Repository navigation
Installation
Download from the releases page. Three packages are published, all signed, notarized and stapled:
| Package | Contents |
|---|---|
SupportCompanion-<version>.pkg |
The app and the privileged helper. |
SupportCompanion_LaunchAgent-<version>.pkg |
The launch agent only. |
SupportCompanion_Suite-<version>.pkg |
Both of the above, for convenience. |
The launch agent is optional, and you are free to write your own instead.
| Path | From |
|---|---|
/Applications/SupportCompanion.app |
App package |
/Library/PrivilegedHelperTools/com.github.macadmins.SupportCompanion.helper |
App package |
/Library/LaunchDaemons/com.github.macadmins.SupportCompanion.helper.plist |
App package |
/Library/LaunchAgents/com.github.macadmins.SupportCompanion.agent.plist |
Launch agent package |
The app must stay at /Applications/SupportCompanion.app. The helper refuses to serve a client
running from anywhere else, because a standard user cannot write to /Applications but can write to
plenty of other places.
The package installs the privileged helper itself, through
SupportCompanion.app/Contents/Resources/helper_install.zsh, which places it in
/Library/PrivilegedHelperTools and loads its LaunchDaemon. SMJobBless is deprecated on macOS 14
and later; SMAppService registration remains only as a fallback for a Mac where the packaged helper
is missing.
Two consequences worth knowing before you deploy:
- The package install fails if the helper does not end up running. The app and the helper speak a versioned interface, so a Mac left with an old helper is not merely stale — every privileged operation on it fails. That must not pass silently, so it is reported as a failed install.
-
The helper only serves clients of 3.0.0 or later. A valid signature only proves the connecting
app is a Support Companion build signed by us, which every 2.x release also satisfies — and 2.x
enforced less. The helper checks the client's version, requires the hardened runtime, and requires
it to run from
/Applications.
If you are turning on Admin elevation, read Deploying the helper first. Declarative deployment is the recommended path there, and it changes how you install.
- Settings that grant privileges must move to a configuration profile. Anything you deploy today with
defaults writeas the user —IsPrivilegedactions, the elevation keys — stops being honoured. Configuration explains which keys and why. - Always upgrade the app and the helper together. They ship in the same package, so this happens on its own unless you deploy them separately.
- A Mac with Fleet's agent installed and no other match now selects Fleet mode instead of System
Profiler. Set
Modeexplicitly if you want something else. See Modes.
An uninstaller ships inside the app bundle:
sudo /Applications/SupportCompanion.app/Contents/Resources/Uninstall.zshIt demotes anyone still holding elevated rights before removing anything. Removing the helper by hand during an open elevation window would leave that user a permanent administrator, since the helper is the thing that would have taken the rights back.
A recipe is available: almenscorner-recipes/SupportCompanion.