# Workbrew > Workbrew is fleet management for Homebrew (`brew`) on macOS: a lightweight Agent on each Device plus a web Console that gives IT, security, and platform teams visibility, policies, and automation over Homebrew packages across their fleet, without changing the developer experience. Notes for readers: - Workbrew-specific terms (Device, Workspace, Workbrew Console, Workbrew Agent, Brew Configuration, Tap) are defined in the [glossary](https://workbrew.com/docs/glossary). - The documentation follows the Diataxis framework: each doc is a tutorial, guide (how-to), reference, or explanation. - Workbrew deploys alongside any MDM; per-MDM deployment guides are listed below. ## Start here - [Product overview](https://workbrew.com/): what Workbrew does and who it is for - [Documentation home](https://workbrew.com/docs): index of all docs by category - [Getting started with Workbrew](https://workbrew.com/docs/getting-started): create an account and Workspace, connect a first Device - [Pricing](https://workbrew.com/pricing): plans and what each includes - [Free plan](https://workbrew.com/free): what the free tier offers and how to sign up - [Book a demo](https://workbrew.com/demo): schedule a demo with the Workbrew team - [Security & trust](https://workbrew.com/security): security practices and compliance posture ## Product & concepts - [Why Workbrew](https://workbrew.com/why-workbrew): the problems Workbrew solves for IT, security, and developers - [Features](https://workbrew.com/software-delivery/features): feature-by-feature overview of the platform - [How it works](https://workbrew.com/software-delivery/how-it-works): architecture of the Agent, Console, and MDM integration - [Works with](https://workbrew.com/works-with): MDM and tooling integrations (Jamf Pro, Microsoft Intune, Fleet, JumpCloud, Mosyle, Hexnode, SimpleMDM, Iru, Swif.ai) - [Workbrew MSP](https://workbrew.com/msp): one platform for managed service providers to deploy, patch, and secure software for every customer - [What is Homebrew?](https://workbrew.com/homebrew): explainer on Homebrew, the macOS package manager Workbrew manages - [Homebrew catalog](https://workbrew.com/catalog/sources/homebrew): browsable index of the Homebrew formulae and casks Workbrew can deploy and manage ## Customers - [Customer Stories](https://workbrew.com/customers): how customer teams deliver software securely with Workbrew ## Docs: getting started & reference - [Getting started with Workbrew](https://workbrew.com/docs/getting-started): first-time setup for admins - [Glossary](https://workbrew.com/docs/glossary): definitions of Workbrew-specific terminology - [Network requirements](https://workbrew.com/docs/network-requirements): domains and endpoints Workbrew needs to reach - [Troubleshooting](https://workbrew.com/docs/troubleshooting): common problems and fixes - [Frequently asked questions](https://workbrew.com/docs/frequently-asked-questions): short answers to common questions - [Workbrew API](https://workbrew.com/docs/workbrew-api): what the REST API covers and how to authenticate - [Workbrew API pagination](https://workbrew.com/docs/workbrew-api-pagination): how paginated API responses work - [How to manually install Workbrew on a Device](https://workbrew.com/docs/how-to-manually-install-workbrew): installation without an MDM - [How to detect Homebrew across your fleet](https://workbrew.com/docs/detect-homebrew-across-your-fleet): find existing Homebrew installs before rollout - [Adding users to the workbrew_users group via MDM](https://workbrew.com/docs/adding-users-to-the-workbrewusers-group-via-mdm): grant users managed brew access via MDM - [How to fix "conflicting Homebrew wrapper configuration" errors](https://workbrew.com/docs/how-to-fix-conflicting-homebrew-wrapper-configuration-errors): resolve wrapper conflicts - [How to fix zsh errors after installing Workbrew](https://workbrew.com/docs/how-to-fix-zsh-errors-after-installing-workbrew): resolve shell configuration errors ## Docs: deployment guides (per MDM) - [Deployment guides index](https://workbrew.com/docs/deployment-guides): all MDM-specific deployment guides - [Jamf Pro](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-jamf-pro): deploy Workbrew with Jamf Pro - [Microsoft Intune](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-microsoft-intune): deploy Workbrew with Microsoft Intune - [Fleet](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-fleet): deploy Workbrew with Fleet - [JumpCloud](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-jumpcloud): deploy Workbrew with JumpCloud - [Mosyle Business](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-mosyle-business): deploy Workbrew with Mosyle Business - [Hexnode](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-hexnode): deploy Workbrew with Hexnode - [SimpleMDM](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-simplemdm): deploy Workbrew with SimpleMDM - [Iru](https://workbrew.com/docs/deployment-guides/workbrew-deployment-guide-iru): deploy Workbrew with Iru ## Docs: remote management - [MDM integration](https://workbrew.com/docs/mdm-integration): how Workbrew connects to your MDM - [MDM Device Group sync](https://workbrew.com/docs/mdm-device-group-sync): reference for syncing MDM device groups - [How MDM Device Group sync works](https://workbrew.com/docs/how-mdm-device-group-sync-works): explanation of the sync mechanism - [Managed brew access](https://workbrew.com/docs/managed-brew-access): controlling which users can run brew - [Private Taps](https://workbrew.com/docs/private-taps): reference for private Homebrew Taps in Workbrew - [Decommission a Device or move it to another Workspace](https://workbrew.com/docs/decommission-a-device-or-move-it-to-another-workspace): device lifecycle management ## Docs: security & compliance - [Automatically patch vulnerable packages](https://workbrew.com/docs/automatically-patch-vulnerable-packages): set up a Vulnerability Patching policy with severity thresholds - [Package vulnerabilities](https://workbrew.com/docs/package-vulnerabilities): the Vulnerabilities page, severity levels, and Vulnerability Patching options - [How vulnerability patching works](https://workbrew.com/docs/how-vulnerability-patching-works): when patching runs and what qualifies a package - [Declare policies to block software packages](https://workbrew.com/docs/declare-policies-to-block-software-packages): block specific formulae or casks fleet-wide - [How policies apply to devices in multiple groups](https://workbrew.com/docs/how-policies-apply-to-devices-in-multiple-groups): policy precedence across device groups - [How to block cask self-installs](https://workbrew.com/docs/how-to-block-cask-self-installs): prevent users installing casks outside policy - [Configure your firewall for Workbrew](https://workbrew.com/docs/configure-your-firewall-for-workbrew): firewall rules for Workbrew traffic - [Why we recommend FQDN-based allowlisting](https://workbrew.com/docs/why-fqdn-based-allowlisting): rationale for domain-based firewall rules - [Configure endpoint privilege management for Workbrew](https://workbrew.com/docs/configure-endpoint-privilege-management-for-workbrew): EPM tool compatibility - [How the Workbrew Agent uses elevated privileges](https://workbrew.com/docs/how-workbrew-uses-elevated-privileges): what runs as root and why - [Why Workbrew needs Full Disk Access to update apps in place](https://workbrew.com/docs/why-workbrew-needs-full-disk-access-for-cask-upgrades): FDA rationale - [Preserve app settings during cask upgrades](https://workbrew.com/docs/preserve-app-settings-during-cask-upgrades): in-place upgrades that keep app data - [How Workbrew Console login and SSO enforcement work](https://workbrew.com/docs/console-login-and-sso-enforcement): authentication and SSO behavior - [How Workbrew handles Homebrew Tap trust](https://workbrew.com/docs/how-workbrew-handles-homebrew-tap-trust): trust model for third-party Taps - [How Secret Brew Configurations stay secret](https://workbrew.com/docs/how-secret-brew-configurations-stay-secret): secret handling model - [Using brew outdated with Workbrew to list outdated casks](https://workbrew.com/docs/using-brew-outdated-with-workbrew-to-list-outdated-casks): auditing outdated software ## Docs: developer productivity - [Create a private Tap with a custom formula and cask](https://workbrew.com/docs/create-a-private-tap): tutorial for building a private Tap - [Sync and authenticate private Taps with Workbrew](https://workbrew.com/docs/sync-and-authenticate-private-taps-with-workbrew): distribute private Taps to the fleet - [How Workbrew authenticates private Taps](https://workbrew.com/docs/how-workbrew-authenticates-private-taps): credential model for private Taps - [Authenticate private artifacts downloaded by a formula or cask](https://workbrew.com/docs/authenticate-private-formula-artifacts): private download authentication - [Allow installation of packages from third party Taps](https://workbrew.com/docs/allow-installation-of-packages-from-third-party-taps): permit specific third-party Taps - [Include third-party Tap formulae in Default Packages](https://workbrew.com/docs/include-third-party-tap-formulae-in-default-packages): auto-install Tap formulae fleet-wide - [Set a Secret Brew Configuration](https://workbrew.com/docs/create-a-secret-brew-configuration): store secrets for brew configurations - [Edit Homebrew formulae](https://workbrew.com/docs/edit-homebrew-formulae): how formula editing works under Workbrew - [How to configure PostgreSQL for local development](https://workbrew.com/docs/how-to-configure-postgresql-for-local-development): PostgreSQL via managed Homebrew - [Workbrew Lock](https://workbrew.com/docs/workbrew-lock-beta): lock dependency versions across the fleet ## Trust & operations - [Trust center](https://trust.workbrew.com/): compliance reports and security documentation - [System status](https://status.workbrew.com/): live service status and incident history ## Optional - [About](https://workbrew.com/about): company background and team, which includes Homebrew maintainers - [Blog](https://workbrew.com/blog): product announcements and release notes - [Press](https://workbrew.com/press): press coverage and media resources - [Webinars](https://workbrew.com/webinars): recorded and upcoming webinars - [Events](https://workbrew.com/events): where to meet the Workbrew team - [Careers](https://workbrew.com/careers): open roles - [Contact](https://workbrew.com/contact): how to reach Workbrew