Deliver, see, patch, and govern from one console

Every Mac admin needs to manage software, and it usually involves numerous tools held together with APIs and scripts that can break at any time. Workbrew consolidates the job for you. Homebrew, npm, IDE extensions, and macOS apps, in one inventory, under one set of policies.

Visibility

Know every piece of software on every Mac, whoever installed it.

Inventory beyond Homebrew

Workbrew inventories the npm packages, macOS apps, and IDE extensions installed on each device, alongside Homebrew.

Dependency details

See which npm and Homebrew dependencies a package pulled in and how they are related.

Search and filter

Find every device running a given package or version across the fleet.

Device details

Drill into any device to see which users it has and exactly what is installed on it.

Vulnerability detection

Known vulnerabilities in installed packages are detected and surfaced automatically.

Learn more

Group views

View devices and their associated data by device group.

Software Delivery

Everyone gets the software they need, however they like to work, deployed and managed from one place.

Deploy and manage Homebrew

Install managed Homebrew on every device via your MDM.

Learn more

Workbrew catalog

Browse and deliver software from a catalog of more than 4.5 million open source and commercial titles across Homebrew, npm, and IDE extensions.

Learn more

Existing install detection

Software people installed themselves shows up in your inventory.

Learn more

Workbrew app and brew CLI

Users install software from the command line or a graphical interface, whichever they prefer.

Default packages

New devices automatically bootstrap with a default set of software the moment they enroll.

Default packages per device group

Give each team or device group its own default software set.

Learn more

Software Updates

Keep everything current, and prove you did it inside the window you promised.

Managed brew for standard users

Standard users can run managed brew safely, without requiring root access.

Learn more

Update prompts

Users are notified when their software is out of date and can upgrade it themselves.

Automatic and scheduled updating

Updates to outdated software apply automatically on the schedule you set, with no user action needed.

Integrations

Workbrew fits the tools you already run, instead of being another console someone has to remember to check.

Connect any major MDM

Pull device records from Jamf, Iru, Microsoft Intune, Fleet, JumpCloud, Mosyle, Hexnode, or SimpleMDM.

Learn more

API access

Work with your Workbrew data programmatically through the API.

Learn more

Granular notifications

Choose which events you're notified about, and where they're sent.

Weekly fleet reports

A weekly summary of your fleet's activity, delivered to your inbox.

Sync device groups

Device groups sync from your MDM automatically.

Learn more

Webhooks

Send Workbrew events to your own endpoint, such as a SIEM or an internal service.

Compliance & Audit

Show an auditor what happened, when, and on which machine.

Device command analytics

The Analytics page shows which brew commands ran on each device, and when.

Learn more

Activity logs

An audit trail of who did what in your workspace, and when.

Data export

Filter any view and export the data as CSV or JSON for audits, reporting, and compliance.

Vulnerability Patching

Close known CVEs across the fleet without waiting for a maintenance window.

Explore Vulnerability Patching in depth

Vulnerability details

The CVE identifiers, severity level, latest available versions, and affected devices for any package in your fleet.

Severity settings

Choose the vulnerability severity threshold at which patching kicks in.

Learn more

Automatic patching

Packages at or above your threshold are upgraded when a device checks in, not on a fixed schedule.

Learn more

Open and resolved analytics

Track open and resolved vulnerabilities over time.

Patching per device group

Give each device group its own patching policy and its own severity thresholds.

Change history reports

Reports of every patch applied, for audits and change management.

Governance

Decide what your company can and can’t install, and enforce it without getting in anyone’s way.

Explore Governance in depth

Curate your own software library

Define a list of software your company allows. Anything outside it isn't installable.

Forbid by title or license

Explicitly forbid risky command-line tools, apps or licenses.

Learn more

Request and approval workflows

Users request software from the app or CLI; admins approve or reject the requests in the console.

Remote management

Install, upgrade, or remove software on any device remotely from the console.

Fine-grained policies per group

Target policies at specific device groups, with clear rules for devices in more than one group.

Learn more

Automatic uninstalls

Software that is forbidden can be removed from devices automatically on detection.

Software Publishing

Distribute the software your company builds the same way you distribute everyone else’s.

Private taps

Distribute internal tools to your fleet from Homebrew taps hosted in private GitHub or GitLab repositories.

Learn more

Secret brew configurations

Secret Brew Configurations hold tokens that are masked in the console and never written to disk.

Learn more

Identity & Access

The right people administer Workbrew, and only them.

Allowed domains

Restrict workspace membership to a single verified email domain.

Learn more

Roles and permissions

Control who can view and manage what in your workspace with granular roles.

Single sign-on

Console users sign in through your identity provider.

Learn more

Start free, with no device or user limits

When you need to know which plan or upgrade unlocks a feature, the pricing page maps every one of them.