Skip to main content
This guide takes you from no Beacon on your Macs to every Mac in scope sending its AI agent activity to an S3 bucket you own. Follow the steps in order. Everything is done in Rippling; nobody installs anything by hand.

What you’ll set up

You add three items to Rippling and scope all three to the same Supergroup: When you finish, each Mac uploads two streams to your bucket:
runtime holds agent activity. inventory holds a snapshot of each Mac’s agents, taken every 6 hours.

Before you start

1. Try Beacon on one Mac (optional)

To see what Beacon does before involving Rippling, follow Try Beacon on One Mac. It installs the same package by hand and sends nothing off the Mac.

2. Prepare S3

If a Mac already sends Beacon telemetry to S3, you can use the same bucket, prefix and access key and skip to step 3. Run these commands on your own computer with the AWS CLI, signed in to the AWS account that will hold the bucket. Check which AWS account you’re signed in to:
It prints the account ID and your identity. Make sure it’s the right account. Set your values. Pick a prefix such as beacon-prod. Beacon adds runtime/ and inventory/ under it, so don’t include either.
Create the bucket, if you don’t have one yet:
It prints the bucket’s location. AWS needs a different command for us-east-1, which is why there are two. Create an IAM user that can only add objects under the prefix:
The first command prints the new user. The second prints nothing when it works. This key can add objects under the prefix and nothing else: it can’t list, read or delete them. Because it can’t list the bucket, the forwarder logs one health-check error each time it starts. Uploads still work. Create an access key for the user:
It prints an AccessKeyId (starting with AKIA) and a SecretAccessKey. Save both in your password manager now; AWS shows the secret only once. You paste them into the Rippling script in step 5. Test the key by uploading a small file with it. Store it as a named profile first, so the secret isn’t typed on a command line:
Enter the access key ID, secret access key and region when asked, and press Enter for the output format. Then upload a test file:
It prints upload: - to s3://<bucket>/<prefix>/key-check.txt. A new key can take a minute to start working; if you get InvalidAccessKeyId, wait and try again. Then delete the test file with your own identity:
Finally, delete the [beacon-writer] section from ~/.aws/credentials and the [profile beacon-writer] section from ~/.aws/config, so the key stays only in your password manager. Two things about the bucket:
  • If its default encryption uses a customer managed KMS key, also allow kms:GenerateDataKey on that key in the user’s policy.
  • Beacon sends no encryption headers. A bucket policy that requires one on every upload rejects Beacon’s uploads.

3. Add the background-items profile

  1. On a Mac, save the profile in Reference: profile as beacon-background-items.mobileconfig.
  2. In Rippling, go to IT > Devices > Policies > Library > macOS library and click Upload.
  3. Name it Beacon background services, choose macOS, select the file, and click Save & continue.
  4. Deploy it to the pilot Supergroup.
Do this before step 4, so the profile is on the Macs before the package installs. Macs pick it up within about 10 minutes.

4. Add the Beacon package

Download and verify the package on your Mac:
pkgutil should print Developer ID Installer: Asymptote Labs, Inc. (3A98D35XJR). Upload it. Go to IT > Devices > Software > Software libraries, filter to Custom software, and click Upload > Upload Software: Leave the script fields empty. Rippling then tracks the package by its version, so new versions upgrade normally. The upload shows Queued, then Ready, usually within 10 minutes. If it shows Error, delete it and upload it again. Deploy it to the pilot Supergroup: Deploy > Save and deploy.

5. Add the configure script

  1. Copy the script in Reference: configure script.
  2. Fill in the five settings at the top: bucket, region, prefix, access key ID and secret access key.
  3. In Rippling, go to IT > Devices > Scripts > Add Script and paste it in.
  4. Use these settings:
Each run prints one line per part, for example:
A line starting with WAIT is normal. It means Beacon isn’t installed yet or nobody is logged in, and the next run finishes the job. To skip the wait on a Mac, open it in Rippling and click Run script on its Activity tab.
Rippling admins who can open this script can read the access key. Limit Devices admin rights to the people who should have it. On the Mac, the script stores the key in a file only root can read, and never prints it.

6. Check a pilot Mac

In Rippling, the pilot Mac shows the profile installed, Beacon Endpoint Agent installed, and the script’s latest run with only OK and INFO lines. On the Mac, run:
Service: loaded=true running=true and telemetry=enabled next to Claude Code and Codex mean it’s working. In S3, write a test event on the Mac, wait five minutes (uploads go in batches), then list today’s objects:
Then quit and reopen Claude Code, run one small task, and check that a newer object arrives. Check the key isn’t readable by users. On the Mac, logged in as a normal user, run this with your access key ID. It should print nothing:
Get the key, region and bucket policy right on the pilot. If S3 rejects an upload, the forwarder retries for about five minutes and then drops it.

7. Roll out to everyone

Scope all three items to your full Supergroup, in this order:
  1. The Beacon background services profile.
  2. Beacon Endpoint Agent.
  3. The Beacon: configure script. Saving it runs it on every Mac in scope.
Keep all three on the same Supergroup. Track progress in Software > My Software (installed, pending and failed counts) and on the script’s page (each Mac’s latest output). Macs that are offline catch up when they come back online.

Update Beacon

  1. Download and verify the new package as in step 4.
  2. Open Beacon Endpoint Agent in the software library and choose Manage > New version.
  3. Upload the new package, with the script fields still empty.
The package keeps the S3 forwarder’s settings, and the next script run updates anything that changed. Watch two or three Macs after each upgrade.

Rotate the S3 key

  1. Create a second access key for the Beacon IAM user.
  2. Put the new key ID and secret in the Beacon: configure script and save it. Rippling runs it on every Mac in scope.
  3. Check that new objects still arrive in S3.
  4. Wait until every Mac has run the updated script, then deactivate and delete the old key. A Mac still using a deactivated key can’t upload until it switches.

Remove Beacon

  1. Take the Mac, or the employee, out of the Beacon Supergroup. Rippling reinstalls software it still targets within an hour.
  2. Add the script in Reference: remove script as Beacon: remove, frequency Once, and run it on the Mac.
  3. Its output ends with OK: Beacon removed when everything is gone: Beacon’s services, files, logs, package receipt, S3 key file, and its hooks in each user’s Claude Code, Codex and Cursor.
Don’t use Rippling’s Uninstall action for Beacon. It removes the package’s files and may leave Beacon’s background services running. To remove Beacon everywhere, do the same for the whole Supergroup, then deactivate the access key in AWS.

Troubleshooting

For anything else, run sudo /opt/beacon/bin/beacon endpoint status --system on the Mac and send the output to Asymptote support. The script’s detailed log is at /var/root/Library/Logs/Beacon/rippling-configure.log on each Mac, readable only by root.

Reference: configure script

Paste into Beacon: configure and fill in the five settings at the top.
Beacon: configure

Reference: remove script

Paste into Beacon: remove as is.
Beacon: remove

Reference: profile

Save as beacon-background-items.mobileconfig and upload it in step 3. It needs no edits and contains no secrets.
beacon-background-items.mobileconfig

Rippling

What the package installs and how Rippling deploys it.

Try Beacon on One Mac

Install the package by hand and see what it captures.

Beacon with Fleet and S3

The same S3 setup, installed with Fleet.

Configure S3 Data Connector

Give Asymptote read-only access to the bucket.