What you’ll set up
You add three items to Rippling and scope all three to the same Supergroup:
When you finish, each Mac uploads two streams to your bucket:
runtime holds agent activity. inventory holds a snapshot of each Mac’s agents, taken every 6 hours.
Before you start
1. Try Beacon on one Mac (optional)
To see what Beacon does before involving Rippling, follow Try Beacon on One Mac. It installs the same package by hand and sends nothing off the Mac.2. Prepare S3
If a Mac already sends Beacon telemetry to S3, you can use the same bucket, prefix and access key and skip to step 3. Run these commands on your own computer with the AWS CLI, signed in to the AWS account that will hold the bucket. Check which AWS account you’re signed in to:beacon-prod. Beacon adds runtime/ and inventory/ under it, so don’t include either.
us-east-1, which is why there are two.
Create an IAM user that can only add objects under the prefix:
AccessKeyId (starting with AKIA) and a SecretAccessKey. Save both in your password manager now; AWS shows the secret only once. You paste them into the Rippling script in step 5.
Test the key by uploading a small file with it. Store it as a named profile first, so the secret isn’t typed on a command line:
upload: - to s3://<bucket>/<prefix>/key-check.txt. A new key can take a minute to start working; if you get InvalidAccessKeyId, wait and try again.
Then delete the test file with your own identity:
[beacon-writer] section from ~/.aws/credentials and the [profile beacon-writer] section from ~/.aws/config, so the key stays only in your password manager.
Two things about the bucket:
- If its default encryption uses a customer managed KMS key, also allow
kms:GenerateDataKeyon that key in the user’s policy. - Beacon sends no encryption headers. A bucket policy that requires one on every upload rejects Beacon’s uploads.
3. Add the background-items profile
- On a Mac, save the profile in Reference: profile as
beacon-background-items.mobileconfig. - In Rippling, go to IT > Devices > Policies > Library > macOS library and click Upload.
- Name it Beacon background services, choose macOS, select the file, and click Save & continue.
- Deploy it to the pilot Supergroup.
4. Add the Beacon package
Download and verify the package on your Mac:pkgutil should print Developer ID Installer: Asymptote Labs, Inc. (3A98D35XJR).
Upload it. Go to IT > Devices > Software > Software libraries, filter to Custom software, and click Upload > Upload Software:
Leave the script fields empty. Rippling then tracks the package by its version, so new versions upgrade normally.
The upload shows Queued, then Ready, usually within 10 minutes. If it shows Error, delete it and upload it again.
Deploy it to the pilot Supergroup: Deploy > Save and deploy.
5. Add the configure script
- Copy the script in Reference: configure script.
- Fill in the five settings at the top: bucket, region, prefix, access key ID and secret access key.
- In Rippling, go to IT > Devices > Scripts > Add Script and paste it in.
- Use these settings:
Each run prints one line per part, for example:
WAIT is normal. It means Beacon isn’t installed yet or nobody is logged in, and the next run finishes the job. To skip the wait on a Mac, open it in Rippling and click Run script on its Activity tab.
6. Check a pilot Mac
In Rippling, the pilot Mac shows the profile installed, Beacon Endpoint Agent installed, and the script’s latest run with onlyOK and INFO lines.
On the Mac, run:
Service: loaded=true running=true and telemetry=enabled next to Claude Code and Codex mean it’s working.
In S3, write a test event on the Mac, wait five minutes (uploads go in batches), then list today’s objects:
Get the key, region and bucket policy right on the pilot. If S3 rejects an upload, the forwarder retries for about five minutes and then drops it.
7. Roll out to everyone
Scope all three items to your full Supergroup, in this order:- The Beacon background services profile.
- Beacon Endpoint Agent.
- The Beacon: configure script. Saving it runs it on every Mac in scope.
Update Beacon
- Download and verify the new package as in step 4.
- Open Beacon Endpoint Agent in the software library and choose Manage > New version.
- Upload the new package, with the script fields still empty.
Rotate the S3 key
- Create a second access key for the Beacon IAM user.
- Put the new key ID and secret in the Beacon: configure script and save it. Rippling runs it on every Mac in scope.
- Check that new objects still arrive in S3.
- Wait until every Mac has run the updated script, then deactivate and delete the old key. A Mac still using a deactivated key can’t upload until it switches.
Remove Beacon
- Take the Mac, or the employee, out of the Beacon Supergroup. Rippling reinstalls software it still targets within an hour.
- Add the script in Reference: remove script as Beacon: remove, frequency Once, and run it on the Mac.
- Its output ends with
OK: Beacon removedwhen everything is gone: Beacon’s services, files, logs, package receipt, S3 key file, and its hooks in each user’s Claude Code, Codex and Cursor.
Troubleshooting
For anything else, run
sudo /opt/beacon/bin/beacon endpoint status --system on the Mac and send the output to Asymptote support. The script’s detailed log is at /var/root/Library/Logs/Beacon/rippling-configure.log on each Mac, readable only by root.
Reference: configure script
Paste into Beacon: configure and fill in the five settings at the top.Beacon: configure
Reference: remove script
Paste into Beacon: remove as is.Beacon: remove
Reference: profile
Save asbeacon-background-items.mobileconfig and upload it in step 3. It needs no edits and contains no secrets.
beacon-background-items.mobileconfig
Related
Rippling
What the package installs and how Rippling deploys it.
Try Beacon on One Mac
Install the package by hand and see what it captures.
Beacon with Fleet and S3
The same S3 setup, installed with Fleet.
Configure S3 Data Connector
Give Asymptote read-only access to the bucket.