AI agent evidence assurance pilot for your Mac fleet
BeProof closes the evidence gap between what AI agents are declared, what access they have been granted, and what activity is observed — without replacing MDM, EDR, or SIEM. This page summarizes the standard 30-day design partner program.
Offer at a glance
- Duration
- 30 days (14-day condensed available)
- Scale
- 25–100 managed Macs (min. 5 for condensed)
- Platform
- macOS 14–15, Apple Silicon
- Connectors
- OpenAI + GitHub org admin (pilot default)
- Admin access
- Web admin console + Firebase sign-in
- Stage
- Pilot-ready — not Enterprise GA
Two-phase scope
Phase A — Local (Week 1)
Signed DMG install, local scan, Policy Pack evaluation, CoverageGap-first results, Ed25519 signed export. Proves endpoint value before MDM scale.
Phase B — Managed fleet (Weeks 2–4)
MDM overlay + enrollment tokens, fleet heartbeat, sanitized review queue, signed policy bundles, and one evidence-chain reconstruction. Metadata-only summaries — raw SQLite never leaves the Mac.
Out of scope for this pilot: SIEM production integration, Endpoint Security live telemetry, enterprise SAML/OIDC, production external enforcement-event adapters, auto-remediation, and non-macOS endpoints (Windows is on the product roadmap under a separate platform PRD — this pilot is macOS-only).
Timeline
- Week 0
Kickoff
Tenant, admin access, roles assigned
- Week 1
Local evidence
Install, scan, policy eval, signed export
- Week 2
MDM pilot ring
PPPC, overlay, first fleet enrollments
- Week 3
Fleet scale
25+ endpoints, optional cloud connectors
- Week 4
Assurance readout
Reconstruct one incident, verify the bundle, document gaps, and complete the exit readout
Success metrics (day 30)
Pass at least 5 of 7 criteria for a successful pilot outcome:
- Enrolled devices report heartbeat within 24h
- Stale audit rate matches manual spot-check
- Signed fleet summaries verify — no raw DB upstream
- Admin RBAC enforced (analyst vs readonly)
- Policy publish reflects on endpoints within one sync cycle
- One incident chain exports as a signed bundle and verifies offline
- MDM overlay precedence on pilot ring
The final bundle must distinguish causal, correlated, and missing links. If an agreed test adapter is included, a blocked outcome is accepted only when an identified external product supplies an explicit enforcement event; otherwise enforcement stays unknown.
Getting started
- Sign pilot charter with scope (endpoints, connectors, sponsor contacts).
- BeProof provisions tenant + admin access → sign in at admin console.
- Optional product walkthrough on demo tenant (Acme Corp sample data) before your dedicated tenant.
- Week 1: local installs. Weeks 2–4: follow managed deployment and create enrollment tokens in the admin console.
- Day 30: scorecard + exit readout.
Tell us what you need to make provable.
We use these details only to evaluate the pilot fit and plan a focused first conversation. BeProof provides a pilot charter, onboarding checklist, and exit readout template at kickoff.