For IT · Deployment guide

Deploy and lock down ClearDictate with your MDM.

Standard macOS managed preferences. Works with Jamf, Kandji, Intune, Mosyle and any MDM that can deliver a configuration profile.

Hardware
Apple Silicon
macOS
14 Sonoma or later
Package
DMG
Preference domain
com.megakad.dictationapp

1. Install with MDM

  1. 01Download the DMG and verify its SHA-256 against the Download page.
  2. 02Upload it to your MDM as an app package, installing to /Applications.
  3. 03Deploy the managed-settings profile (below) to the same devices.
  4. 04Deploy a PPPC profile for Accessibility (step 5).
  5. 05Scope to a pilot group first, then roll out.

2. Managed settings

Managed values override the user’s settings. In the app, a managed setting is hidden and replaced by a note that it is managed by your organisation.

KeyTypeEffect
ForceOnDeviceBooleantrue allows only the on-device engine (Parakeet). The Cloud engine and Smart cleanup are hidden, and the app never contacts OpenAI. Audio and text never leave the Mac.
ModelMirrorURLString (https URL)Downloads the speech model from this mirror instead of https://huggingface.co. The mirror must serve the same paths as Hugging Face for FluidInference/parakeet-tdt-0.6b-v3-coreml.
HistoryRetentionDaysInteger0 keeps no history, and the History window shows “History Is Off”. Any other number keeps that many days. Unset keeps everything, up to 2,000 dictations.

To test on one Mac without MDM: defaults write com.megakad.dictationapp ForceOnDevice -bool true. A user can undo this, so use a profile to enforce it.

3. Sample profile

ClearDictate-managed.mobileconfigDownload
<?xml version="1.0" encoding="UTF-8"?>
<plist version="1.0"><dict>
  <key>PayloadType</key><string>Configuration</string>
  <key>PayloadDisplayName</key><string>ClearDictate (managed)</string>
  <key>PayloadIdentifier</key><string>com.example.cleardictate</string>
  <key>PayloadScope</key><string>System</string>
  <key>PayloadContent</key>
  <array><dict>
    <key>PayloadType</key><string>com.megakad.dictationapp</string>
    <key>PayloadDisplayName</key><string>ClearDictate settings</string>
    <key>ForceOnDevice</key><true/>
    <key>ModelMirrorURL</key>
    <string>https://models.example.internal</string>
    <key>HistoryRetentionDays</key><integer>30</integer>
  </dict></array>
</dict></plist>

UUIDs and version keys are omitted for readability; the downloadable file is complete, and Copy copies the whole file. Remove any key you don’t want to enforce, and replace the PayloadUUIDs with your own (uuidgen).

4. Model mirror

On first run each Mac downloads the speech model (about 470 MB) from Hugging Face. To keep this inside your network, or to avoid repeated downloads:

  1. aMirror the Hugging Face repository FluidInference/parakeet-tdt-0.6b-v3-coreml to an internal HTTPS host, keeping the same paths.
  2. bSet ModelMirrorURL to that host, for example https://models.example.internal.
  3. cOptionally block huggingface.co at your proxy to confirm no Mac falls back.
ClearDictate Settings, Speech Engine page on a managed Mac: the engine is fixed to On-device with the note that the organisation requires on-device dictation.
Settings › Speech Engine on a Mac with ForceOnDevice set.

5. Permissions (PPPC)

Deploy a Privacy Preferences Policy Control payload for bundle ID com.megakad.dictationapp and the app’s code requirement (from codesign -dr - /Applications/ClearDictate.app). macOS limits what MDM can pre-approve:

PermissionPPPC serviceWhat MDM can do
AccessibilityAccessibilityAllow silently
Input MonitoringListenEventLet standard users approve. Only needed for the Fn key; users can pick a custom shortcut instead.
MicrophoneMicrophoneUser approves on first use
Download sample PPPC profile

Its CodeRequirement already matches ClearDictate as we sign it (Developer ID, team E6Y52GB4C4). If you re-sign the app internally, replace it with the output of the codesign command above.