> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Agent Hub with Jamf Pro

> Create a least-privilege Jamf Pro API Role and Client so Cimento can deploy the endpoint agent to a computer group, with every privilege explained.

Cimento authenticates to Jamf Pro as an API Client using the client-credentials flow, uploads the agent package and configuration profile, scopes them to a computer group you choose, and tracks the install per Mac.

## Prerequisites

* Your Jamf Pro instance URL, for example `https://yourcompany.jamfcloud.com`.
* A Jamf Pro administrator who can create API Roles and API Clients.
* A smart or static computer group to use as the pilot target.
* Macs with an assigned user in Jamf inventory. The profile uses Jamf's `$EMAIL` variable to attribute each Mac, so Cimento never reads your directory.

## Steps

<Steps>
  <Step title="Create an API Role">
    In Jamf Pro, open **Settings › System › API roles and clients › API Roles** and create a role named something like `Cimento Agent Deployment`. Grant exactly the privileges in the table below and leave every other privilege unselected.
  </Step>

  <Step title="Create an API Client bound to that role">
    On the **API Clients** tab, create a client, assign it the role, enable it, and generate a client secret. Jamf shows the secret once; copy it before closing the dialog.
  </Step>

  <Step title="Enter the credentials in Cimento">
    Under **Admin → Integrations → AI agents → Jamf Pro**, paste the instance URL, client ID and client secret. All three are stored encrypted per tenant and never shown again.
  </Step>

  <Step title="Verify">
    Cimento makes read-only calls to confirm the client can authenticate and to list your computer groups.
  </Step>

  <Step title="Deploy">
    Choose a computer group. Cimento uploads the signed `.pkg` as a Package and the `.mobileconfig` as a macOS Configuration Profile, creates a Policy scoped to the group, and triggers the install. Nothing is installed until you click **Deploy**. The page then tracks install status per Mac.
  </Step>
</Steps>

## Privileges to grant and why

| Privilege target | Privilege | Purpose |
| - | - | - |
| Computers | Read | Required by the calls above. |
| Smart Computer Groups and Static Computer Groups | Read | Lists the groups you pick a deployment target from, and reads their membership. |
| Packages | Create, Read, Update | Uploads the agent package and replaces it with each new release. |
| macOS Configuration Profiles | Create, Read, Update | Creates the profile carrying the agent's configuration and updates it in place on later releases. |
| Policies | Create, Read, Update | Creates the policy that installs the agent on the target group. |
| Policies | Delete | Required by Jamf, together with Flush Policy Logs, to clear a policy's run history when the agent is re-deployed. |
| Jamf Pro Server Actions | Flush Policy Logs | Clears the policy's run history so Macs that already installed an earlier version install the new one. Without it those Macs stay on the older version. |

If a privilege is missing, Cimento names the specific one to add, so you can start with this set.

## Why a dedicated API Role

A role scoped to this deployment can do only what the deployment needs, and you can revoke Cimento's access by disabling one API Client.

## Disconnecting

**Disconnect** in Cimento uninstalls the agent from the targeted Macs, removes the package, profile and policy Cimento created, and then deletes the stored credentials.
