---
title: Configure Goldfish with MDM
description: Set organization policies for Goldfish on managed Macs.
---

IT administrators can configure Goldfish on managed Macs with a device
management (MDM) tool. Goldfish currently supports two managed settings.

## Supported settings

| Setting | Type | Default | What it does |
|---|---|---|---|
| `CaptureExclusions` | Array of strings | Empty | Apps, websites and windows Goldfish never captures, on top of its built-in list. |
| `AutoUpdate` | Boolean | `true` | Set to `false` to stop automatic updates. You then deploy new versions yourself. |

Each entry in `CaptureExclusions` is one of:

| Entry | Excludes |
|---|---|
| `intranet.example.com` | The site and all its subdomains. |
| `app:Slack` | An app, by the name shown in the app picker on Goldfish's Ignore list page. |
| `title:Confidential` | Any window whose title contains the text. |
| `url:/hr/` | Any page whose address contains the text. |
| `path:payroll` | Any page with that part in its path, like `/payroll`. |

Matching ignores upper and lower case. An exclusion stops future capture.

## macOS

### Option 1: app settings

Add custom settings to a configuration profile with the preference domain
`com.kaspi.goldfish`, and upload this property list:

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>CaptureExclusions</key>
    <array>
        <string>intranet.example.com</string>
        <string>title:Confidential</string>
    </array>
    <key>AutoUpdate</key>
    <false/>
</dict>
</plist>
```

### Option 2: complete profile

Deploy a full `.mobileconfig` with a managed preferences payload. Replace
both `PayloadUUID` values with UUIDs of your own (`uuidgen` makes one).

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>PayloadContent</key>
    <array>
        <dict>
            <key>PayloadType</key>
            <string>com.apple.ManagedClient.preferences</string>
            <key>PayloadVersion</key>
            <integer>1</integer>
            <key>PayloadIdentifier</key>
            <string>com.kaspi.goldfish.managed.preferences</string>
            <key>PayloadUUID</key>
            <string>00000000-0000-0000-0000-000000000001</string>
            <key>PayloadDisplayName</key>
            <string>Goldfish settings</string>
            <key>PayloadContent</key>
            <dict>
                <key>com.kaspi.goldfish</key>
                <dict>
                    <key>Forced</key>
                    <array>
                        <dict>
                            <key>mcx_preference_settings</key>
                            <dict>
                                <key>CaptureExclusions</key>
                                <array>
                                    <string>intranet.example.com</string>
                                    <string>title:Confidential</string>
                                </array>
                                <key>AutoUpdate</key>
                                <false/>
                            </dict>
                        </dict>
                    </array>
                </dict>
            </dict>
        </dict>
    </array>
    <key>PayloadDisplayName</key>
    <string>Goldfish</string>
    <key>PayloadIdentifier</key>
    <string>com.kaspi.goldfish.managed</string>
    <key>PayloadScope</key>
    <string>System</string>
    <key>PayloadType</key>
    <string>Configuration</string>
    <key>PayloadUUID</key>
    <string>00000000-0000-0000-0000-000000000002</string>
    <key>PayloadVersion</key>
    <integer>1</integer>
</dict>
</plist>
```

## Windows

Managed settings are not available on Windows yet.

## Verification

Goldfish picks up a new or changed profile within a minute, without a
restart. Open Goldfish's Settings, then the Ignore list page: your exclusions
appear under "Set by your organization". Removing the profile removes them.
