirm behavior reverts to the device-default / built-in floor. Removing the profile un-forces the keys immediately.