The complete software control plane
Deliver, see, patch, and govern from one console
Every Mac admin needs to manage software, and it usually involves numerous tools held together with APIs and scripts that can break at any time. Workbrew consolidates the job for you. Homebrew, npm, IDE extensions, and macOS apps, in one inventory, under one set of policies.
Visibility
Know every piece of software on every Mac, whoever installed it.
Inventory beyond Homebrew
Workbrew inventories the npm packages, macOS apps, and IDE extensions installed on each device, alongside Homebrew.
Dependency details
See which npm and Homebrew dependencies a package pulled in and how they are related.
Search and filter
Find every device running a given package or version across the fleet.
Device details
Drill into any device to see which users it has and exactly what is installed on it.
Vulnerability detection
Known vulnerabilities in installed packages are detected and surfaced automatically.
Group views
View devices and their associated data by device group.
Software Delivery
Everyone gets the software they need, however they like to work, deployed and managed from one place.
Workbrew catalog
Browse and deliver software from a catalog of more than 4.5 million open source and commercial titles across Homebrew, npm, and IDE extensions.
Existing install detection
Software people installed themselves shows up in your inventory.
Workbrew app and brew CLI
Users install software from the command line or a graphical interface, whichever they prefer.
Default packages
New devices automatically bootstrap with a default set of software the moment they enroll.
Default packages per device group
Give each team or device group its own default software set.
Software Updates
Keep everything current, and prove you did it inside the window you promised.
Managed brew for standard users
Standard users can run managed brew safely, without requiring root access.
Update prompts
Users are notified when their software is out of date and can upgrade it themselves.
Automatic and scheduled updating
Updates to outdated software apply automatically on the schedule you set, with no user action needed.
Integrations
Workbrew fits the tools you already run, instead of being another console someone has to remember to check.
Connect any major MDM
Pull device records from Jamf, Iru, Microsoft Intune, Fleet, JumpCloud, Mosyle, Hexnode, or SimpleMDM.
Granular notifications
Choose which events you're notified about, and where they're sent.
Weekly fleet reports
A weekly summary of your fleet's activity, delivered to your inbox.
Webhooks
Send Workbrew events to your own endpoint, such as a SIEM or an internal service.
Compliance & Audit
Show an auditor what happened, when, and on which machine.
Device command analytics
The Analytics page shows which brew commands ran on each device, and when.
Activity logs
An audit trail of who did what in your workspace, and when.
Data export
Filter any view and export the data as CSV or JSON for audits, reporting, and compliance.
Vulnerability Patching
Close known CVEs across the fleet without waiting for a maintenance window.
Explore Vulnerability Patching in depthVulnerability details
The CVE identifiers, severity level, latest available versions, and affected devices for any package in your fleet.
Automatic patching
Packages at or above your threshold are upgraded when a device checks in, not on a fixed schedule.
Open and resolved analytics
Track open and resolved vulnerabilities over time.
Patching per device group
Give each device group its own patching policy and its own severity thresholds.
Change history reports
Reports of every patch applied, for audits and change management.
Governance
Decide what your company can and can’t install, and enforce it without getting in anyone’s way.
Explore Governance in depthCurate your own software library
Define a list of software your company allows. Anything outside it isn't installable.
Request and approval workflows
Users request software from the app or CLI; admins approve or reject the requests in the console.
Remote management
Install, upgrade, or remove software on any device remotely from the console.
Fine-grained policies per group
Target policies at specific device groups, with clear rules for devices in more than one group.
Automatic uninstalls
Software that is forbidden can be removed from devices automatically on detection.
Software Publishing
Distribute the software your company builds the same way you distribute everyone else’s.
Private taps
Distribute internal tools to your fleet from Homebrew taps hosted in private GitHub or GitLab repositories.
Secret brew configurations
Secret Brew Configurations hold tokens that are masked in the console and never written to disk.
Identity & Access
The right people administer Workbrew, and only them.
Roles and permissions
Control who can view and manage what in your workspace with granular roles.
Start free, with no device or user limits
When you need to know which plan or upgrade unlocks a feature, the pricing page maps every one of them.