Governance

Control the software your company runs, without slowing your team down.

With Governance, every piece of software at your company comes through one catalog you control. You decide what's allowed, set guardrails around the rest, and your team stays productive. The open source your company runs stays secure — by default.

  • $10 / device / month upgrade to the free Team plan
  • Included with Business and Enterprise plans
  • Includes Vulnerability Patching

The problem

Your team installs software straight off the internet, because that's how modern work happens. There's no line between what your company has decided to trust and what simply ended up on a laptop, and closing that gap usually means locking machines down until they're painful to use.

16K+Titles your team can install,
none of them procured

What you get

A catalog that's yours, built on the safest way to get software.

Your catalog starts from the full Homebrew library, with over 16k titles that are curated, maintainer-reviewed, and delivered from one trusted place. Governance lets you narrow that to the titles your company trusts, so the easiest way for your team to get software is also the most secure.

Guardrails instead of a lockdown.

Block a risky license, a particular app, or everything that isn't on your list. Whatever you decide, nothing changes for your team until someone reaches for software you haven't approved, and then they get a clear reason and a way to request it. The guardrail does its job without turning into a blocker.

Vulnerable software patched for you.

Governance builds on Vulnerability Patching, so everything you've approved also stays free of known vulnerabilities. Workbrew finds vulnerable packages across the fleet and fixes them at the severity you set, automatically. With the full run of policies behind it, you get finer control over what gets patched than patching gives you on its own.

One baseline for the whole company.

Push a set of default software to every machine so people start with what they need, and hold workspace sign-in to your own domains so only your team gets in. It's one set of rules applied evenly across every device.

How it works

You decide which software titles your company allows. Everything else stays visible, it just isn't installable.

When someone reaches for something that isn't on the list, they're told why, and given a way to ask for it. You approve or decline in the console, and it installs on their next check-in. Nobody files a ticket and nobody waits in a Slack thread.

Frequently Asked Questions

Deploy Workbrew free

Turn on Governance when your security posture calls for it.