Docs overview

Every Mac needs its own record.

A team record is only as complete as its device coverage. Install on each supported Mac, keep owners identifiable and read the assessed count beside every score.

Start with the devices you expect

Make a list of the Macs that should be included and who uses them. Compare that list with the devices cybee reports. The installation token identifies an install. An email helps distinguish employees and their devices.

The billing unit is a Mac on the paid plan. One person with two Macs on that plan pays for two devices. The free plan has no Mac or user limit, within supported product scope.

Give missing devices a real state

Three different observations.
Assessed

Read the controls and their dates for the selected period.

Silent

No recent observation does not prove continued visibility.

Unassessed

Keep the device in the total, outside the assessed count.

Open a part to see how it fits.

Illustrative device record. No live devices.

DeviceObservationInterpretation
Studio Mac 01Assessed in selected periodInclude its observed controls and dates.
Studio Mac 02No recent observationInvestigate the gap. Do not imply ongoing visibility.
Studio Mac 08Not assessedKeep it outside the score and inside the coverage count.
Ask your assistant

Compare the Macs in our team with the assessed devices. Which are missing, silent or outside the selected period?

A useful review routine

  • Check the expected device list before reading a team score.
  • Look for devices that have gone silent.
  • Check who owns each unresolved finding.
  • Review proposed changes on the devices they affect.
  • When sharing a record, name the assessed coverage and the period.

Use this routine in your connected assistant. The website examples use sample data.

When a Mac leaves the team

cybee flags devices that stop reporting. An admin can remove a lost or wiped device from the list in one confirmed step.

Do not treat removing a device from a list as a remote wipe, account offboarding or proof that someone’s cloud access has ended. Google Workspace offboarding removes access in one confirmed step. Its record is separate from the Mac inventory. Keep the historical record distinct from the current device list.

Keep accounts separate

Google Workspace monitoring covers connected accounts, sign ins, app grants, Drive downloads and admin changes. Visibility is free. Sealed account and offboarding records are included in the paid plan. Microsoft 365 is in development.

Connected Google Workspace has its own account record. The device Passport described here covers the listed Macs. Workspace MFA observations cover the connected organisation, not personal Gmail, Apple ID, GitHub, cloud consoles or every other service in the business.

Explore Google Workspace security

The next step is one command.

Protect your Mac, strengthen its settings and keep a dated record of the results.

For supported Macs. cybee is a Swiss company, independent, privacy first.

Chat · CLI · IDE · Terminal
curl -sSf https://get.cybee.dev | sh